PDA

View Full Version : so i decided to infect myself with the storm worm



rabid9797
December 29th, 2007, 08:24 AM
through a virtual machine.

here were the results:

http://xs122.xs.to/xs122/07526/windowsvir.png.xs.jpg (http://xs.to/xs.php?h=xs122&d=07526&f=windowsvir.png)

http://xs122.xs.to/xs122/07526/Screenshot-EtherApe.png

as you can see, the damage was system-wide, and transmission of data started immediatley. in fact, i was connecting to so many other ip's that etherape crashed!

needless to say, i killed the machine quickly, and restored it to its original state.

i have to say though, it was very interesting to watch filemon spit out the files it was editing and creating, and watch the list of ip's grow almost exponentially :popcorn:

Linuxratty
December 29th, 2007, 02:26 PM
So, how can people infected with this not notice?

fuscia
December 29th, 2007, 02:30 PM
So, how can people infected with this not notice?

they're not trying as hard.

SOULRiDER
January 2nd, 2008, 05:00 AM
Is it easy to get infected with this thing?

sefs
January 2nd, 2008, 05:11 AM
Is it easy to get infected with this thing?

... and if so how? I would like to try this myself in a VM.

Depressed Man
January 2nd, 2008, 05:20 AM
It's found mostly in email attachments. So just look for them. Wikipedia has a nice article about it. http://en.wikipedia.org/wiki/Storm_worm

It's apparantly hard to remove, though I think it's doable under safe mode in Windows.

p_quarles
January 2nd, 2008, 05:26 AM
It's found mostly in email attachments. So just look for them. Wikipedia has a nice article about it. http://en.wikipedia.org/wiki/Storm_worm

It's apparantly hard to remove, though I think it's doable under safe mode in Windows.
I.e, make a snapshot of your VM before attempting a stunt like this.

Also, it seems pretty likely that the worm will attempt to start spamming people as soon as it's fully installed. In doing this, you're actually contributing resources to the worm's controller, and could be getting more victims to unwittingly turn their computers into zombies. If you feel the need to experiment with this, please turn off your WAN connection before doing so.

arashiko28
January 2nd, 2008, 05:33 AM
That thing looks fun, i'll try it some day!
About not noticing, most of windows users, don't know the machine, only how to work on them and if anything goes wrong, they call someone else. At least that's what 'm tired of seeing. So when their net crashes, mostly reboot the pc or call the service company for support.

ray bot
January 2nd, 2008, 05:39 AM
This reminds me of an xkcd. xkcd.com/350

Polygon
January 2nd, 2008, 06:19 AM
how did you get a copy of the worm? lol

and thats intense. scary how much a virus can do once it has complete control O.o

EdThaSlayer
January 2nd, 2008, 09:07 AM
I also heard that the storm worm has created the worlds most powerful supercomputer, well at least it's combined infected pcs processing speed is on par with todays supercomputers.