
SonicWALL UTM Research team received reports of a new variant of Peer-to-Peer (P2P) Worm Prolaco spreading in the wild. It propagates through P2P channels as well as spammed e-mail. The e-mail contains the malicious file inside the zip attachment.
Below are sample e-mails:
Subject:
Attachment:
Email Body:
You have got a personal message on Facebook from your friend.
To read it please check the attachment.
Thanks,
The Facebook Team
===================================================
Hello!
You have received a Hallmark E-Card from your friend.
To see it, check the attachment.
There's something special about that E-Card feeling. We invite you to make a friend's day and send one.
Hope to see you soon,
Your friends at Hallmark
===================================================
We just received your resume and would like to thank you for your interest in working at Google.
This email confirms that your application has been submitted for an open position.
Our staffing team will carefully assess your qualifications for the role(s) you selected and others that
may be a fit. Should there be a suitable match, we will be sure to get in touch with you.
Click on the attached file to review your submitted application.
Have fun and thanks again for applying to Google!
Google Staffing
===================================================
The e-mail message looks like below:
Once the user runs the executable file, it will do the following activities:
File Operation:
Added Files
Registry Operation:
Added Entries
Allows program to run without user notification:
Ensures this Worm runs on every Windows startup.
Ensures this Worm bypass the Firewall.
Malware Propagation:
This Worm drops copies on P2P shared folders using filenames taken from its list:
List of the P2P apps:
Filenames it uses when copying itself to P2P folders which are key generator and cracking tools of popular commercial applications:
Mass-Mailing
This Worm harvests email addresses from the system and send spam emails with an attachment of itself.
Network Activity:
The following HTTP request were observed from this Worm:
Pop-up Advertisements
The following are the keyword terms that it monitors and once found displays pop-up advertisements from the domain "tetrosearch.com":
SonicWALL Gateway AntiVirus provides protection against these Worm via the following signatures:
Share This Article

An Article By
An Article By
Security News
Security News