All the latest UK technology news, reviews and analysis

The 'hacker tool' worm that gurned

by Iain Thomson

02 Feb 2005

Be the first to comment

  • Tweet this

The old English practice of gurning, in which participants pull a funny or scary face, is being used by a newly discovered worm to distract PC users while their machines are being compromised.

The Wurmark-F worm, a variant of Wurmark-D which began spreading last month, arrives as a zipped email attachment and displays a picture of an old man pulling an impressive gurn.

Meanwhile the worm installs itself in the Windows system folder, along with a new version of the Rbot worm, which spreads via networks without the need for user interaction.

Wurmark-F then harvests email addresses, except those of antivirus companies, and emails itself out. The Rbot payload immediately starts to look for vulnerable computers on the network and installs a Trojan to allow the PC to be used remotely for hacking or spamming.

"This is a nasty one because it's a carrier for a much more dangerous worm," said Graham Cluley, senior technology consultant at IT security firm Sophos.

"The Rbot worm is a tremendously powerful hacker tool and there are a lot of variants out there. It's very popular in the hacking and spamming community because it gives the hacker full control of the PC."

Wurmark-F is spreading through the English speaking world, but Cluley warned that the Rbot worm it carries is far more dangerous.

Emails have the subject line 'Hhahahah lol!!!!', 'Rate My Pic', 'Your Pic On A Website!!' or 'You have an Admirer'.

The choice of a gurning picture may indicate that the worm's writer is British. Gurning is an ancient Cumbrian practice of pulling a funny face and is famously practised in the village of Egremont at its annual crab apple fair.

Last year a record 29 contestants turned up from Australia, New Zealand, Sweden and the UK to contest the men's Gurning World Championship. Cumbrian local Tommy Mattinson clinched the prize.

More information about Wurmark-F is available from Sophos here.

Do you agree?

 

Add your comment

We won't publish your address
By submitting a comment you agree to abide by our Terms & Conditions. Your comment will be moderated before publication.

Poll

Flame virus poll

Are you confident that the UK's IT infrastructure is secure from attack in the wake of the Flame malware revelations?

31%

1%

12%

56%

Connect with V3.co.uk

Sign up to our daily or weekly newsletters

Symanteccloud

Social networking: a guide for IT managers

Social networking is almost ubiquitous. This white paper examines the benefits and risks and it looks at the different ways companies can reconcile them

Riverbed

Mitigating the risks of IT change

The importance of understanding your infrastructure

Scrum Master

Want to work for one of the most dynamic, creative environments...

Interactive & Mobile QA Engineer

Want to work for one of the most dynamic, creative environments...

Enterprise Architect - London - £100k - £120k

Roc Search is currently recruiting for an Infrastructure...

IP Services Project Engineer (Alcatel/Cisco)

Want to work for one of the most dynamic, creative environments...

To send to more than one email address, simply separate each address with a comma.