How to promote your Storm Worm Peacomm Rootkit via Google and newyearcards2008.com
Saturday, December 29th, 2007Whats the first thing people all over the world do when they want to find out about something…they Google it!!! “Googling” something has become a keyword in so many people’s lives these days. Googling has an entry on popular online dictionaries http://dictionary.reference.com/browse/google which means it wont be long before you can actually use the word Googling “legally”.
So when millions of people recently got an email with a link to newyearcards2008.com where they could pick up their New Years E Card Greeting they went to Google and did a search for newyearcards2008.com and they would have seen newyearcards2008.com at the very top,
From Google….
“Happy New Year!
| Your download should begin shortly. If your download does not start in approximately 15 seconds, you can click here to launch the download and then press … newyearcards2008.com/ - 1k - Cached - Similar pages“ |
Most Google users would think it is legitimate such is the trust in Google these days. When clicked on the user would have seen a page delivered via someones PC whether it be in their front room, bedroom, office, factory floor even unsuspecting Internet Cafe’s all over the world.

Snapshot from newyearcards2008.com
These infected PC users do not suspect a thing because their Anti Virus program shows that everything is ok, all is well. Why? The latest Storm Worm is using a rootkit … http://www.antirootkit.com/blog/2007/12/27/happy-new-rootkit/ . Nothing shows because of the stealth capabilities of the rootkit. It hides all traces of itself from normal anti virus and anti spyware scanners. Different scanners are now required for checking for rootkits. Scanners that know exactly how the rootkit operates are required, check out the Antirootkit Software page for list of new scanners.
Why does a search of newyearcards2008.com show the main infection site up first on a Google search? It’s all about how many pages on the internet link to newyearcards2008.com. Even by me putting newyearcards2008.com in this blog will help the name climb the Google ladder so that it shows at the very top and stays top for as long as it can, fooling people into thing it is legitimate ( I mention newyearcards2008.com a lot here so that this blog entry will raise higher than newyearcards2008.com and people will read this warning before getting their New Year’s “Surprise” E-Card).
The people who registered newyearcards2008.com, they went about getting the domain name mentioned on a lot of internet pages around the world, mostly on blog pages belonging to Google. Most of the Blogspot pages have been disabled by Google but many Blogspot and Blogger owners who are using their own domain name have links to newyearcards2008.com
in thier “hacked” blogs.
If you suspect a site as being unusual with unusual activity then you can report it to Google and help them mark it as suspect. You can report to Google, suspect sites, via http://www.google.com/safebrowsing/report_badware/
A recent Trend Micro Blog entry highlights Blogger pages being used to harbor links to newyearcards2008.com… http://blog.trendmicro.com/hundreds-of-blogger-pages-harboring-new-years-storm-links/trackback/
So far as of 29th Dec GMT newyearcards2008.com is showing tops, lets see when it is highlighted as a suspect site by Google on a web search.
Also keep an eye out for newyearwithlove.com
(Asked whois.nic.ru:43 about newyearwithlove.com)
Domain name: NEWYEARWITHLOVE.COM
Name Server: ns.newyearwithlove.com 24.161.84.89
Name Server: ns10.newyearwithlove.com 69.179.23.34
Name Server: ns11.newyearwithlove.com 70.241.145.212
Name Server: ns12.newyearwithlove.com 69.137.25.197
Name Server: ns13.newyearwithlove.com 82.67.135.130
Name Server: ns2.newyearwithlove.com 71.201.48.186
Name Server: ns3.newyearwithlove.com 68.114.62.80
Name Server: ns4.newyearwithlove.com 76.226.178.239
Name Server: ns5.newyearwithlove.com 70.128.122.94
Name Server: ns6.newyearwithlove.com 76.201.158.149
Name Server: ns7.newyearwithlove.com 75.49.2.123
Name Server: ns8.newyearwithlove.com 67.8.191.249
Name Server: ns9.newyearwithlove.com 71.12.83.79
Creation Date: 2007.12.26
Updated Date: 2007.12.26
Expiration Date: 2008.12.26
Status: DELEGATED
Registrant ID: XHAEJUS-RU
Registrant Name: Bill Gudzon
Registrant Organization: Bill Gudzon
Registrant Street1: 1920 str. office 345
Registrant City: Los-Angeles
Registrant State: CA
Registrant Postal Code: 32089
Registrant Country: US
Administrative Technical Contact
Contact ID: XHAEJUS-RU
Contact Name: Bill Gudzon
Contact Organization: Bill Gudzon
Contact Street1: 1920 str. office 345
Contact City: Los-Angeles
Contact State: CA
Contact Postal Code: 32089
Contact Country: US
Contact Phone: 1 320 5427834
Contact E-mail: bgudzon1956@hotmail.com
Registrar: ANO Regional Network Information Center dba RU-CENTER
Last updated on 2007.12.29 05: 07: 05 MSK/MSD
Keep Safe,
Steo - www.antirootkit.com