Member sign in
- Not a member?
Sign up
for free.
/
STOCK COLLEGE
/
SPAM REPORT
/
STOCK PROFILES
/
BOARDROOM
/
FORUMS
/
CONTACT
/
Stock Market Forums
May 16, 2008, 02:44:05 AM
Welcome,
Guest
. Please
login
or
register
.
Did you miss your
activation email?
1 Hour
1 Day
1 Week
1 Month
Forever
Login with username, password and session length
Home
Search
Login
Register
Qwoter Stock Market Forums
>
Stock Spam And Spammers
>
Qwoter Stock Spam News
(Moderator:
The Web Team
) >
Storm Worm Victims Get Stock Spam Pop-Up
« previous
next »
Pages:
[
1
]
Author
Topic: Storm Worm Victims Get Stock Spam Pop-Up (Read 479 times)
The Web Team
Administrator
Hero Member
Karma: 12
Posts: 5728
Storm Worm Victims Get Stock Spam Pop-Up
«
on:
November 14, 2007, 08:22:03 AM »
Full article located at :
http://blog.washingtonpost.com/securityfix/2007/11/storm_worm_victims_get_stock_s_1.html
By: BRIAN KREBS, © 2006-2007 The Washington Post Company
-----------------------------------------------
HPGI — Hemisphere Gold, Inc.
Com (1 Cent)
Primary Venue: Pink Sheets
Pink Sheets Status: Still Quoted
----------------------------------------------
If you're a Windows users and today received a surprise pop-up advertisement urging you to invest in an obscure penny stock, it is highly likely that your computer is infected with the virulent Storm worm, a nasty intruder that currently resides on an estimated 200,000 PCs worldwide.
Criminal groups that control the pool of Storm-infected computers have traditionally used those systems to pump out junk e-mail ads touting thinly traded penny stocks as part of an elaborate and ongoing series of "pump-and-dump" schemes. But today, according to security researchers, the Storm worm authors went a step further by causing a pop-up ad for a particular penny stock to be shown on all infected machines.
Atlanta-based SecureWorks tracked the latest Storm activity, which began earlier this morning. The pop-up, shown in the image to the right, touts a microcap stock for Hemisphere Gold Inc. [HPGI.PK] as a "strong buy." Joe Stewart, a senior security researcher at SecureWorks who has closely tracked Storm since its inception in January, said this is the same stock that Storm-infected machines advertised in a traditional spam run that began Monday evening.
For those readers who received this pop-up, the news only gets worse: Detecting and removing a Storm infestation can be exceedingly difficult, as it is programed to regularly mutate its digital make-up. Part of Storm's sneakiness stems from the fact that it ships with what's known as a "rootkit," a set of computer instructions designed to hide the malicious files and system processes that carry out most of the worm's activities. It does this essentially by inserting those components into legitimate Windows processes and drivers -- such as "tcpip.sys," the driver that handles core Internet networking functions on Windows systems.
"By injecting itself into regular Windows processes and hijacking Windows drivers, Storm doesn't give you much to grab onto there," Stewart said. "Most people are going to have to depend on their anti-virus vendor to eventually get updated to detect whichever Storm variant is on their machine, or pay an expert to find it on their machine and remove it."
Predictably, anyone who was foolish enough to snap up shares of the Storm-touted stock -- HPGI.PK -- lost money in trading. The company's share price fell 15 cents today, from $1.15 per share to $1.00. A noticeable and uncharacteristic uptick in trading volume on this stock is evident over the past week, possibly indicating that groups allied with the Storm worm authors were taking a position in advance of this spam campaign.
I put a call into Hemisphere Gold and am awaiting a response. I'll update this post if the company issues a comment or responds to my query.
Logged
The Web Team
Qwoter.com
The Web Team
Administrator
Hero Member
Karma: 12
Posts: 5728
Re: Storm Worm Victims Get Stock Spam Pop-Up
«
Reply #1 on:
November 15, 2007, 06:55:13 PM »
ALERT: I think we are turning SOUTH, the "Storm" is clearing out!
Logged
The Web Team
Qwoter.com
Pages:
[
1
]
« previous
next »
Jump to:
Please select a destination:
-----------------------------
Qwoter Announcements
-----------------------------
=> Qwoter Site Discussion
=> Qwoter Services Directory & Links
=> Qwoter Boardroom
=> Qwoter Featured Profiles
=> Qwoter Press Wire
-----------------------------
Stock Spam And Spammers
-----------------------------
=> Qwoter Stock Spam News
=> Qwoter Stock Spam Report
=> Stock Promotions (Current)
-----------------------------
General Category
-----------------------------
=> General Discussion
=> Trading strategies from the street
=> Pinksheet Discussion
=> Grey Sheets Discussion
=> OTCBB Discussion
=> OTCQX
=> AMEX Discussion
=> NYSE Discussion
=> Bizarre News
=> Qwoter Crazy Weather
=> Old Stock Cert. Art
-----------------------------
Qwoter Media Sections
-----------------------------
=> Short Term Trading
=> Securities Video Media
=> Securities Audio Media
=> Microcap Analysis Reports
-----------------------------
Securities Regulators
-----------------------------
=> SEC, DTC & NASD
=> SEC Administrative Proceedings
=> SEC Litigation Releases
=> BC Securities Commission
Loading...