Sick of Storm Worm news? I’m not

I am not really sick of hearing about Storm Worm news because it’s not like EICAR test file yet.  Why? Because with EICAR test file, all antivirus will detect it as EICAR but for Storm Worm, um.. not:

stormworm

It will offer secret_archive.exe file when user visits or clicks such links:

stormworm2

So it is really not like EICAR like yet.  Scanners still need to do more work to be able to detect all variants of Storm Worm:

stormwormvt

http://www.virustotal.com/analisis/b0d43f3fa36f76695a0e30ee846322df

Well, malware scanners have excuse, EICAR test file has no variant.

Leave a Reply