Whenever tragedy strikes, spam is sure to follow. This spam follows recent trends that capitalize on, and exploit, tragedies or high profile media events, to entice people to click on links and visit malicious Web sites. This message uses the Chinese earthquake tragedy to further a virus -- with the subject lines that emulate news headlines.
There is even one headline informing readers that the Chinese Olympic Games might be endangered because of the earthquake.
A single URL is contained in the body of the message, which, when opened, displays an image appearing to be a video screen. However, instead of a news report, the user is treated to a malicious executable file that is silently installed on their computer. The executable, in actuality, is a version of the Storm worm known as Trojan.Peacom.D, a malicious bot that downloads information-stealing code on affected PCs.
While the Chinese earthquake tragedy is currently the headline du jour, spammers and cyber attackers consistently use on large-scale events as the bait to drive significant traffic to their infected links.