TrendLabs Malware Blog
Glossary
TrendWatch
TrendLabs Twitter
WORM_NUWAR.ZIP
Overview

Malware type: Worm

Aliases: Email-Worm.Win32.Zhelatin.ct (Kaspersky), Trojan.Peacomm!zip (Symantec), TR/Zhelatin.ZIP.Gen (Avira), Troj/Dorf-Zip (Sophos),

In the wild: Yes

Destructive: No

Language: English

Platform: Windows 98, ME, NT, 2000, XP, Server 2003

Encrypted: No

Overall risk rating:


Reported infections:

Damage potential:

High

Distribution potential:

High

Infection Channel 1 : Propagates via email


Description: 

To get a one-glance comprehensive view of the behavior of this malware, refer to the Behavior Diagram shown below.

WORM_NUWAR.ZIP Behavior Diagram

Malware Overview

This is the Trend Micro detection for the password-protected archive (.ZIP) file mass-mailed by the WORM_NUWAR.AOP.

The email message sent by WORM_NUWAR.AOP contains a password with random characters that is used to open this archive file. Once opened, the user must execute the file for routines of WORM_NUWAR.AOP to be exhibited on the affected system.

Due to the nature of WORM_NUWAR.AOP's propagation, this detection prevents the said archive file from spreading on a network.

For additional information about this threat, see:
Solution
Technical Details

Description created: Apr. 12, 2007 6:51:16 PM GMT -0800

Search a new malware

Tell us how we did. Take our quick survey.