Nume: Worm/SdBot.akv Descoperit pe data de: 17/11/2005 Tip: Vierme ITW: Nu Numar infectii raportate: Scazut Potential de raspandire: Mediu Potential de distrugere: Mediu Fisier static: Da Marime: 76.800 Bytes MD5: e4c3dcd460c2e4c898c65a59161c2d80 Versiune VDF: 6.36.01.45 Versiune IVDF: 6.36.01.48 - Freitag, 17. November 2006
General Metoda de raspandire: • Reteaua locala Alias: • Kaspersky: Backdoor.Win32.SdBot.avd • TrendMicro: WORM_SDBOT.ALQ • Sophos: W32/Tilebot-HH Initial identificat ca: • TR/Packed.CryptExe Sistem de operare: • Windows 95 • Windows 98 • Windows 98 SE • Windows NT • Windows ME • Windows 2000 • Windows XP • Windows 2003 Efecte secundare: • Modificari in registri • Profita de vulnerabilitatile softului • Posibilitatea accesului neautorizat la computer Fisiere Se copiaza in urmatoarea locatie: • %SYSDIR%\lsyss.exe Sterge copia initiala a virusului. Registrii sistemului Urmatoarele chei sunt adaugate in registri pentru a incarca serviciul la repornirea sistemului: – HKLM\SYSTEM\CurrentControlSet\Services\Windows Reg Service • "Type"=dword:00000110 • "Start"=dword:00000002 • "ErrorControl"=dword:00000000 • "ImagePath"="%SYSDIR%\lsyss.exe" • "DisplayName"="Windows Reg Service" • "ObjectName"="LocalSystem" • "FailureActions"=%hex value% • "Description"="Windows Reg Service" Valorile urmatoarelor chei sunt sterse din registrii sistemului: – HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Shell Extensions • "jda30"=%fisier executat% – HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings\ ProxyEnable – HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings\ ProxyServer – HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings\ ProxyOverride – HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings\ AutoConfigURL Urmatoarele chei sunt adaugate in registrii sistemului: – HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Shell Extensions • "jda30"=%fisier executat% – HKLM\SYSTEM\CurrentControlSet\Services\Windows Reg Service\Security • "Security"=%hex value% – HKLM\SYSTEM\CurrentControlSet\Services\Windows Reg Service\Enum • "0"="Root\\LEGACY_WINDOWS_REG_SERVICE\\0000" • "Count"=dword:00000001 • "NextInstance"=dword:00000001 – HKLM\SYSTEM\CurrentControlSet\Enum\Root\LEGACY_WINDOWS_REG_SERVICE • "NextInstance"=dword:00000001 – HKLM\SYSTEM\CurrentControlSet\Enum\Root\LEGACY_WINDOWS_REG_SERVICE\ 0000 • "Service"="Windows Reg Service" • "Legacy"=dword:00000001 • "ConfigFlags"=dword:00000000 • "Class"="LegacyDriver" • "ClassGUID"="{8ECC055D-047F-11D1-A537-0000F8753ED1}" • "DeviceDesc"="Windows Reg Service" – HKLM\SYSTEM\CurrentControlSet\Enum\Root\LEGACY_WINDOWS_REG_SERVICE\ 0000\Control • "*NewlyCreated*"=dword:00000000 • "ActiveService"="Windows Reg Service" – HKLM\SOFTWARE\Microsoft\Security Center • "UpdatesDisableNotify"=dword:00000001 • "AntiVirusDisableNotify"=dword:00000001 • "FirewallDisableNotify"=dword:00000001 • "AntiVirusOverride"=dword:00000001 • "FirewallOverride"=dword:00000001 – HKLM\SOFTWARE\Policies\Microsoft\WindowsFirewall\DomainProfile • "EnableFirewall"=dword:00000000 – HKLM\SOFTWARE\Policies\Microsoft\WindowsFirewall\StandardProfile • "EnableFirewall"=dword:00000000 – HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\WindowsUpdate\ Auto Update • "AUOptions"=dword:00000001 – HKLM\SYSTEM\CurrentControlSet\Services\wscsvc • "Start"=dword:00000004 – HKLM\SYSTEM\CurrentControlSet\Services\lanmanserver\parameters • "AutoShareWks"=dword:00000000 • "AutoShareServer"=dword:00000000 – HKLM\SOFTWARE\Policies\Microsoft\Windows\WindowsUpdate • "DoNotAllowXPSP2"=dword:00000001 – HKLM\SYSTEM\CurrentControlSet\Services\TlntSvr • "Start"=dword:00000004 – HKLM\SYSTEM\CurrentControlSet\Services\RemoteRegistry • "Start"=dword:00000004 – HKLM\SYSTEM\CurrentControlSet\Services\Messenger • "Start"=dword:00000004 Urmatoarele chei din registri sunt modificate: – HKLM\SYSTEM\CurrentControlSet\Control Vechea valoare: • "WaitToKillServiceTimeout"="2000" Noua valoare: • "WaitToKillServiceTimeout"="7000" – HKLM\SYSTEM\CurrentControlSet\Control\Lsa Vechea valoare: • "restrictanonymous"=dword:00000000 Noua valoare: • "restrictanonymous"=dword:00000001 – HKLM\SOFTWARE\Microsoft\Ole Vechea valoare: • "EnableDCOM"="Y" Noua valoare: • "EnableDCOM"="N" Reţea Exploit: Foloseste urmatoarele vulnerabilitati: – MS03-026 (Buffer Overrun in RPC Interface) – MS03-039 (Buffer Overrun in RPCSS Service) – MS04-007 (ASN.1 Vulnerability) – MS04-011 (LSASS Vulnerability) – MS05-039 (Vulnerability in Plug and Play) Procesul de infectare: Se creeaza un script FTP in sistemul afectat, pentru a descarcaun malware pe alt computer controlat la distanta. Activare de la distanta: –Incearca sa activeze de la distanta malware-ul pe sistemul recent infectat. Pentru aceasta, apeleaza functia NetScheduleJobAdd. IRC Pentru a trimite informatii si pentru a fi controlat se conecteaza la serverul IRC: Server: x.realdot********** Port: 8080 Parola serverului: master Canal: #4. Nick: [P00|USA|%sir de 5 caractere aleatoare% ] Parola: ..... – Acest malware poate obtine si trimite infomatii cum ar fi: • Timpul de cand malware-ul a fost lansat in executie • Informatii despre retea • Informatii despre procesele sistemului • Informatii despre sistemul de operare – In plus, poate efectua urmatoarele operatii: • dezactivarea partajarii de resurse in retea • descarcare fisier • editare registru sistem • activarea partajarii de resurse in retea • terminare proces • deschidere consola • Scaneaza reteaua • oprierea sistemului • terminare proces malware Terminarea proceselor Lista cu procesele oprite: • i11r54n4.exe; rate.exe; winsys.exe; irun4.exe; bbeagle.exe; d3dupdate.exe; teekids.exe; Penis32.exe; MSBLAST.exe; PandaAVEngine.exe; mscvb32.exe; ssate.exe; sysinfo.exe Detaliile fisierului Compresia fisierului: Pentru a ingreuna detectia si a reduce marimea fisierului, este folosit un program de compresie runtime.
Die Beschreibung wurde erstellt von Bogdan Iliuta am Freitag, 17. November 2006 Die Beschreibung wurde geändert von Bogdan Iliuta am Montag, 20. November 2006
zurück
.
.
.
.