Virus: BDS/Verify.K.1 Date discovered: 06/03/2005 Type: Backdoor Server In the wild: No Reported Infections: Low Distribution Potential: Low to medium Damage Potential: Medium Static file: Yes File size: 32.256 Bytes MD5 checksum: e7d155c42fe5e7d13f92e533436c5bda VDF version: 6.30.00.225
General Method of propagation: • Peer to Peer Aliases: • Symantec: Backdoor.Verify • Mcafee: BackDoor-CNQ • Kaspersky: Backdoor.Win32.Verify.k • TrendMicro: BKDR_VERIFY.E • F-Secure: BACKDOOR PROGRAM • Grisoft: BackDoor.Small.43.J • Bitdefender: Backdoor.Verify.K Platforms / OS: • Windows 95 • Windows 98 • Windows 98 SE • Windows NT • Windows ME • Windows 2000 • Windows XP • Windows 2003 Side effects: • Downloads malicious files • Drops malicious files • Records keystrokes • Registry modification • Steals information • Third party control Files It copies itself to the following locations: • %SYSDIR% \pVF.pMK • %SYSDIR% \msidle32.exe • %system drive root% \MsBootMgr.exe It renames the following files: • ntldr into loveyou_pTH • msdos.sys into loveyou_pTH.sys The following files are created: – Non malicious files: • %SYSDIR% \pMK_readme.txt • %SYSDIR% \pMK_wLog.txt • %SYSDIR% \pMK_kLog.txt • %SYSDIR% \pMK_kLogF.txt • %SYSDIR% \music.mid – %WINDIR% \smss.exe Furthermore it gets executed after it was fully created. Further investigation pointed out that this file is malware, too. Detected as: BDS/Verify.J.1 – %SYSDIR% \MsIdle32Hook.dll Further investigation pointed out that this file is malware, too. Detected as: BDS/Verify.H.2 – %SYSDIR% \MsIdle32loader.dll Further investigation pointed out that this file is malware, too. Detected as: BDS/Verify.K It tries to download a file: – The locations are the following: • freewebs.com/rhspyx007/********** • websamba.com/rhspyx007/********** • siteburg.com/download/********** It is saved on the local hard drive under: %TEMPDIR% \pVF_update.exe Furthermore this file gets executed after it was fully downloaded. At the time of writing this file was not online for further investigation. Registry The following registry key is continuously in an infinite loop added in order to run the process after reboot. – [HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Run] • "msidle32.exe"="%SYSDIR% \msidle32.exe" The following registry keys are added: – [HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\pVF] • "pVF_Version"=dword:0000082e – [HKLM\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\ FirewallPolicy\StandardProfile] • "DoNotAllowExceptions"=dword:00000000 • "DisableNotifications"=dword:00000000 – [HKLM\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\ FirewallPolicy\StandardProfile\AuthorizedApplications\List] • "%SYSDIR% \msidle32.exe"="%SYSDIR% \msidle32.exe:*:Enabled:Remote Access" – [HKCR\CLSID\{319A31D4-9194-41e4-8450-A5F99BD0FA0A}] • @="MsIdle32loader.dll" – [HKCR\CLSID\{319A31D4-9194-41e4-8450-A5F99BD0FA0A}\InprocServer32] • @="%SYSDIR% \MsIdle32loader.dll" – [HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\ ShellServiceObjectDelayLoad] • "MsIdle32loader.dll"="{319A31D4-9194-41e4-8450-A5F99BD0FA0A}" – [HKLM\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\ {319A31D4-9194-41e4-8450-A5F99BD0FA0A}] • @="MsIdle32loader.dll" – [HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\App Paths\pVF.exe] • @="%SYSDIR% \msidle32.exe" – [HKCU\Software\Microsoft\Windows\CurrentVersion\Explorer\Advanced] • "Hidden"=dword:00000002 Email It doesn't have its own spreading routine but it has the ability to send an email. It is most likely that the receiver is the author. The characteristics are described below: From: The sender address is spoofed. The sender of the email is the following: • pVF2@pMK.pTH The recipient of the email is the following: • pMK29A@yahoo.com Subject: The following: • pVF v2 Report Body: The contents is the same as in the file: pMK_kLog.txt The email looks like the following: Mailing MX Server: It has the ability to contact one of the following MX servers: • smtp.server.localhost • mail.eircom.net • smtp.wanadoo.fr P2P In order to infect other systems in the Peer to Peer network community the following action is performed: – It searches for directories that contain one of the following substrings: • user • system • book • game • pic • media • download • upload • share • music • doc • program • soft If successful, the following files are created: • MU Korea new!!.exe; Shower girl.exe; _-_Click_-Me!_.exe; Microsoft Office 2003 Crack.exe-_-Secret-_-.exe; ACDSee 8.0 beta.exe; Free telephone.exe; I want to say that....exe; Age of Empires new !!!.exe; MU online-update.exe; kiss me.jpg.exe; Windows XP update new.exe; Mirosoft Windows Longhorn beta test.exe; Monster.jpg.exe; Love you....exe; Hack Yahoo! Pass.exe; Linkin' Park.jpg.exe; My Diary.doc.exe; Top Secret.exe; Manga news.html.exe; Kid1412.jpg.exe; Sherlock Homes.doc.exe; Conan Doyle.jpg.exe; Ichi shinpo.jpg.exe; Yahoo! Smiley new !.exe; FiFa WorldCup 2006 Beta.exe; Nero 7.0 Full.exe; WinRAR 4.0 Full.exe; fun fun fun.exe; Fantasy XII Update.exe; Half-Life 2 Update.exe; Windows XP source code.exe; Norton Antivirus Update.exe; Spy search and destroy new!.exe; bikini.jpg.exe; UFO.doc.exe; The X-files.jpg.exe; XXX-Cindy.jpg.exe; XXX-Britney Spears.jpg.exe; Sexy girl.jpg.exe; xxx_Girl.jpg.exe; BinLaden PPP.jpg.exefucker.jpg.exe; Sweet Valetine.exe; Love to kick boot.exe; Yahoo! Account Cracker.exe; WinAmp 6.0 Full.exe; nude_girl.jpg.exe; H.O.T news.html.exe; ZaiZai smileys.jpg.exe; Hillary Duff - nude.jpg.exe; Photoshop 9.0 Full.exe; Hot Sexxxxx.avi.exe Process termination List of processes that are terminated: • @ZONEALARM.EXE; WEBSCANX.EXE; VSSTAT.EXE; VSHWIN32.EXE; VSECOMR.EXE; VSCAN40.EXE; VETTRAY.EXE; VET95.EXE; TDS2-NT.EXE; TDS2-98.EXE; TBSCAN.EXE; SWEEP95.EXE; F-STOPW.EXE; SPHINX.EXE; SERV95.EXE; SCRSCAN.EXE; SCANPM.EXE; SCAN95.EXE; SCAN32.EXE; SAFEWEB.EXE; RESCUE.EXE; RAV7WIN.EXE; RAV7.EXE; F-PROT95.EXE; F-PROT.EXE; PERSFW.EXE; PCFWALLICON.EXE; PCCWIN98.EXE; PAVW.EXE; PAVCL.EXE; PADMIN.EXE; OUTPOST.EXE; NVC95.EXE; NUPGRADE.EXE; NORMIST.EXE; NISUM.EXE; NAVWNT.EXE; NAVNT.EXE; NAVLU32.EXE; NAVAPW32.EXE; N32SCANW.EXE; MPFTRAY.EXE; MOOLIVE.EXE; LUALL.EXE; LOOKOUT.EX; LOCKDOWN2000.EXE; JEDI.EXE; IOMON98.EXE; IFACE.EXE; ICSUPPNT.EXE; ICSUPP95.EXE; ICMON.EXE; ICLOADNT.EXE; ICLOAD95.EXE; IBMAVSP.EXE; IBMASN.EXE; IAMSERV.EXE; IAMAPP.EXE; FPROT.EXE; FINDVIRU.EXE; ESPWATCH.EXE; ESAFE.EXE; ECENGINE.EXE; DVP95_0.EXE; CLEANER3.EXE; CLEANER.EXE; CLAW95CF.EXE; CLAW95.EXE; CFINET32.EXE; CFINET.EXE; CFIAUDIT.EXE; CFIADMIN.EXE; BLACKICE.EXE; BLACKD.EXE; AVWUPD32.EXE; AVWIN95.EXE; AVSCHED32.EXE; AVPUPD.EXE; AVPTC32.EXE; AVPDOS32.EXE; AVNT.EXE; AVKSERV.EXE; AVGCTRL.EXE; AVE32.EXE; AVCONSOL.EXE; AUTODOWN.EXE; APVXDWIN.EXE; ANTI-TROJAN.EXE; ACKWIN32.EXE; PVIEW.EXE; TASKMGR.EXE; REGEDIT.EXE; MSCONFIG.EXE; D32.EXE; BKAV2002.EXE; PAVSCHED.EXE; NMAIN.EXE; NAVW32.EXE; NAVAPSVC.EXENAVAPW32.EXE; F-AGNT95.EXE; WFINDV32.EXE; AVPM.EXE; AVPCC.EXE; AVP32.EXE Backdoor The following ports are opened: – %executed file% on TCP port 1907 in order to provide a remote Shell. – %executed file% on TCP port 1906 in order to provide backdoor capabilities. Contact server: The following: • ftp://ftp22.websamba.********** As a result it may send some information. Sends information about: • Computer name • Environment variables • Username • Information about the Windows operating system Remote control capabilities: • Download file • Execute file • Send emails • Start keylog • Terminate process • Upload file Stealing – A logging routine is started after keystrokes are typed that match one of the following strings: • securit • dial • credit • admin • pass • ftp • mail • profile • account • regist • sign • log on • log in • logon • login – It captures: • Keystrokes • Window information Miscellaneous Mutex: It creates the following Mutex: • ::. Love_you_pTH .:: String: Furthermore it contains the following string: • ---[ pMK_VeryFun - Written by pMK - (c) 2005]--- File details Programming language: The malware program was written in MS Visual C++. Runtime packer: In order to aggravate detection and reduce size of the file it is packed with the following runtime packer: • UPX
Description inserted by Ionut Slaveanu on Wednesday, May 3, 2006 Description updated by Ionut Slaveanu on Thursday, May 4, 2006
Back
.
.
.
.