Virus: Worm/Warezov.A.3 Date discovered: 29/08/2006 Type: Worm In the wild: Yes Reported Infections: Low Distribution Potential: Medium Damage Potential: Medium Static file: Yes File size: 90.566 Bytes MD5 checksum: 5fdc2edefcae9b0Beb98c743d7951291 VDF version: 6.35.01.157 IVDF version: 6.35.01.160 - Wednesday, August 30, 2006
General Method of propagation: • Email Aliases: • Symantec: W32.Stration.C@mm • Mcafee: W32/Stration@MM • Kaspersky: Email-Worm.Win32.Warezov.h • TrendMicro: WORM_STRATION.BD • VirusBuster: Trojan.Opnis.AI • Eset: Win32/Stration.L • Bitdefender: Trojan.Strationee.K Platforms / OS: • Windows 95 • Windows 98 • Windows 98 SE • Windows NT • Windows ME • Windows 2000 • Windows XP • Windows 2003 Side effects: • Downloads a file • Drops a malicious file • Uses its own Email engine • Registry modification Right after execution the following information is displayed: Files It copies itself to the following location: • %WINDIR% \rsmb.exe The following files are created: – A file that contains collected email addresses: • %WINDIR% \rsmb.wax – %WINDIR% \rsmb.gfx – %malware execution directory% \%two-digit random character string% .tmp – %WINDIR% \rsmb.dll Used to hide a process. Detected as: Worm/Warezov.C It tries to download a file: – The location is the following: • gadesunheranwui.com/chr/zjjk/********** At the time of writing this file was not online for further investigation. Registry The following registry key is added in order to run the process after reboot: – HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Run • "rsmb"="%WINDIR% \rsmb.exe s" Email It contains an integrated SMTP engine in order to send emails. A direct connection with the destination server will be established. The characteristics are described in the following: From: The sender address is spoofed. To: – Email addresses found in specific files on the system. – Email addresses gathered from WAB (Windows Address Book) Subject: One of the following: • Error • picture • Status • Good day • Mail Delivery System • Mail Transaction Failed Body: The body of the email is one of the lines: • The message contains Unicode characters and has been sentas a binary attachment. • The message cannot be represented in 7-bit ASCII encodingand has been sent as a binary attachment • Mail transaction failed. Partial message is available. Attachment: The filename of the attachment is constructed out of the following: – It starts with one of the following: • test • file • doc • document • message Continued by one of the following fake extensions: • dat • log • msg • txt The file extension is one of the following: • exe • cmd • pif The attachment is a copy of the malware itself. The email looks like the following: Mailing Search addresses: It searches the following files for email addresses: • xml; xls; wsh; wab; uin; txt; tbb; stm; shtm; sht; php; oft; ods; nch; msg; mmf; mht; mdx; mbx; jsp; html; htm; eml; dhtm; dbx; cgi; cfg; asp; adb File details Programming language: The malware program was written in MS Visual C++. Runtime packer: In order to aggravate detection and reduce size of the file it is packed with the following runtime packer: • MEW
Description inserted by Irina Boldea on Wednesday, October 18, 2006 Description updated by Irina Boldea on Thursday, October 19, 2006
Back
.
.
.
.