Virus: Worm/Koobface.exa Date discovered: 08/02/2010 Type: Worm In the wild: Yes Reported Infections: Low to medium Distribution Potential: Low Damage Potential: Low to medium Static file: Yes File size: 59.392 Bytes MD5 checksum: 339e910b5aec569e30a73362fa4a851b IVDF version: 7.10.03.235 - Monday, February 8, 2010
General Aliases: • Mcafee: W32/Koobface.worm.gen.e • Panda: W32/Koobface.JT.worm • Eset: Win32/Koobface.NCL • Bitdefender: Worm.Generic.225291 Platforms / OS: • Windows 2000 • Windows XP • Windows 2003 Side effects: • Downloads a malicious file • Drops malicious files • Registry modification Files It copies itself to the following location: • %WINDIR% \freddy84.exe It deletes the initially executed copy of itself. It deletes the following files: • %malware execution directory% \sd.dat • %WINDIR% \dxxdv34567.bat • c:\3.reg The following files are created: – c:\3.reg This is a non malicious text file with the following content: • %code that runs malware% – %WINDIR% \dxxdv34567.bat Furthermore it gets executed after it was fully created. This batch file is used to delete a file. – %malware execution directory% \sd.dat – %WINDIR% \bk23567.dat It tries to download a file: – The locations are the following: • http://mm2dc.com/**********/?action=%character string% &v=%number% &crc=%number% • http://welovetweet.com/**********/?action=%character string% &v=%number% &crc=%number% • http://dentistschoice-fl.com/**********/?action=%character string% &v=%number% &crc=%number% • http://optimumorg.com/**********/?action=%character string% &v=%number% &crc=%number% • http://optimumorg.com/**********/?action=%character string% &mode=%character string% &age=%number% &a=%number% &v=%number% &crc=%number% &ie=%character string% • http://beautiteen.hostmaniacs.com/**********/?action=%character string% &v=%number% &crc=%number% • http://whoffmanchiro.com/**********/?action=%character string% &v=%number% &crc=%number% • http://pactivefranchises.com/**********/?action=%character string% &v=%number% &crc=%number% • http://mag5.kiev.ua/**********/?action=%character string% &v=%number% &crc=%number% • http://cia.gg/**********/?action=%character string% &v=%number% &crc=%number% • http://greystoneofellijay.com/**********/?action=%character string% &v=%number% &crc=%number% • http://ilivemusic.co.il/**********/?action=%character string% &v=%number% &crc=%number% • http://miltecit.co.uk/**********/?action=%character string% &v=%number% &crc=%number% It tries to executes the following files: – Filename: • %WINDIR% \freddy84.exe – Filename: • cmd /c %WINDIR% \dxxdv34567.bat – Filename: • regedit /s c:\2.reg Registry The following registry key is added: – [HKCR\Mime\Database\Content Type\application/xhtml+xml] • "CLSID"="{25336920-03F9-11cf-8FD0-00AA00686F13}" • "Encoding"=hex:08,00,00,00 • "Extension"=".xml" Miscellaneous Checks for an internet connection by contacting the following web site: • http://www.google.com File details Runtime packer: In order to aggravate detection and reduce size of the file it is packed with a runtime packer.
Description inserted by Petre Galan on Wednesday, April 7, 2010 Description updated by Petre Galan on Wednesday, April 7, 2010
Back
.
.
.
.