Virus: Worm/Koobface.NCL.7 Date discovered: 28/01/2010 Type: Worm In the wild: Yes Reported Infections: Low to medium Distribution Potential: Low to medium Damage Potential: Low to medium Static file: Yes File size: 62.976 Bytes MD5 checksum: 2348da8fdc70dd4423875c2e06c8fe85 IVDF version: 7.10.03.113 - Thursday, January 28, 2010
General Aliases: • Mcafee: Generic.dx • Sophos: Troj/Agent-MIA • Panda: W32/Koobface.HZ.worm • Eset: Win32/Koobface.NCL • Bitdefender: Worm.Generic.221244 Platforms / OS: • Windows 2000 • Windows XP • Windows 2003 Side effects: • Downloads a malicious file • Drops malicious files • Registry modification Files It copies itself to the following location: • %drive% \windows\freddy81.exe It overwrites the following files. – %WINDIR% \bk23567.dat – %WINDIR% \freddy81.exe It deletes the initially executed copy of itself. It deletes the following files: • %malware execution directory% \sd.dat • %WINDIR% \dxxdv34567.bat • %drive% \3.reg The following files are created: – %drive% \3.reg This is a non malicious text file with the following content: • %code that runs malware% – %drive% \windows\bk23567.dat – %malware execution directory% \sd.dat – %WINDIR% \dxxdv34567.bat Furthermore it gets executed after it was fully created. This batch file is used to delete a file. It tries to download a file: – The locations are the following: • http://almullahotels.com/**********/?action=%character string% &v=%number% &crc=%number% • http://www.tomsmassagepraxis.at/**********/?action=%character string% &v=%number% &crc=%number% • http://thyselius.tv/**********/?action=%character string% &v=%number% &crc=%number% • http://www.gecahe.com/**********/?action=%character string% &v=%number% &crc=%number% • http://advance.com.my/**********/?action=%character string% &v=%number% &crc=%number% • http://www.arketwood.com/**********/?action=%character string% &v=%number% &crc=%number% • http://feda-wien.at/**********/?action=%character string% &v=%number% &crc=%number% • http://e-autosystem.gr/**********/?action=%character string% &v=%number% &crc=%number% • http://www.chimera-crew.de/**********/?action=%character string% &v=%number% &crc=%number% • http://www.jallabyah.com/**********/?action=%character string% &v=%number% &crc=%number% • http://www.herangi.com/**********/?action=%character string% &v=%number% &crc=%number% It tries to executes the following files: – Filename: • %WINDIR% \freddy81.exe – Filename: • cmd /c %WINDIR% \dxxdv34567.bat – Filename: • regedit /s c:\3.reg Registry The following registry key is added: – [HKCR\Mime\Database\Content Type\application/xhtml+xml] • "CLSID"="{25336920-03F9-11cf-8FD0-00AA00686F13}" • "Encoding"=hex:08,00,00,00 • "Extension"=".xml" Miscellaneous Checks for an internet connection by contacting the following web site: • http://www.google.com File details Runtime packer: In order to aggravate detection and reduce size of the file it is packed with a runtime packer.
Description inserted by Petre Galan on Thursday, June 24, 2010 Description updated by Petre Galan on Thursday, June 24, 2010
Back
.
.
.
.