Virus: WORM/Autorun.bfxr Date discovered: 27/04/2010 Type: Worm In the wild: Yes Reported Infections: Low to medium Distribution Potential: Low to medium Damage Potential: Low to medium Static file: Yes File size: 188.416 Bytes MD5 checksum: 89ba009b7619c36947602708f4af93db VDF version: 7.10.02.209 IVDF version: 7.10.06.225 - Tuesday, April 27, 2010
General Methods of propagation: • Autorun feature • Mapped network drives Aliases: • Symantec: W32.Gammima.AG • Kaspersky: Worm.Win32.AutoRun.bfxr • TrendMicro: Mal_Run-8 • Sophos: Mal/Taterf-B • Microsoft: Worm:Win32/Taterf.DL • AVG: Win32/NSAnti.J • Panda: W32/Lineage.LMP • PCTools: Malware.Gammima • Eset: Win32/PSW.OnLineGames.PLU • DrWeb: Trojan.PWS.Wsgame.13163 • Ikarus: Worm.Win32.AutoRun Platforms / OS: • Windows 2000 • Windows XP • Windows 2003 Side effects: • Lowers security settings • Downloads malicious files • Drops malicious files • Registry modification Files It copies itself to the following locations: • %SYSDIR% \cyban.exe • %drive% \abqj61fm.exe It deletes the initially executed copy of itself. The following files are created: – %drive% \autorun.inf This is a non malicious text file with the following content: • %code that runs malware% – %SYSDIR% \ieban0.dll Furthermore it gets executed after it was fully created. Further investigation pointed out that this file is malware, too. Detected as: TR/PSW.Magania.dcar – %SYSDIR% \cyban0.dll Furthermore it gets executed after it was fully created. Further investigation pointed out that this file is malware, too. Detected as: TR/PSW.Magania.dbzw – %SYSDIR% \nodabc.exe Further investigation pointed out that this file is malware, too. – %SYSDIR% \nodabc0.dll Further investigation pointed out that this file is malware, too. Detected as: TR/Crypt.ASPM.Gen – %SYSDIR% \nodie0.dll Further investigation pointed out that this file is malware, too. Detected as: TR/Crypt.ASPM.Gen It tries to download some files: – The location is the following: • http://www.googlecbm.com/1********** It is saved on the local hard drive under: %TEMPDIR% \ah1.rar – The location is the following: • http://www.yahookjh.com/1********** It is saved on the local hard drive under: %TEMPDIR% \ah.exe Registry The following registry key is added in order to run the process after reboot: – [HKCU\Software\Microsoft\Windows\CurrentVersion\Run] • "cybansos"="%SYSDIR% \cyban.exe" • "odsos"="%SYSDIR% \nodabc.exe" The following registry keys are added: – [HKLM\SOFTWARE\Classes\TypeLib\ {7F235922-8F2C-4C08-83A8-BBE01BF9CC64}\1.0\0\win32] • "@"="%SYSDIR% \ieban0.dll" – [HKLM\SOFTWARE\Classes\TypeLib\ {5DA7432B-6725-4ADE-BF17-C328743011FD}\1.0\0\win32] • "@"="%SYSDIR% \nodie0.dll" – [HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\ Browser Helper Objects\{7F23592B-8F2C-4C08-83A8-BBE01BF9CC64}] – [HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\ Browser Helper Objects\{5DA743EA-6725-4ADE-BF17-C328743011FD}] – [HKLM\SYSTEM\ControlSet001\Services\kmixer\Enum\0] • "@"="\"SW\{b7eafdc0-a680-11d0-96d8-00aa0051e51d}\{9B365890-165F-11D0-A195-0020AFD156E4}" – [HKLM\SYSTEM\CurrentControlSet\Services\kmixer\Enum\0] • "@"="SW\{b7eafdc0-a680-11d0-96d8-00aa0051e51d}\{9B365890-165F-11D0-A195-0020AFD156E4}" The following registry keys are changed: Various Explorer settings: – [HKU\S-1-5-21-2052111302-1336601894-725345543-1003\Software\ Microsoft\Windows\CurrentVersion\Explorer\Advanced\] Old value: • "ShowSuperHidden"=dword:00000001 New value: • "ShowSuperHidden"=dword:00000000 – [HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Advanced\ Folder\Hidden\SHOWALL] Old value: • "Hdden"=dword:000000001 New value: • "Hdden"=dword:000000002 Injection – It injects the following file into a process: %SYSDIR% \cyban0.dll Process name: • explorer.exe – It injects itself into a process. Process name: • iexplore.exe – It injects the following file into a process: %SYSDIR% \nodabc0.dll Process name: • explorer.exe File details Runtime packer: In order to aggravate detection and reduce size of the file it is packed with a runtime packer.
Description inserted by Alexandru Dinu on Wednesday, August 18, 2010 Description updated by Alexandru Dinu on Monday, August 23, 2010
Back
.
.
.
.