Virus: Worm/Yahos.oq Date discovered: 01/02/2011 Type: Worm In the wild: No Reported Infections: Low to medium Distribution Potential: Low to medium Damage Potential: Low to medium Static file: Yes File size: 102.400 Bytes MD5 checksum: 128C152BDD7C4FBAD9987022F5790589 VDF version: 7.10.08.99 IVDF version: 7.11.02.40 - Tuesday, February 1, 2011
General Method of propagation: • Messenger Aliases: • Mcafee: W32/Sdbot.bfr!a • Kaspersky: IM-Worm.Win32.Yahos.oq • Sophos: Mal/Rimecud-D • Panda: W32/Lolbot.Q.worm • DrWeb: Win32.HLLW.Oscar.25 • Norman: W32/Slenfbot.T Platforms / OS: • Windows 2000 • Windows XP • Windows 2003 • Windows Vista • Windows Server 2008 • Windows 7 Side effects: • Drops a file • Lowers security settings • Records keystrokes • Registry modification • Opens website in web browser Files It copies itself to the following location: • %WINDIR% \nvsvc32.exe The following file is created: – Non malicious file: • %WINDIR% \ntdll.dl It tries to execute the following files: – Filename: • %SYSDIR% \net.exe – Filename: • %SYSDIR% \netsh.exe using the following command line arguments: firewall add allowedprogram 1.exe 1 ENABLE – Filename: • %SYSDIR% \ntvdm.exe using the following command line arguments: -f -i1 – Filename: • %SYSDIR% \ntvdm.exe using the following command line arguments: -f -i2 – Filename: • %SYSDIR% \sc.exe using the following command line arguments: config MsMpSvc start= disabled – Filename: • %WINDIR% \explorer.exe using the following command line arguments: http://browseusers.myspace.com/Browse/Browse.aspx Registry The following registry keys are added in order to run the processes after reboot: – [HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Run] • "NVIDIA driver monitor"="%WINDIR% \nvsvc32.exe" – [HKCU\Software\Microsoft\Windows\CurrentVersion\Run] • "NVIDIA driver monitor"="%WINDIR% \nvsvc32.exe" – [HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Terminal Server\ Install\Software\Microsoft\Windows\CurrentVersion\Run] • "NVIDIA driver monitor"="%WINDIR% \nvsvc32.exe" It creates the following entry in order to bypass the Windows XP firewall: – [HKLM\SYSTEM\ControlSet001\Services\SharedAccess\Parameters\ FirewallPolicy\StandardProfile\AuthorizedApplications\List] • "%malware execution directory% \%executed file% "="%WINDIR% \nvsvc32.exe:*:Enabled:NVIDIA driver monitor" The following registry keys are changed: – [HKCR\TypeLib\{1EA4DBF0-3C3B-11CF-810C-00AA00389B71}\1.1\0\win32] New value: • "(Default)"="oleacc.dll" Lower security settings from Internet Explorer: – [HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings\ ZoneMap] Old value: • "ProxyBypass"=%user defined settings% • "IntranetName"=%user defined settings% • "UNCAsIntranet"=%user defined settings% New value: • "ProxyBypass"=dword:00000001 • "IntranetName"=dword:00000001 • "UNCAsIntranet"=dword:00000001 – [HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\Internet Settings] Old value: • "MigrateProxy"=%user defined settings% • "ProxyEnable"=%user defined settings% • "ProxyServer"=%user defined settings% • "ProxyOverride"=%user defined settings% • "AutoConfigURL"=%user defined settings% New value: • "MigrateProxy"=dword:00000001 • "ProxyEnable"=dword:00000000 • "ProxyServer"=- • "ProxyOverride"=- • "AutoConfigURL"=- – [HKEY_CURRENT_CONFIG\Software\Microsoft\windows\CurrentVersion\ Internet Settings] Old value: • "ProxyEnable"=%user defined settings% New value: • "ProxyEnable"=dword:00000000 Messenger It is spreading via Messenger. The characteristics are described below: – Yahoo Messenger Message The sent message looks like the following: • hahahh Foto :D http://lprottsmanpw.com/********** At the time of analysis the file was not online anymore. IRC To deliver system information and to provide remote control it connects to the following IRC Server: Server: %IRC server% Port: 1234 Server password: xxx Channel: #!nn!********** Nickname: NEW-[GBR|00|**********|%random numbers% ] – Furthermore it has the ability to perform actions such as: • connect to IRC server • disconnect from IRC server • Join IRC channel • Leave IRC channel Miscellaneous Internet connection: It queries with the following names: • astro.ic.**********.uk • ale.pakibi**********.com • versat**********.com • journalofaccountan**********.com • transnatio**********.org • mas.0730**********.com • api.albertoshisto**********.info • browseusers.myspa**********.com • stayonti**********.info • www.shearm**********.com • www.myspa**********.com • insidehigher**********.net • websitetraffics**********.com • qun.5**********.com • summer-uni-sw.ee**********.ch • shopsty**********.com • xxx.stopklat**********.pl • x.myspace**********.com • unclef**********.com • mcsp.lvengi**********.com • deirdremcclosk**********.org • ftp.phoenix-**********.net • journals.**********.com • middleastpo**********.org • mas.archiv**********.info • scribbidyscru**********.com • mas.mti**********.com • ols.systemofado**********.com • mas.tgu**********.cl • albertoshisto**********.info • mas.josba**********.com • erdbeerloun**********.de • mas.juegosbakug**********.net • screenservi**********.com • xxx.jagdc**********.de • old.longjuyt2tug**********.com • heidegger.**********.net • southampton.**********.uk • ope.oaklandathleti**********.com • mix.price-erotske.**********.rs • uks.linked**********.com • opl.munin.**********.se • jb.a**********.org • mas.ahlamonta**********.com • mas.univie.**********.at • pru.landmin**********.org • epp.gunmabl**********.jp • mix.thenaturistcl**********.ro • old.you**********.com • goodrea**********.com • hrm.**********.edu • refugee-action.**********.uk • mmm.bolbalatru**********.org • pra.a**********.org • www.facebo**********.com Accesses internet resources: • http://browseusers.myspa**********.com/Browse/Browse.aspx; http://www.myspa**********.com/browse/people; http://www.myspa**********.com/help/browserunsupported; http://x.myspace**********.com/images/BrowserUpgrade/bg_infobox.jpg; http://x.myspace**********.com/modules/splash/static/img/cornersSheet.png; http://x.myspace**********.com/images/BrowserUpgrade/icon_information.gif; http://x.myspace**********.com/images/BrowserUpgrade/bg_browserSection.jpg; http://x.myspace**********.com/images/BrowserUpgrade/browserLogos_med.jpg; http://174.37.200.**********/config.php; http://www.facebo**********.com/home.php; http://www.facebo**********.com/login.php File details Programming language: The malware program was written in MS Visual C++. Compilation date: Date: 31/01/2011 Time: 12:55:06
Description inserted by Alexander Bauer on Wednesday, February 2, 2011 Description updated by Alexander Bauer on Wednesday, February 2, 2011
Back
.
.
.
.