Virus: Worm/Dorkbot.A.387 Date discovered: 20/07/2011 Type: Worm In the wild: Yes Reported Infections: Low Distribution Potential: Medium Damage Potential: Medium Static file: Yes File size: 179.712 Bytes MD5 checksum: 53422FC023412D12C429B6289F5075BC VDF version: 7.11.12.21 - Wednesday, July 20, 2011IVDF version: 7.11.12.21 - Wednesday, July 20, 2011
General Method of propagation: • Autorun feature • Email • Messenger Aliases: • Kaspersky: Trojan.Win32.Jorik.IRCbot.aha • TrendMicro: TROJ_SPNR.02GB11 • Sophos: Mal/VBCheMan-A Platforms / OS: • Windows 2000 • Windows XP • Windows 2003 • Windows Vista • Windows 7 Side effects: • Third party control • Blocks access to security websites • Drops files • Registry modification • Steals information Files It copies itself to the following location: • %APPDATA%\%random character string% .exe It deletes the initially executed copy of itself. Registry To each registry key one of the values is added in order to run the processes after reboot: – [HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Run] • "%random character string% "="%APPDATA%\%random character string% .exe" – [HKEY_USERS\.DEFAULT\Software\Microsoft\Windows\CurrentVersion\Run] • "%random character string% "="%APPDATA%\%random character string% .exe" – [HKCU\Software\Microsoft\Windows\CurrentVersion\Run] • "%random character string% "="%APPDATA%\%random character string% .exe" – [HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\system] • "Shell"="explorer.exe,%APPDATA%\%random character string% .exe" – [HKCU\Software\Microsoft\Windows\CurrentVersion\Policies\System] • "Shell"="explorer.exe,%APPDATA%\%random character string% .exe" Messenger It is spreading via Messenger. The characteristics are described below: – Windows Live Messenger – Yahoo Messenger IRC To deliver system information and to provide remote control it connects to the following IRC Servers: Server: **********.photomarket.me Port: 1234 Channel: #ngr Nickname: %random character string% – This malware has the ability to collect and send information such as: • Current user • Username • Information about the Windows operating system – Furthermore it has the ability to perform actions such as: • connect to IRC server • Launch DDoS SYN flood • Launch DDoS UDP flood • disconnect from IRC server • Download file • Join IRC channel • Leave IRC channel • Perform DDoS attack • Restart system • Start spreading routine Stealing It tries to steal the following information: – Passwords typed into 'password input fields' – A logging routine is started after the following website is visited, which contains one of the following substrings in the URL: • .moneybookers.; 1and1.com; 4shared.com; alertpay.com; aol.; bcointernacional; bigstring.; depositfiles.; dotster.com; dyndns; enom.com; facebook.; fastmail.; fileserv.com; filesonic.com; freakshare.com; gmx.; godaddy.com; google.; hackforums.; hotfile.com; letitbit.net; login.live.; login.yahoo.; mediafire.com; megaupload.; members*.iknowthatgirl; members.brazzers.com; moniker.com; namecheap.com; netflix.com; netload.in; no-ip; officebanking.cl; oron.com; paypal.; runescape; screenname.aol.; secure.logmein.; sendspace.com; signin.ebay; sms4file.com; speedyshare.com; steampowered; thepiratebay.org; torrentleech.org; twitter.com; uploaded.to; uploading.com; vip-file.com; webnames.ru; what.cd; whcms; youporn. – It captures: • Login information Injection – It injects itself as a remote thread into processes. All of the following processes: • alg.exe; chrome.exe; csrss.exe; explorer.exe; firefox.exe; flock.exe; ieuser.exe; iexplore.exe; msmsgs.exe; msnmsgr.exe; opera.exe; pidgin.exe; services.exe; smss.exe; spoolsv.exe; svchost.exe; winlogon.exe; wlcomm.exe; wuauclt.exe; %random process% Purpose: Access to the following websites is effectively blocked: • *avast.*; *avira.*; *bitdefender.*; *bullguard.*; *clamav.*; *comodo.*; *emsisoft.*; *eset.*; *f-secure.*; *fortinet.*; *garyshood.*; *gdatasoftware.*; *heck.tc*; *iseclab.*; *jotti.*; *kaspersky.*; *lavasoft.*; *malwarebytes.*; *mcafee.*; *norman.*; *norton.*; *novirusthanks.*; *onecare.live.*; *onlinemalwarescanner.*; *pandasecurity.*; *precisesecurity.*; *sophos.*; *sunbeltsoftware.*; *symantec*; *threatexpert.*; *trendmicro.*; *virscan.*; *virus.*; *virusbuster.nprotect.*; *viruschief.*; *virustotal.*; *webroot.* Miscellaneous Accesses internet resources: • api.wipmania.com Mutex: It creates the following Mutex: • paraboner-Mutex File details Runtime packer: In order to aggravate detection and reduce size of the file it is packed with a runtime packer.
Description inserted by Andrei Ilie on Thursday, August 18, 2011 Description updated by Andrei Ilie on Thursday, August 18, 2011
Back
.
.
.
.