Virus: Worm/Dorkbot.A.391 Date discovered: 20/07/2011 Type: Worm In the wild: Yes Reported Infections: Low Distribution Potential: Medium Damage Potential: Medium Static file: Yes File size: 188.416 Bytes MD5 checksum: 5F5C9C0C0454F94C9A942623233449AD VDF version: 7.11.12.21 - Wednesday, July 20, 2011IVDF version: 7.11.12.21 - Wednesday, July 20, 2011
General Method of propagation: • Autorun feature • Email • Messenger Aliases: • TrendMicro: BKDR_RUSKILL.IW • Sophos: Troj/DorkBot-I • Microsoft: Worm:Win32/Dorkbot.A Platforms / OS: • Windows 2000 • Windows XP • Windows 2003 • Windows Vista • Windows 7 Side effects: • Third party control • Blocks access to security websites • Drops files • Registry modification • Steals information Files It copies itself to the following location: • %APPDATA%\%random character string% .exe It deletes the initially executed copy of itself. Registry One of the following values is added in order to run the process after reboot: – [HKCU\Software\Microsoft\Windows\CurrentVersion\Run] • "%random character string% "="%APPDATA%\%random character string% .exe" Messenger It is spreading via Messenger. The characteristics are described below: – Windows Live Messenger – Yahoo Messenger IRC To deliver system information and to provide remote control it connects to the following IRC Servers: Server: **********ta.servebeer.com Port: %number% Server password: ngrBot Channel: #DarkSons-01# Nickname: %random character string% Server: **********o.dukatlgg.com Port: %number% Server password: ngrBot Channel: #DarkSons-01# Nickname: %random character string% Server: **********azin.zavoddebila.com Port: %number% Server password: ngrBot Channel: #DarkSons-01# Nickname: %random character string% Server: **********ea.dukatlgg.com Port: %number% Server password: ngrBot Channel: #DarkSons-01# Nickname: %random character string% Server: **********bck0.vadi-ga-van.info Port: %number% Server password: ngrBot Channel: #DarkSons-01# Nickname: %random character string% Server: **********bck1.turisticka-agencija-reality.co.cc Port: %number% Server password: ngrBot Channel: #DarkSons-01# Nickname: %random character string% Server: **********bck2.saintgroup.co.za Port: %number% Server password: ngrBot Channel: #DarkSons-01# Nickname: %random character string% – This malware has the ability to collect and send information such as: • Current user • Username • Information about the Windows operating system – Furthermore it has the ability to perform actions such as: • connect to IRC server • Launch DDoS SYN flood • Launch DDoS UDP flood • disconnect from IRC server • Download file • Join IRC channel • Leave IRC channel • Perform DDoS attack • Restart system • Start spreading routine Stealing It tries to steal the following information: – Passwords typed into 'password input fields' – A logging routine is started after the following website is visited, which contains one of the following substrings in the URL: • .moneybookers.; 1and1.com; 4shared.com; alertpay.com; aol.; bcointernacional; bigstring.; depositfiles.; dotster.com; dyndns; enom.com; facebook.; fastmail.; fileserv.com; filesonic.com; freakshare.com; gmx.; godaddy.com; google.; hackforums.; hotfile.com; letitbit.net; login.live.; login.yahoo.; mediafire.com; megaupload.; members*.iknowthatgirl; members.brazzers.com; moniker.com; namecheap.com; netflix.com; netload.in; no-ip; officebanking.cl; oron.com; paypal.; runescape; screenname.aol.; secure.logmein.; sendspace.com; signin.ebay; sms4file.com; speedyshare.com; steampowered; thepiratebay.org; torrentleech.org; twitter.com; uploaded.to; uploading.com; vip-file.com; webnames.ru; what.cd; whcms; youporn. – It captures: • Login information Injection – It injects itself as a remote thread into processes. All of the following processes: • alg.exe; chrome.exe; csrss.exe; explorer.exe; firefox.exe; flock.exe; ieuser.exe; iexplore.exe; msmsgs.exe; msnmsgr.exe; opera.exe; pidgin.exe; services.exe; smss.exe; spoolsv.exe; svchost.exe; winlogon.exe; wlcomm.exe; wuauclt.exe; %random process% Purpose: Access to the following websites is effectively blocked: • *avast.*; *avira.*; *bitdefender.*; *bullguard.*; *clamav.*; *comodo.*; *emsisoft.*; *eset.*; *f-secure.*; *fortinet.*; *garyshood.*; *gdatasoftware.*; *heck.tc*; *iseclab.*; *jotti.*; *kaspersky.*; *lavasoft.*; *malwarebytes.*; *mcafee.*; *norman.*; *norton.*; *novirusthanks.*; *onecare.live.*; *onlinemalwarescanner.*; *pandasecurity.*; *precisesecurity.*; *sophos.*; *sunbeltsoftware.*; *symantec*; *threatexpert.*; *trendmicro.*; *virscan.*; *virus.*; *virusbuster.nprotect.*; *viruschief.*; *virustotal.*; *webroot.* Miscellaneous Accesses internet resources: • api.wipmania.com Mutex: It creates the following Mutex: • aciCty21CAjoSS8o
Description inserted by Andrei Ilie on Friday, August 19, 2011 Description updated by Andrei Ilie on Monday, August 22, 2011
Back
.
.
.
.