Virus: WORM/Dorkbot.A.184 Date discovered: 09/06/2011 Type: Worm In the wild: No Reported Infections: Low Distribution Potential: Medium Damage Potential: Medium Static file: Yes File size: 236.544 Bytes MD5 checksum: A8C24BE57021EDE8CB5C52EBF41022A3 VDF version: 7.11.09.122 - Thursday, June 9, 2011IVDF version: 7.11.09.122 - Thursday, June 9, 2011
General Method of propagation: • Autorun feature • Email • Messenger Aliases: • Kaspersky: Trojan.Win32.VBKrypt.deqp • TrendMicro: WORM_DORKBOT.AKO • Microsoft: Worm:Win32/Dorkbot Platforms / OS: • Windows 2000 • Windows XP • Windows 2003 • Windows Vista • Windows 7 Side effects: • Third party control • Blocks access to security websites • Drops files • Registry modification • Steals information Files It copies itself to the following location: • %APPDATA%\%random character string% .exe It deletes the initially executed copy of itself. Registry The following registry keys are added in order to run the processes after reboot: – [HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\system] • "Shell"="explorer.exe,%APPDATA%\%random character%.exe" – [HKCU\Software\Microsoft\Windows\CurrentVersion\Policies\System] • "Shell"="explorer.exe,%APPDATA%\%random character%.exe" To each registry key one of the values is added in order to run the processes after reboot: – [HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Run] • "%random character%"="%APPDATA%\%random character%.exe" – [HKEY_USERS\.DEFAULT\Software\Microsoft\Windows\CurrentVersion\Run] • "%random character%"="%APPDATA%\%random character%.exe" – [HKCU\Software\Microsoft\Windows\CurrentVersion\Run] • "%random character%"="%APPDATA%\%random character%.exe" Messenger It is spreading via Messenger. The characteristics are described below: – Windows Live Messenger – Yahoo Messenger IRC To deliver system information and to provide remote control it connects to the following IRC Servers: Server: **********.photomarket.me Port: 1234 Nickname: %random character string% – This malware has the ability to collect and send information such as: • Current user • Username • Information about the Windows operating system – Furthermore it has the ability to perform actions such as: • connect to IRC server • Launch DDoS SYN flood • Launch DDoS UDP flood • disconnect from IRC server • Download file • Join IRC channel • Leave IRC channel • Perform DDoS attack • Restart system • Start spreading routine Stealing It tries to steal the following information: – Passwords typed into 'password input fields' – A logging routine is started after the following website is visited, which contains one of the following substrings in the URL: • .moneybookers.; 1and1.com; 4shared.com; alertpay.com; aol.; bcointernacional; bigstring.; depositfiles.; dotster.com; dyndns; enom.com; facebook.; fastmail.; fileserv.com; filesonic.com; freakshare.com; gmx.; godaddy.com; google.; hackforums.; hotfile.com; letitbit.net; login.live.; login.yahoo.; mediafire.com; megaupload.; members*.iknowthatgirl; members.brazzers.com; moniker.com; namecheap.com; netflix.com; netload.in; no-ip; officebanking.cl; oron.com; paypal.; runescape; screenname.aol.; secure.logmein.; sendspace.com; signin.ebay; sms4file.com; speedyshare.com; steampowered; thepiratebay.org; torrentleech.org; twitter.com; uploaded.to; uploading.com; vip-file.com; webnames.ru; what.cd; whcms; youporn. – It captures: • Login information Injection – It injects itself as a remote thread into processes. All of the following processes: • alg.exe; chrome.exe; csrss.exe; explorer.exe; firefox.exe; flock.exe; ieuser.exe; iexplore.exe; msmsgs.exe; msnmsgr.exe; opera.exe; pidgin.exe; services.exe; smss.exe; spoolsv.exe; svchost.exe; winlogon.exe; wlcomm.exe; wuauclt.exe; %random process% Purpose: Access to the following websites is effectively blocked: • *avast.*; *avira.*; *bitdefender.*; *bullguard.*; *clamav.*; *comodo.*; *emsisoft.*; *eset.*; *f-secure.*; *fortinet.*; *garyshood.*; *gdatasoftware.*; *heck.tc*; *iseclab.*; *jotti.*; *kaspersky.*; *lavasoft.*; *malwarebytes.*; *mcafee.*; *norman.*; *norton.*; *novirusthanks.*; *onecare.live.*; *onlinemalwarescanner.*; *pandasecurity.*; *precisesecurity.*; *sophos.*; *sunbeltsoftware.*; *symantec*; *threatexpert.*; *trendmicro.*; *virscan.*; *virus.*; *virusbuster.nprotect.*; *viruschief.*; *virustotal.*; *webroot.* Miscellaneous Accesses internet resources: • api.wipmania.com File details Programming language: The malware program was written in MS Visual C++.
Description inserted by Andrei Ilie on Friday, September 30, 2011 Description updated by Andrei Ilie on Tuesday, October 4, 2011
Back
.
.
.
.