English
Deutsch
Francais
Español
Italian
Home
Virus Info
Worm/Biatch
Search
Home
Support
Solutions
Products
Downloads
Virus Info
Statistics
Phishing Worldmap
VDF History
Virus Science
Submit Sample
Security News
Viruses In the Wild
Company
Press
Partners
Newsletter
Worm/Biatch - Worm
See also
Summary
Full description
Statistics
How would you rate this information?
Worthless
Excellent
Virus:
Worm/Biatch
Date discovered:
17/01/2006
Type:
Worm
In the wild:
No
Reported Infections:
Low
Distribution Potential:
Medium
Damage Potential:
Medium
Static file:
Yes
File size:
20.480 Bytes
MD5 checksum:
d9c745ef21721938fd44b8bf85717b8c
General
Method of propagation:
• Local network
Aliases:
• Mcafee: W32/Pinom.worm!backdoor
• TrendMicro: WORM_PINOM.A
• Bitdefender: Win32.Worm.Pinom.G
Platforms / OS:
• Windows 95
• Windows 98
• Windows 98 SE
• Windows NT
• Windows ME
• Windows 2000
• Windows XP
• Windows 2003
Side effects:
• Registry modification
• Third party control
Files
It copies itself to the following location:
•
%SYSDIR%
\penis.exe
Registry
The following registry key is changed:
– [HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon]
Old value:
• "Shell"="Explorer.exe"
New value:
• "Shell"="Explorer.exe
%SYSDIR%
\penis.exe"
Network Infection
In order to ensure its propagation the malware attemps to connect to other machines as described below.
It drops a copy of itself to the following network share:
•
%all shared folders%
\setup.exe
It uses the following login information in order to gain access to the remote machine:
– A list of usernames and passwords:
• 1234; 0; 7; 110; 111; 123; 1111; 1313; 2002; 2003; 2112; 2600; 5150;
6969; 7777; 12345; 54321; 111111; 121212; 123123; 123456; 654321;
901100; 1234567; 11111111; 12345678; 88888888; 123456789; 1234qwer;
123abc; 123asd; 123qwe; aaa; abc; abc123; abcd; admin; Admin;
admin123; administrator; Administrator; alpha; asdf; baseball; ccc;
computer; database; enable; fish; foobar; god; godblessyou; golf;
Guest; harley; home; ihavenopass; Internet; letmein; login; Login;
love; mustang; mypass; mypass123; mypc; mypc123; oracle'pwd; owner;
Owner; pass; passwd; password; Password; pat; patrick; pussy; pw123;
qwer; qwerty; root; Root; secret; server; sex; shadow; super; sybase;
temp; temp123; test; test123; win; xxx; yxcv; zxcv
IP address generation:
It creates random IP addresses and tries to establish a connection with them.
Remote execution:
–It attempts to schedule a remote execution of the malware, on the newly infected machine. Therefore it uses the NetScheduleJobAdd function.
IRC
To deliver system information and to provide remote control it connects to the following IRC Server:
Server: genesis.ga**********.us
Port: 6667
Channel: #peniz
Nickname:
%random character string%
Password: pubic
– Furthermore it has the ability to perform actions such as:
• Download file
• Execute file
• Perform DDoS attack
• Terminate malware
• Updates itself
• Visit a website
File details
Programming language:
The malware program was written in Delphi.
Runtime packer:
In order to aggravate detection and reduce size of the file it is packed with the following runtime packer:
• UPX
See a brief description
here
.
Description inserted by Iulia Diaconescu on Wed, 18 Jan 2006 11:54 (GMT+1)
Description updated by Andrei Gherman on Tue, 24 Jan 2006 12:57 (GMT+1)
»
About Malware
»
About Phishing
»
Viruses In the Wild
« back
Print this page
Worm/Mytob.AT
Worm/Mytob.U
TR/Crypt.CFI.Gen
Worm/Netsky.J
Worm/Mytob.AD
HEUR/PDF.Obfuscated
SPR/mIRC.Gen
TR/Crypt.UPKM.Gen
JS/Dldr.Agent.cex
TR/Dldr.Tiny.bqw
Get comfortable up to the minute info from Avira as
Detects and removes the following malware and its variants:
Worm/Sober.J
Worm/Sober.P
Worm/Sober.Y
W32/Stanit.A
Worm/NetSky.AA
Worm/NetSky.B.1
Worm/NetSky.C
Worm/Netsky.D.Dam
Worm/NetSky.P
Worm/NetSky.X
Worm/Mytob.IN.2
Worm/Mytob.KS
TR/Spy.Banker.AATZ
TR/Spy.Banker.AATZ.1
TR/Spy.Banker.AATZ.2
TR/Spy.Banker.AATZ.3
Download here
Click
here
to get the panel...
© 2008 Avira GmbH
Copyright
Privacy
Sitemap
Feedback
Imprint
FAQ
Contact