English
Deutsch
Español
Italian
Home
Virus Info
Worm/Sdbot.19212
Search
Home
Support
Solutions
Products
Downloads
Virus Info
Statistics
Phishing Worldmap
VDF History
Virus Science
Submit Sample
Security News
Viruses In the Wild
Company
Press
Partners
Newsletter
Worm/Sdbot.19212 - Worm
See also
Summary
Full description
Statistics
How would you rate this information?
Worthless
Excellent
Virus:
Worm/Sdbot.19212
Date discovered:
02/11/2006
Type:
Worm
In the wild:
No
Reported Infections:
Low
Distribution Potential:
Medium to high
Damage Potential:
Medium
Static file:
Yes
File size:
19.212 Bytes
MD5 checksum:
d810a7a72bb1b9ea13a691ae8f85353f
VDF version:
6.36.00.117
IVDF version:
6.36.00.134
- Thu, 19 Oct 2006 13:10 (GMT+1)
General
Methods of propagation:
• Local network
• Messenger
Aliases:
• Mcafee: W32/Sdbot.worm.gen.h
• Sophos: Mal/Behav-057
• Grisoft: BackDoor.Generic3.RZA
• Eset: Win32/IRCBot.UE
• Bitdefender: Generic.PWStealer.724E7E99
Platforms / OS:
• Windows 95
• Windows 98
• Windows 98 SE
• Windows NT
• Windows ME
• Windows 2000
• Windows XP
• Windows 2003
Side effects:
• Registry modification
• Makes use of software vulnerability
• Third party control
Files
It copies itself to the following location:
•
%SYSDIR%
\dllcache\updtftpini.exe
It deletes the initially executed copy of itself.
Registry
The following registry keys are added in order to load the service after reboot:
– [HKLM\SYSTEM\CurrentControlSet\Services\Microsoft windows FTPd\
Security]
• "Security"=
%hex values%
– [HKLM\SYSTEM\CurrentControlSet\Services\Microsoft windows FTPd]
• "Type"=dword:00000110
"Start"=dword:00000002
"ErrorControl"=dword:00000000
"ImagePath"="
%SYSDIR%
\dllcache\updtftpini.exe"
"DisplayName"="Microsoft windows FTPd"
"ObjectName"="LocalSystem"
"FailureActions"=
%hex values%
"Description"="Windows security FTPd update"
– [HKLM\SYSTEM\CurrentControlSet\Services\Microsoft windows FTPd\
Enum]
• "0"="Root\\LEGACY_MICROSOFT_WINDOWS_FTPD\\0000"
"Count"=dword:00000001
"NextInstance"=dword:00000001
The following registry keys are added:
– [HKLM\SYSTEM\CurrentControlSet\Enum\Root\
LEGACY_MICROSOFT_WINDOWS_FTPD]
• "NextInstance"=dword:00000001
– [HKLM\SYSTEM\CurrentControlSet\Enum\Root\
LEGACY_MICROSOFT_WINDOWS_FTPD\0000]
• "Service"="Microsoft windows FTPd"
• "Legacy"=dword:00000001
• "ConfigFlags"=dword:00000000
• "Class"="LegacyDriver"
• "ClassGUID"="{8ECC055D-047F-11D1-A537-0000F8753ED1}"
• "DeviceDesc"="Microsoft windows FTPd"
– [HKLM\SYSTEM\CurrentControlSet\Enum\Root\
LEGACY_MICROSOFT_WINDOWS_FTPD\0000\Control]
• "*NewlyCreated*"=dword:00000000
• "ActiveService"="Microsoft windows FTPd"
The following registry key is changed:
– [HKLM\SYSTEM\ControlSet001\Control\ServiceCurrent]
New value:
• @=dword:0000000d
Messenger
It is spreading via Messenger. The characteristics are described below:
– AIM Messenger
Network Infection
In order to ensure its propagation the malware attemps to connect to other machines as described below.
It drops copies of itself to the following network shares:
• C$
• D$
It uses the following login information in order to gain access to the remote machine:
–Cached usernames and passwords.
– A list of usernames and passwords:
• www; windows; web; visitor; test2; test1; test; temp; telnet; ruler;
remote; real; random; qwerty; public; pub; private; poiuytre;
password; passwd; passoracle; one; nopass; nobody; nick; newpass; new;
network; monitor; money; manager; mail; login; internet; install;
hello; guest; free; demo; default; debug; database; crew; computer;
coffee; bin; beta; backup; backdoor; anonymous; anon; alpha; adm;
access; abc123; abc; system; sys; super; sql; shit; shadow; setup;
security; secure; secret; 123456789; 12345678; 1234567; 123456; 12345;
1234; 123; 00000000; 0000000; 000000; 00000; 0000; 000; server;
asdfgh; admin; root
Exploit:
It makes use of the following Exploits:
–
MS02-061
(Elevation of Privilege in SQL Server Web)
–
MS04-007
(ASN.1 Vulnerability)
–
MS06-040
(Vulnerability in Server Service)
IP address generation:
It creates random IP addresses while it keeps the first two octets from its own address. Afterwards it tries to establish a connection with the created addresses.
Infection process:
Creates an FTP script on the compromised machine in order to download the malware to the remote location.
IRC
To deliver system information and to provide remote control it connects to the following IRC Server:
Server: freedoom.suicidegaming.**********
Port: 4512
Channel: #sm
Nickname: [
%number%
]USA|
%Windows version%
-SP
%number%
[P]
%six-digit random character string%
Password: 2pac
– This malware has the ability to collect and send information such as:
• Platform ID
• Information about the Windows operating system
– Furthermore it has the ability to perform actions such as:
• connect to IRC server
• Launch DDoS SYN flood
• disconnect from IRC server
• Download file
• Execute file
• Join IRC channel
• Leave IRC channel
• Perform network scan
• Perform port redirection
• Shut down system
• Start keylog
• Start spreading routine
• Updates itself
Backdoor
The following ports are opened:
–
%SYSDIR%
\dllcache\updtftpini.exe on a random TCP port in order to provide an FTP server.
–
%SYSDIR%
\dllcache\updtftpini.exe on a random TCP port in order to provide an HTTP server.
Miscellaneous
Mutex:
It creates the following Mutex:
• windxws
File details
Programming language:
The malware program was written in MS Visual C++.
Runtime packer:
In order to aggravate detection and reduce size of the file it is packed with a runtime packer.
See a brief description
here
.
Description inserted by Monica Ghitun on Thu, 02 Nov 2006 16:02 (GMT+1)
Description updated by Monica Ghitun on Tue, 21 Nov 2006 15:04 (GMT+1)
»
About Malware
»
About Phishing
»
Viruses In the Wild
« back
Print this page
W32/Elkern.C
TR/Crypt.CFI.Gen
Worm/KillAV.GR
Worm/Mytob.AP
Worm/Mytob.AT
TR/Crypt.PEPM.Gen
TR/Vundo.ewz.9
TR/Monderb.318720
Worm/IrcBot.39673.1
TR/PSW.Steam.DU
Get comfortable up to the minute info from Avira as
Detects and removes the following malware and its variants:
Worm/Sober.J
Worm/Sober.P
Worm/Sober.Y
W32/Stanit.A
Worm/NetSky.AA
Worm/NetSky.B.1
Worm/NetSky.C
Worm/Netsky.D.Dam
Worm/NetSky.P
Worm/NetSky.X
Worm/Mytob.IN.2
Worm/Mytob.KS
TR/Spy.Banker.AATZ
TR/Spy.Banker.AATZ.1
TR/Spy.Banker.AATZ.2
TR/Spy.Banker.AATZ.3
Download here
Click
here
to get the panel...
© 2008 Avira GmbH
Copyright
Privacy
Sitemap
Feedback
Imprint
FAQ
Contact