Virus: Worm/IRCBot.aak Date discovered: 19/07/2007 Type: Worm In the wild: Yes Reported Infections: Low Distribution Potential: Low to medium Damage Potential: Medium Static file: Yes File size: 75.549 Bytes MD5 checksum: 4629915b7e40dddedf7deeb07ced5784 VDF version: 6.39.00.34 - Tue, 19 Jun 2007 16:00 (GMT+1) IVDF version: 6.39.00.34 - Tue, 19 Jun 2007 16:00 (GMT+1)
General Method of propagation: • Email Aliases: • Mcafee: W32/Sdbot.worm.gen.l • Kaspersky: Backdoor.Win32.IRCBot.aak • F-Secure: Backdoor.Win32.IRCBot.aak • Panda: Trj/Mailbot.CE • Eset: Win32/IRCBot.XN • Bitdefender: Backdoor.RBot.BTK Platforms / OS: • Windows 95 • Windows 98 • Windows 98 SE • Windows NT • Windows ME • Windows 2000 • Windows XP • Windows 2003 Side effects: • Drops malicious files • Uses its own Email engine • Registry modification Files It copies itself to the following location: • %SYSDIR% \mdmd.exe It deletes the initially executed copy of itself. The following file is created: – %SYSDIR% \helpermdmd.exe Furthermore it gets executed after it was fully created. Detected as: TR/Proxy.Slaper.E.51 Registry The following registry keys are added in order to run the processes after reboot: – [HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Run] • "melg34"="%SYSDIR% \mdmd.exe" – [HKCU\Software\Microsoft\Windows\CurrentVersion\Run] • "melg34"="%SYSDIR% \mdmd.exe" Backdoor Contact server: The following: • l4.penny**********:24104 As a result it may send information and remote control could be provided. Remote control capabilities: • Send emails File details Programming language: The malware program was written in MS Visual C++. See a brief description here . Description inserted by Ana Maria Niculescu on Wed, 03 Oct 2007 15:59 (GMT+1) Description updated by Ana Maria Niculescu on Thu, 04 Oct 2007 14:51 (GMT+1)