Virus: Worm/Warezov.DLL.C Date discovered: 22/09/2006 Type: Worm In the wild: Yes Reported Infections: Low Distribution Potential: Medium Damage Potential: Low to medium Static file: Yes File size: 153.128 Bytes MD5 checksum: 6d5b6945f50dc801208525936d5c24b9 VDF version: 6.36.00.50 IVDF version: 6.36.00.61 - Tuesday, September 26, 2006
General Method of propagation: • Email Aliases: • Mcafee: W32/Stration@MM • Kaspersky: Email-Worm.Win32.Warezov.ab • TrendMicro: WORM_STRATION.BC • F-Secure: Email-Worm.Win32.Warezov.ab • Eset: Win32/Stration.AR Platforms / OS: • Windows 98 • Windows 98 SE • Windows NT • Windows ME • Windows 2000 • Windows XP • Windows 2003 Side effects: • Blocks access to security websites • Drops malicious files • Uses its own Email engine • Lowers security settings • Registry modification Right after execution the following information is displayed: Files It copies itself to the following location: • %WINDIR% \tsrv.exe The following files are created: – A file that contains collected email addresses: • %WINDIR% \tsrv.wax – %HOME%\Desktop\%two-digit random character string% .tmp This is a non malicious text file with the following content: • %random character string% – %SYSDIR% \msji449c14b7.dll Further investigation pointed out that this file is malware, too. Detected as: Worm/Stration – %SYSDIR% \cmut449c14b7.dll Further investigation pointed out that this file is malware, too. Detected as: Worm/Warezov.AB – %SYSDIR% \hpzl449c14b7.exe Further investigation pointed out that this file is malware, too. Detected as: Worm/Warezov.AB.2 – %WINDIR% \tsrv.dll Further investigation pointed out that this file is malware, too. Detected as: Worm/Warezov.AB.1 Registry The following registry key is added in order to run the process after reboot: – [HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Run] • "tsrv"="%WINDIR% \tsrv.exe s" The following registry key is changed: – [HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Windows] Old value: • "AppInit_DLLs"="" New value: • "AppInit_DLLs"=" msji449c14b7.dll" Email It contains an integrated SMTP engine in order to send emails. A direct connection with the destination server will be established. The characteristics are described in the following: From: The sender address is spoofed. Generated addresses. Please do not assume that it was the sender's intention to send this email to you. He might not know about his infection or might not even be infected at all. Furthermore it is possible that you will receive bounced emails telling you that you are infected. This might also not be the case. To: – Email addresses found in specific files on the system. – Email addresses gathered from WAB (Windows Address Book) – Generated addresses Email design: From: sec@%recipient's domain% Subject: Mail server report. Body: • Mail server report. Our firewall determined the e-mails containing worm copies are being sent from your computer. Nowadays it happens from many computers, because this is a new virus type (Network Worms). Using the new bug in the Windows, these viruses infect the computer unnoticeably. After the penetrating into the computer the virus harvests all the e-mail addresses and sends the copies of itself to these e-mail addresses Please install updates for worm elimination and your computer restoring. Best regards, Customers support service Attachment: • Update-KB%number% -x86.exe From: secur@%recipient's domain% Subject: Mail server report. Body: • Mail server report. Our firewall determined the e-mails containing worm copies are being sent from your computer. Nowadays it happens from many computers, because this is a new virus type (Network Worms). Using the new bug in the Windows, these viruses infect the computer unnoticeably. After the penetrating into the computer the virus harvests all the e-mail addresses and sends the copies of itself to these e-mail addresses Please install updates for worm elimination and your computer restoring. Best regards, Customers support service Attachment: • Update-KB%number% -x86.exe From: serv@%recipient's domain% Subject: Mail server report. Body: • Mail server report. Our firewall determined the e-mails containing worm copies are being sent from your computer. Nowadays it happens from many computers, because this is a new virus type (Network Worms). Using the new bug in the Windows, these viruses infect the computer unnoticeably. After the penetrating into the computer the virus harvests all the e-mail addresses and sends the copies of itself to these e-mail addresses Please install updates for worm elimination and your computer restoring. Best regards, Customers support service Attachment: • Update-KB%number% -x86.exe Subject: One of the following: • Error • Good day • hello • Mail Delivery System • Mail Transaction Failed • picture • Server Report • Status • test Body: The body of the email is one of the following: • Mail transaction failed. Partial message is available. • The message cannot be represented in 7-bit ASCII encoding and has been sent as a binary attachment • The message contains Unicode characters and has been sent as a binary attachment. Attachment: The filenames of the attachments is constructed out of the following: – It starts with one of the following: • body • data • doc • docs • document • file • message • readme • test • text Continued by one of the following fake extensions: • .elm • .msg • .dat • .txt • .log The file extension is one of the following: • .bat • .exe • .scr • .cmd • .pif The attachment is a copy of the malware itself. The email may look like one of the following: Hosts The host file is modified as explained: – In this case already existing entries remain unmodified. – Access to the following domains is effectively blocked: • download.microsoft.com; go.microsoft.com; msdn.microsoft.com; office.microsoft.com; windowsupdate.microsoft.com; http://www.microsoft.com/downloads/Search.aspx?displaylang=en; avp.ru; www.avp.ru; http://avp.ru; http://www.avp.ru; kaspersky.ru; www.kaspersky.ru; http://kaspersky.ru; kaspersky.com; www.kaspersky.com; http://kaspersky.com; kaspersky-labs.com; www.kaspersky-labs.com; http://kaspersky-labs.com; avp.ru/download/; www.avp.ru/download/; http://www.avp.ru/download/; http://www.kaspersky.ru/updates/; http://www.kaspersky-labs.com/updates/; http://kaspersky.ru/updates/; http://kaspersky-labs.com/updates/; downloads1.kaspersky-labs.com; downloads2.kaspersky-labs.com; downloads3.kaspersky-labs.com; downloads4.kaspersky-labs.com; downloads5.kaspersky-labs.com; http://downloads1.kaspersky-labs.com; http://downloads2.kaspersky-labs.com; http://downloads3.kaspersky-labs.com; http://downloads4.kaspersky-labs.com; http://downloads5.kaspersky-labs.com; downloads1.kaspersky-labs.com/products/; downloads2.kaspersky-labs.com/products/; downloads3.kaspersky-labs.com/products/; downloads4.kaspersky-labs.com/products/; downloads5.kaspersky-labs.com/products/; http://downloads1.kaspersky-labs.com/products/; http://downloads2.kaspersky-labs.com/products/; http://downloads3.kaspersky-labs.com/products/; http://downloads4.kaspersky-labs.com/products/; http://downloads5.kaspersky-labs.com/products/; downloads1.kaspersky-labs.com/updates/; downloads2.kaspersky-labs.com/updates/; downloads3.kaspersky-labs.com/updates/; downloads4.kaspersky-labs.com/updates/; downloads5.kaspersky-labs.com/updates/; http://downloads1.kaspersky-labs.com/updates/; http://downloads2.kaspersky-labs.com/updates/; http://downloads3.kaspersky-labs.com/updates/; http://downloads4.kaspersky-labs.com/updates/; http://downloads5.kaspersky-labs.com/updates/; ftp://downloads1.kaspersky-labs.com; ftp://downloads2.kaspersky-labs.com; ftp://downloads3.kaspersky-labs.com; ftp://downloads4.kaspersky-labs.com; ftp://downloads5.kaspersky-labs.com; ftp://downloads1.kaspersky-labs.com/products/; ftp://downloads2.kaspersky-labs.com/products/; ftp://downloads3.kaspersky-labs.com/products/; ftp://downloads4.kaspersky-labs.com/products/; ftp://downloads5.kaspersky-labs.com/products/; ftp://downloads1.kaspersky-labs.com/updates/; ftp://downloads2.kaspersky-labs.com/updates/; ftp://downloads3.kaspersky-labs.com/updates/; ftp://downloads4.kaspersky-labs.com/updates/; ftp://downloads5.kaspersky-labs.com/updates/; http://updates.kaspersky-labs.com/updates/; http://updates1.kaspersky-labs.com/updates/; http://updates2.kaspersky-labs.com/updates/; http://updates3.kaspersky-labs.com/updates/; http://updates4.kaspersky-labs.com/updates/; ftp://updates.kaspersky-labs.com/updates/; ftp://updates1.kaspersky-labs.com/updates/; ftp://updates2.kaspersky-labs.com/updates/; ftp://updates3.kaspersky-labs.com/updates/; ftp://updates4.kaspersky-labs.com/updates/; viruslist.com; www.viruslist.com; http://viruslist.com; viruslist.ru; www.viruslist.ru; http://viruslist.ru; ftp://ftp.kasperskylab.ru/updates/; symantec.com; www.symantec.com; http://symantec.com; customer.symantec.com; http://customer.symantec.com; liveupdate.symantec.com; http://liveupdate.symantec.com; liveupdate.symantecliveupdate.com; http://liveupdate.symantecliveupdate.com; securityresponse.symantec.com; http://securityresponse.symantec.com; service1.symantec.com; http://service1.symantec.com; symantec.com/updates; http://symantec.com/updates; updates.symantec.com; http://updates.symantec.com; eset.com/; www.eset.com/; http://www.eset.com/; eset.com/products/index.php; www.eset.com/products/index.php; http://www.eset.com/products/index.php; eset.com/download/index.php; www.eset.com/download/index.php; http://www.eset.com/download/index.php; eset.com/joomla/; www.eset.com/joomla/; http://www.eset.com/joomla/; u3.eset.com/; http://u3.eset.com/; u4.eset.com/; http://u4.eset.com/; www.symantec.com/updates The modified host file will look like this: Injection – It injects the following file into a process: tsrv.dll Process name: • %all running processes% File details Programming language: The malware program was written in MS Visual C++. Runtime packer: In order to aggravate detection and reduce size of the file it is packed with the following runtime packer: • MEW
Descripción insertada por Adriana Popa el martes, 26 de septiembre de 2006 Descripción actualizada por Adriana Popa el martes, 26 de septiembre de 2006
Volver
.
.
.
.