Nome del virus: VBS/Small.Sasan.A Scoperto: 08/11/2007 Tipo: Worm In circolazione (ITW): No Numero delle infezioni segnalate: Basso Potenziale di propagazione: Medio-Basso Potenziale di danni: Medio-Basso File statico: Si Dimensione del file: 10.164 Byte Somma di controllo MD5: efe528483fd3c6ed75a8c1e016026e10 Versione VDF: 7.00.00.185 Versione IVDF: 7.00.00.192 - giovedì 8 novembre 2007
Generale Metodo di propagazione: • Unità di rete mappata Alias: • Sophos: VBS/Sasan-Fam • Grisoft: VBS/LoveLetter Piattaforme / Sistemi operativi: • Windows 95 • Windows 98 • Windows 98 SE • Windows NT • Windows ME • Windows 2000 • Windows XP • Windows 2003 Effetti secondari: • Disattiva le applicazioni di sicurezza • Duplica un file • Modifica del registro Giusto dopo l'esecuzione, avvia un'applicazione Windows che visualizzerà la seguente finestra: Merlin: Huh..Banjarbaru makin panas aja ya Merlin: It's now time to work. Jangan ngerumpi mulu.. Merlin: Hope you enjoy today. Merlin: Komputernya ta dinginin dulu OK Merlin: Cape dech, Bye Bye Ahh! File Si copia alle seguenti posizioni: • %sysdir%\ctfmon.exe.vbe • %unità disco% \Thumbs.db.vbe • %unità disco% \%file cancellato% .vbe Viene ricercata la seguente directory: • %unità disco% \ Occorre fare attenzione ai seguenti tipi di file: • .doc • .docx • .xls • .ppt • .jpg • .bmp • .3gp • .rm In seguito viene eliminato il file originale. Viene creato il seguente file: – %unità disco% \autorun.inf Questo è un file di testo “non maligno” con il seguente contenuto: • [autorun] shellexecute=wscript.exe Thumbs.db.vbe Prova ad eseguire il seguente file: – Nome del file: • %sysdir%\cmd.exe utilizzando i seguenti parametri: shutdown -s -t 00 -f -m Registro Viene aggiunta nel registro la seguente chiave con lo scopo di eseguire il processo dopo il riavvio: – [HKLM\Software\Microsoft\Windows\CurrentVersion\Run] • CTFMon="%sysdir%\ctfmon.exe.vbe" Vengono aggiunte le seguenti chiavi di registro: – [HKCU\Software\Microsoft\Windows\CurrentVersion\Policies\Explorer\ Advanced] • Hidden=dword:00000002 – [HKLM\Software\Microsoft\Windows NT\CurrentVersion\ Image File Execution Options\cmd.exe] • Debugger="notepad.exe" – [HKLM\Software\Microsoft\Windows NT\CurrentVersion\ Image File Execution Options\install.exe] • Debugger="notepad.exe" – [HKLM\Software\Microsoft\Windows NT\CurrentVersion\ Image File Execution Options\msconfig.exe] • Debugger="notepad.exe" – [HKLM\Software\Microsoft\Windows NT\CurrentVersion\ Image File Execution Options\regedit.exe] • Debugger="notepad.exe" – [HKLM\Software\Microsoft\Windows NT\CurrentVersion\ Image File Execution Options\AVG Free.exe] • Debugger="notepad.exe" – [HKLM\Software\Microsoft\Windows NT\CurrentVersion\ Image File Execution Options\regedt32.exe] • Debugger="notepad.exe" – [HKLM\Software\Microsoft\Windows NT\CurrentVersion\ Image File Execution Options\RegistryEditor.exe] • Debugger="notepad.exe" – [HKLM\Software\Microsoft\Windows NT\CurrentVersion\ Image File Execution Options\setup.exe] • Debugger="notepad.exe" – [HKLM\Software\Microsoft\Windows NT\CurrentVersion\ Image File Execution Options\setup32.exe] • Debugger="notepad.exe" – [HKLM\Software\Microsoft\Windows NT\CurrentVersion\ Image File Execution Options\AVG 7.5.exe] • Debugger="notepad.exe" – [HKLM\Software\Microsoft\Windows NT\CurrentVersion\ Image File Execution Options\rstrui.exe] • Debugger="notepad.exe" – [HKLM\Software\Microsoft\Windows NT\CurrentVersion\ Image File Execution Options\PCMAV.exe] • Debugger="notepad.exe" – [HKLM\Software\Microsoft\Windows NT\CurrentVersion\ Image File Execution Options\PCMAV-CLN.exe] • Debugger="notepad.exe" – [HKLM\Software\Microsoft\Windows NT\CurrentVersion\ Image File Execution Options\PCMAV-RTP.exe] • Debugger="notepad.exe" – [HKLM\Software\Microsoft\Windows NT\CurrentVersion\ Image File Execution Options\ANSAV.exe] • Debugger="notepad.exe" – [HKLM\Software\Microsoft\Windows NT\CurrentVersion\ Image File Execution Options\AVG.exe] • Debugger="notepad.exe" – [HKLM\Software\Microsoft\Windows NT\CurrentVersion\ Image File Execution Options\run.exe] • Debugger="notepad.exe" – [HKLM\Software\Microsoft\Windows NT\CurrentVersion\ Image File Execution Options\avgw.exe] • Debugger="notepad.exe" – [HKLM\Software\Microsoft\Windows NT\CurrentVersion\ Image File Execution Options\AVG Free Edition.exe] • Debugger="notepad.exe" – [HKLM\Software\Microsoft\Windows NT\CurrentVersion\ Image File Execution Options\AVG Free Edition Test Centre.exe] • Debugger="notepad.exe" – [HKLM\Software\Microsoft\Windows NT\CurrentVersion\ Image File Execution Options\Avg Free Control Center.exe] • Debugger="notepad.exe" – [HKLM\Software\Microsoft\Windows NT\CurrentVersion\ Image File Execution Options\vbren.exe] • Debugger="notepad.exe" – [HKLM\Software\Microsoft\Windows NT\CurrentVersion\ Image File Execution Options\Kaspersky.exe] • Debugger="notepad.exe" – [HKLM\Software\Microsoft\Windows NT\CurrentVersion\ Image File Execution Options\Kaspersky 6.0.2.exe] • Debugger="notepad.exe" – [HKLM\Software\Microsoft\Windows NT\CurrentVersion\ Image File Execution Options\PC Tools.exe] • Debugger="notepad.exe" – [HKLM\Software\Microsoft\Windows NT\CurrentVersion\ Image File Execution Options\AVAST.exe] • Debugger="notepad.exe" – [HKLM\Software\Microsoft\Windows NT\CurrentVersion\ Image File Execution Options\CAV.exe] • Debugger="notepad.exe" – [HKLM\Software\Microsoft\Windows NT\CurrentVersion\ Image File Execution Options\McAfee.exe] • Debugger="notepad.exe" – [HKLM\Software\Microsoft\Windows NT\CurrentVersion\ Image File Execution Options\McAfee VirusScan.exe] • Debugger="notepad.exe" – [HKLM\Software\Microsoft\Windows NT\CurrentVersion\ Image File Execution Options\Symantec.exe] • Debugger="notepad.exe" – [HKLM\Software\Microsoft\Windows NT\CurrentVersion\ Image File Execution Options\Norman.exe] • Debugger="notepad.exe" – [HKLM\Software\Microsoft\Windows NT\CurrentVersion\ Image File Execution Options\TuneUp Utilities.exe] • Debugger="notepad.exe" – [HKLM\Software\Microsoft\Windows NT\CurrentVersion\ Image File Execution Options\TuneUp Utilities 2006.exe] • Debugger="notepad.exe" – [HKLM\Software\Microsoft\Windows NT\CurrentVersion\ Image File Execution Options\TuneUp Utilities 2007.exe] • Debugger="notepad.exe" – [HKLM\Software\Microsoft\Windows NT\CurrentVersion\ Image File Execution Options\Stars TuneUp Utilities.exe] • Debugger="notepad.exe" – [HKLM\Software\Microsoft\Windows NT\CurrentVersion\ Image File Execution Options\Fix the BRONTOK.exe] • Debugger="notepad.exe" – [HKLM\Software\Microsoft\Windows NT\CurrentVersion\ Image File Execution Options\NOD32.exe] • Debugger="notepad.exe" – [HKLM\Software\Microsoft\Windows NT\CurrentVersion\ Image File Execution Options\HijackThis.exe] • Debugger="notepad.exe" – [HKLM\Software\Microsoft\Windows NT\CurrentVersion\ Image File Execution Options\hijack.exe] • Debugger="notepad.exe" – [HKLM\Software\Microsoft\Windows NT\CurrentVersion\ Image File Execution Options\navw32.exe] • Debugger="notepad.exe" – [HKLM\Software\Microsoft\Windows NT\CurrentVersion\ Image File Execution Options\griso.exe] • Debugger="notepad.exe" – [HKLM\Software\Microsoft\Windows NT\CurrentVersion\ Image File Execution Options\procexp.exe] • Debugger="notepad.exe" – [HKLM\Software\Microsoft\Windows NT\CurrentVersion\ Image File Execution Options\avp.exe] • Debugger="notepad.exe" – [HKLM\Software\Microsoft\Windows NT\CurrentVersion\ Image File Execution Options\samdAV 3.3.exe] • Debugger="notepad.exe" – [HKLM\Software\Microsoft\Windows NT\CurrentVersion\ Image File Execution Options\samdAV 3.2.exe] • Debugger="notepad.exe" – [HKLM\Software\Microsoft\Windows NT\CurrentVersion\ Image File Execution Options\smadAV.exe] • Debugger="notepad.exe" – [HKLM\Software\Microsoft\Windows NT\CurrentVersion\ Image File Execution Options\ Avira Antivir PersonalEdition Classic.exe] • Debugger="notepad.exe" – [HKLM\Software\Microsoft\Windows NT\CurrentVersion\ Image File Execution Options\avcenter.exe] • Debugger="notepad.exe" – [HKLM\Software\Microsoft\Windows NT\CurrentVersion\ Image File Execution Options\AntiVir.exe] • Debugger="notepad.exe" – [HKLM\Software\Microsoft\Windows NT\CurrentVersion\ Image File Execution Options\Avira.exe] • Debugger="notepad.exe" – [HKLM\Software\Microsoft\Windows NT\CurrentVersion\ Image File Execution Options\procmon.exe] • Debugger="notepad.exe" – [HKLM\Software\Microsoft\Windows NT\CurrentVersion\ Image File Execution Options\filemon.exe] • Debugger="notepad.exe" – [HKLM\Software\Microsoft\Windows NT\CurrentVersion\ Image File Execution Options\DiskCleaner.exe] • Debugger="notepad.exe" – [HKLM\Software\Microsoft\Windows NT\CurrentVersion\ Image File Execution Options\RegistryCleaner.exe] • Debugger="notepad.exe" – [HKLM\Software\Microsoft\Windows NT\CurrentVersion\ Image File Execution Options\StarUpManager.exe] • Debugger="notepad.exe" – [HKLM\Software\Microsoft\Windows NT\CurrentVersion\ Image File Execution Options\TuneUp RescueCenter.exe] • Debugger="notepad.exe" – [HKLM\Software\Microsoft\Windows NT\CurrentVersion\ Image File Execution Options\RescueCenter.exe] • Debugger="notepad.exe" – [HKLM\Software\Microsoft\Windows NT\CurrentVersion\ Image File Execution Options\TuneUp RegistryEditor.exe] • Debugger="notepad.exe" – [HKLM\Software\Microsoft\Windows NT\CurrentVersion\ Image File Execution Options\avgcc.exe] • Debugger="notepad.exe" – [HKLM\Software\Microsoft\Windows NT\CurrentVersion\ Image File Execution Options\VPTray.exe] • Debugger="notepad.exe" – [HKLM\Software\Microsoft\Windows NT\CurrentVersion\ Image File Execution Options\VPDN_LU.exe] • Debugger="notepad.exe" – [HKLM\Software\Microsoft\Windows NT\CurrentVersion\ Image File Execution Options\VPC32.exe] • Debugger="notepad.exe" – [HKLM\Software\Microsoft\Windows NT\CurrentVersion\ Image File Execution Options\TweakUI for Windows XP.exe] • Debugger="notepad.exe" – [HKLM\Software\Microsoft\Windows NT\CurrentVersion\ Image File Execution Options\TweakUI.exe] • Debugger="notepad.exe" – [HKLM\Software\Microsoft\Windows NT\CurrentVersion\ Image File Execution Options\MSConfig CleanUp.exe] • Debugger="notepad.exe" – [HKLM\Software\Microsoft\Windows NT\CurrentVersion\ Image File Execution Options\CCleaner.exe] • Debugger="notepad.exe" – [HKLM\Software\Microsoft\Windows NT\CurrentVersion\ Image File Execution Options\Itegrator.exe] • Debugger="notepad.exe" Vengono cambiate le seguenti chiavi di registro: – [HKCU\Software\Microsoft\Windows\CurrentVersion\Policies\Explorer] Nuovo valore: • NoDriveTypeAutoRun=dword:00000000 • NoFind=dword:00000001 • NoFolderOptions=dword:00000001 • NoRun=dword:00000001 • NoViewContextMenu=dword:00000001 – [HKCR\VBEFile\DefaultIcon] Nuovo valore: • (Default)=shell32.dll,-50 – [HKCU\Software\Microsoft\Windows\CurrentVersion\Explorer\Advanced] Valore precedente: • Hidden= %impostazioni definite dell'utente% HideFileExt= %impostazioni definite dell'utente% SuperHidden= %impostazioni definite dell'utente% Nuovo valore: • Hidden=dword:00000000 HideFileExt=dword:00000001 SuperHidden=dword:00000000 – [HKCU\Software\Microsoft\Windows\CurrentVersion\Policies\System] Valore precedente: • DisableRegistryTools= %impostazioni definite dell'utente% DisableTaskMgr= %impostazioni definite dell'utente% Nuovo valore: • DisableRegistryTools=dword:00000001 DisableTaskMgr=dword:00000001 Dettagli del file Linguaggio di programmazione: Il malware è stato scritto in Visual Basic. Software di compressione: Per complicarne l'individuazione e ridurre la dimensione del file, viene compresso con un software di compressione.
Descrizione inserita da Monica Ghitun su venerdì 9 novembre 2007 Descrizione aggiornata da Monica Ghitun su venerdì 9 novembre 2007
Indietro
.
.
.
.