Vírus VBS/Small.Sasan.A Data em que surgiu: 08/11/2007 Tipo: Worm Incluído na lista "In The Wild" Não Nível de danos: Baixo Nível de distribuição: De baixo a médio Nível de risco: De baixo a médio Ficheiro estático: Sim Tamanho: 10.164 Bytes MD5 checksum: efe528483fd3c6ed75a8c1e016026e10 Versão VDF: 7.00.00.185 Versão IVDF: 7.00.00.192 - quinta-feira, 8 de novembro de 2007
Vulgarmente Meio de transmissão: • Unidade de rede Alias: • Sophos: VBS/Sasan-Fam • Grisoft: VBS/LoveLetter Sistemas Operativos: • Windows 95 • Windows 98 • Windows 98 SE • Windows NT • Windows ME • Windows 2000 • Windows XP • Windows 2003 Efeitos secundários: • Desactiva aplicações de segurança • Descarrega um ficheiro • Altera o registo do Windows Depois da execução executa um aplicação que exibe a janela seguinte: Merlin: Huh..Banjarbaru makin panas aja ya Merlin: It's now time to work. Jangan ngerumpi mulu.. Merlin: Hope you enjoy today. Merlin: Komputernya ta dinginin dulu OK Merlin: Cape dech, Bye Bye Ahh! Ficheiros Autocopia-se para as seguintes localizações • %sysdir%\ctfmon.exe.vbe • %unidade% \Thumbs.db.vbe • %unidade% \%ficheiro eliminado% .vbe É pesquisada a seguinte pasta: • %unidade% \ Presta atenção aos seguintes ficheiros: • .doc • .docx • .xls • .ppt • .jpg • .bmp • .3gp • .rm No final o ficheiro original é eliminado. É criado o seguinte ficheiro: – %unidade% \autorun.inf É um ficheiro de texto não malicioso com o seguinte conteúdo: • [autorun] shellexecute=wscript.exe Thumbs.db.vbe Tenta executar o seguinte ficheiro: – Executa um dos seguintes ficheiros: • %sysdir%\cmd.exe Executa o ficheiro com um dos seguintes parâmetros: shutdown -s -t 00 -f -m Registry (Registo do Windows) É adicionado o seguinte valor ao registo do Windows de forma a que o processo seja executado depois do computador ser reiniciado: – [HKLM\Software\Microsoft\Windows\CurrentVersion\Run] • CTFMon="%sysdir%\ctfmon.exe.vbe" São adicionadas as seguintes chaves ao registo: – [HKCU\Software\Microsoft\Windows\CurrentVersion\Policies\Explorer\ Advanced] • Hidden=dword:00000002 – [HKLM\Software\Microsoft\Windows NT\CurrentVersion\ Image File Execution Options\cmd.exe] • Debugger="notepad.exe" – [HKLM\Software\Microsoft\Windows NT\CurrentVersion\ Image File Execution Options\install.exe] • Debugger="notepad.exe" – [HKLM\Software\Microsoft\Windows NT\CurrentVersion\ Image File Execution Options\msconfig.exe] • Debugger="notepad.exe" – [HKLM\Software\Microsoft\Windows NT\CurrentVersion\ Image File Execution Options\regedit.exe] • Debugger="notepad.exe" – [HKLM\Software\Microsoft\Windows NT\CurrentVersion\ Image File Execution Options\AVG Free.exe] • Debugger="notepad.exe" – [HKLM\Software\Microsoft\Windows NT\CurrentVersion\ Image File Execution Options\regedt32.exe] • Debugger="notepad.exe" – [HKLM\Software\Microsoft\Windows NT\CurrentVersion\ Image File Execution Options\RegistryEditor.exe] • Debugger="notepad.exe" – [HKLM\Software\Microsoft\Windows NT\CurrentVersion\ Image File Execution Options\setup.exe] • Debugger="notepad.exe" – [HKLM\Software\Microsoft\Windows NT\CurrentVersion\ Image File Execution Options\setup32.exe] • Debugger="notepad.exe" – [HKLM\Software\Microsoft\Windows NT\CurrentVersion\ Image File Execution Options\AVG 7.5.exe] • Debugger="notepad.exe" – [HKLM\Software\Microsoft\Windows NT\CurrentVersion\ Image File Execution Options\rstrui.exe] • Debugger="notepad.exe" – [HKLM\Software\Microsoft\Windows NT\CurrentVersion\ Image File Execution Options\PCMAV.exe] • Debugger="notepad.exe" – [HKLM\Software\Microsoft\Windows NT\CurrentVersion\ Image File Execution Options\PCMAV-CLN.exe] • Debugger="notepad.exe" – [HKLM\Software\Microsoft\Windows NT\CurrentVersion\ Image File Execution Options\PCMAV-RTP.exe] • Debugger="notepad.exe" – [HKLM\Software\Microsoft\Windows NT\CurrentVersion\ Image File Execution Options\ANSAV.exe] • Debugger="notepad.exe" – [HKLM\Software\Microsoft\Windows NT\CurrentVersion\ Image File Execution Options\AVG.exe] • Debugger="notepad.exe" – [HKLM\Software\Microsoft\Windows NT\CurrentVersion\ Image File Execution Options\run.exe] • Debugger="notepad.exe" – [HKLM\Software\Microsoft\Windows NT\CurrentVersion\ Image File Execution Options\avgw.exe] • Debugger="notepad.exe" – [HKLM\Software\Microsoft\Windows NT\CurrentVersion\ Image File Execution Options\AVG Free Edition.exe] • Debugger="notepad.exe" – [HKLM\Software\Microsoft\Windows NT\CurrentVersion\ Image File Execution Options\AVG Free Edition Test Centre.exe] • Debugger="notepad.exe" – [HKLM\Software\Microsoft\Windows NT\CurrentVersion\ Image File Execution Options\Avg Free Control Center.exe] • Debugger="notepad.exe" – [HKLM\Software\Microsoft\Windows NT\CurrentVersion\ Image File Execution Options\vbren.exe] • Debugger="notepad.exe" – [HKLM\Software\Microsoft\Windows NT\CurrentVersion\ Image File Execution Options\Kaspersky.exe] • Debugger="notepad.exe" – [HKLM\Software\Microsoft\Windows NT\CurrentVersion\ Image File Execution Options\Kaspersky 6.0.2.exe] • Debugger="notepad.exe" – [HKLM\Software\Microsoft\Windows NT\CurrentVersion\ Image File Execution Options\PC Tools.exe] • Debugger="notepad.exe" – [HKLM\Software\Microsoft\Windows NT\CurrentVersion\ Image File Execution Options\AVAST.exe] • Debugger="notepad.exe" – [HKLM\Software\Microsoft\Windows NT\CurrentVersion\ Image File Execution Options\CAV.exe] • Debugger="notepad.exe" – [HKLM\Software\Microsoft\Windows NT\CurrentVersion\ Image File Execution Options\McAfee.exe] • Debugger="notepad.exe" – [HKLM\Software\Microsoft\Windows NT\CurrentVersion\ Image File Execution Options\McAfee VirusScan.exe] • Debugger="notepad.exe" – [HKLM\Software\Microsoft\Windows NT\CurrentVersion\ Image File Execution Options\Symantec.exe] • Debugger="notepad.exe" – [HKLM\Software\Microsoft\Windows NT\CurrentVersion\ Image File Execution Options\Norman.exe] • Debugger="notepad.exe" – [HKLM\Software\Microsoft\Windows NT\CurrentVersion\ Image File Execution Options\TuneUp Utilities.exe] • Debugger="notepad.exe" – [HKLM\Software\Microsoft\Windows NT\CurrentVersion\ Image File Execution Options\TuneUp Utilities 2006.exe] • Debugger="notepad.exe" – [HKLM\Software\Microsoft\Windows NT\CurrentVersion\ Image File Execution Options\TuneUp Utilities 2007.exe] • Debugger="notepad.exe" – [HKLM\Software\Microsoft\Windows NT\CurrentVersion\ Image File Execution Options\Stars TuneUp Utilities.exe] • Debugger="notepad.exe" – [HKLM\Software\Microsoft\Windows NT\CurrentVersion\ Image File Execution Options\Fix the BRONTOK.exe] • Debugger="notepad.exe" – [HKLM\Software\Microsoft\Windows NT\CurrentVersion\ Image File Execution Options\NOD32.exe] • Debugger="notepad.exe" – [HKLM\Software\Microsoft\Windows NT\CurrentVersion\ Image File Execution Options\HijackThis.exe] • Debugger="notepad.exe" – [HKLM\Software\Microsoft\Windows NT\CurrentVersion\ Image File Execution Options\hijack.exe] • Debugger="notepad.exe" – [HKLM\Software\Microsoft\Windows NT\CurrentVersion\ Image File Execution Options\navw32.exe] • Debugger="notepad.exe" – [HKLM\Software\Microsoft\Windows NT\CurrentVersion\ Image File Execution Options\griso.exe] • Debugger="notepad.exe" – [HKLM\Software\Microsoft\Windows NT\CurrentVersion\ Image File Execution Options\procexp.exe] • Debugger="notepad.exe" – [HKLM\Software\Microsoft\Windows NT\CurrentVersion\ Image File Execution Options\avp.exe] • Debugger="notepad.exe" – [HKLM\Software\Microsoft\Windows NT\CurrentVersion\ Image File Execution Options\samdAV 3.3.exe] • Debugger="notepad.exe" – [HKLM\Software\Microsoft\Windows NT\CurrentVersion\ Image File Execution Options\samdAV 3.2.exe] • Debugger="notepad.exe" – [HKLM\Software\Microsoft\Windows NT\CurrentVersion\ Image File Execution Options\smadAV.exe] • Debugger="notepad.exe" – [HKLM\Software\Microsoft\Windows NT\CurrentVersion\ Image File Execution Options\ Avira Antivir PersonalEdition Classic.exe] • Debugger="notepad.exe" – [HKLM\Software\Microsoft\Windows NT\CurrentVersion\ Image File Execution Options\avcenter.exe] • Debugger="notepad.exe" – [HKLM\Software\Microsoft\Windows NT\CurrentVersion\ Image File Execution Options\AntiVir.exe] • Debugger="notepad.exe" – [HKLM\Software\Microsoft\Windows NT\CurrentVersion\ Image File Execution Options\Avira.exe] • Debugger="notepad.exe" – [HKLM\Software\Microsoft\Windows NT\CurrentVersion\ Image File Execution Options\procmon.exe] • Debugger="notepad.exe" – [HKLM\Software\Microsoft\Windows NT\CurrentVersion\ Image File Execution Options\filemon.exe] • Debugger="notepad.exe" – [HKLM\Software\Microsoft\Windows NT\CurrentVersion\ Image File Execution Options\DiskCleaner.exe] • Debugger="notepad.exe" – [HKLM\Software\Microsoft\Windows NT\CurrentVersion\ Image File Execution Options\RegistryCleaner.exe] • Debugger="notepad.exe" – [HKLM\Software\Microsoft\Windows NT\CurrentVersion\ Image File Execution Options\StarUpManager.exe] • Debugger="notepad.exe" – [HKLM\Software\Microsoft\Windows NT\CurrentVersion\ Image File Execution Options\TuneUp RescueCenter.exe] • Debugger="notepad.exe" – [HKLM\Software\Microsoft\Windows NT\CurrentVersion\ Image File Execution Options\RescueCenter.exe] • Debugger="notepad.exe" – [HKLM\Software\Microsoft\Windows NT\CurrentVersion\ Image File Execution Options\TuneUp RegistryEditor.exe] • Debugger="notepad.exe" – [HKLM\Software\Microsoft\Windows NT\CurrentVersion\ Image File Execution Options\avgcc.exe] • Debugger="notepad.exe" – [HKLM\Software\Microsoft\Windows NT\CurrentVersion\ Image File Execution Options\VPTray.exe] • Debugger="notepad.exe" – [HKLM\Software\Microsoft\Windows NT\CurrentVersion\ Image File Execution Options\VPDN_LU.exe] • Debugger="notepad.exe" – [HKLM\Software\Microsoft\Windows NT\CurrentVersion\ Image File Execution Options\VPC32.exe] • Debugger="notepad.exe" – [HKLM\Software\Microsoft\Windows NT\CurrentVersion\ Image File Execution Options\TweakUI for Windows XP.exe] • Debugger="notepad.exe" – [HKLM\Software\Microsoft\Windows NT\CurrentVersion\ Image File Execution Options\TweakUI.exe] • Debugger="notepad.exe" – [HKLM\Software\Microsoft\Windows NT\CurrentVersion\ Image File Execution Options\MSConfig CleanUp.exe] • Debugger="notepad.exe" – [HKLM\Software\Microsoft\Windows NT\CurrentVersion\ Image File Execution Options\CCleaner.exe] • Debugger="notepad.exe" – [HKLM\Software\Microsoft\Windows NT\CurrentVersion\ Image File Execution Options\Itegrator.exe] • Debugger="notepad.exe" Altera as seguintes chaves de registo do Windows: – [HKCU\Software\Microsoft\Windows\CurrentVersion\Policies\Explorer] Valor recente: • NoDriveTypeAutoRun=dword:00000000 • NoFind=dword:00000001 • NoFolderOptions=dword:00000001 • NoRun=dword:00000001 • NoViewContextMenu=dword:00000001 – [HKCR\VBEFile\DefaultIcon] Valor recente: • (Default)=shell32.dll,-50 – [HKCU\Software\Microsoft\Windows\CurrentVersion\Explorer\Advanced] Valor anterior: • Hidden= %definições do utilizador % HideFileExt= %definições do utilizador % SuperHidden= %definições do utilizador % Valor recente: • Hidden=dword:00000000 HideFileExt=dword:00000001 SuperHidden=dword:00000000 – [HKCU\Software\Microsoft\Windows\CurrentVersion\Policies\System] Valor anterior: • DisableRegistryTools= %definições do utilizador % DisableTaskMgr= %definições do utilizador % Valor recente: • DisableRegistryTools=dword:00000001 DisableTaskMgr=dword:00000001 Detalhes do ficheiro Linguagem de programação: O programa de malware está escrito em Visual Basic. Empacotador de Runtime: De forma a agravar a detecção e reduzir o tamanho do ficheiro é lançado com um empacotador de runtime.
Descrição enviada por Monica Ghitun em
sexta-feira, 9 de novembro de 2007 Descrição atualizada por Monica Ghitun em
sexta-feira, 9 de novembro de 2007
Voltar
.
.
.
.