Home    Forum    Search    FAQ    Register    Log in
Post new topic  Reply to topic Page 1 of 1
 
Email-Worm.Win32.Brontok.q
Author Message
Reply with quote
Post Email-Worm.Win32.Brontok.q 
 
Other Names:

W32/Rontokbro.gen@MM (McAfee),   W32.Rontokbro@mm (Symantec),   BackDoor.Generic.1138 (Doctor Web),   W32/Korbo-B (Sophos),   WORM_RONTOKBRO.F (Trend Micro),   WORM/Brontok.C (H+BEDV),   W32/Brontok.C@mm (FRISK),   Win32:Rontokbr-B (ALWIL),   I-Worm/VB.FY (Grisoft),   Win32.Brontok.C@MM (SOFTWIN),   Worm.Brontok.E (ClamAV),   Win32/Brontok.F (Eset)

Behavior: Email Worm

This worm spreads via the Internet as an attachment to infected messages. It sends itself to email addresses harvested from the victim machine.

The worm itself is a Windows PE EXE file written in Visual Basic. The size of the infected file can vary significantly. The functionality described below is characteristic of the most common variants of this worm.

Installation

When the infected file is first launched, the user will see a Windows Explorer window, with an open 'My Pictures' folder.

When installing, the worm modifies the following keys of the system registry, disabling system registry tools, the command line, and displaying files and folders in Windows Explorer.

[HKCU\software\Microsoft\Windows\CurrentVersion\Policies\System]
 "DisableRegistryTools"="1"
 "DisableCMD"="0"

[HKCU\Software\Microsoft\Windows\CurrentVersion\Explorer\Advanced]
 "Hidden"="0"
 "HideFileExt"="1"
 "ShowSuperHidden"="0"

[HKCU\Software\Microsoft\Windows\CurrentVersion\Policies\Explorer]
 "NoFolderOptions"="1"


For example, the following message will be displayed when the registry editor is launched:

Image


The worm then gets a path to Application Data for the current user (%UserProfile%\Local Settings\Application Data) and copies its body to this directory under the following names:

%UserProfile%\Local Settings\Application Data\br<random>on.exe
%UserProfile%\Local Settings\Application Data\csrss.exe
%UserProfile%\Local Settings\Application Data\inetinfo.exe
%UserProfile%\Local Settings\Application Data\lsass.exe
%UserProfile%\Local Settings\Application Data\services.exe
%UserProfile%\Local Settings\Application Data\smss.exe
%UserProfile%\Local Settings\Application Data\svchost.exe
%UserProfile%\Local Settings\Application Data\winlogon.exe


A text file called Kosong.Bron.Tok.txt (51 bytes in size) is also created in this directory. The file has the following contents:

Brontok.A
By: HVM31
-- JowoBot #VM Community --


The worm also copies its body to the Windows root directory (%WinDir%) under the following name:

%WinDir%\sembako-<random>.exe

and to the ShellNew subdirectory under a name generated as follows: bbm-<random>.exe:

%WinDir%\ShellNew\bbm-<random>.exe

and to the Windows system directory under the following names:

%System%\DXBLBO.exe
%System%\cmd-bro-<random>.exe
%System%\%UserName%'s Setting.scr


The worm also copies itself to the Start menu Autorun directory as Empty.pif:

%UserProfile%\%Autorun%\Empty.pif

and to the Document Template subdirectory:

%UserProfile%\Templates\<random>-NendangBro.com

and to the My Pictures directory of the current user:

%MyPictures%\Mypictures.exe

An HTML page called about.Brontok.A.html is also created in this directory:

Image

When this page is viewed using the browser, the following message is displayed:

Image

This page contains the contents of the email message which the worm sends to email addresses harvested from the victim machine.

The copies of the worm will then be registered in the system registry to ensure that they are launched automatically:

[HKLM\Software\Microsoft\Windows\CurrentVersion\Run]
 "Bron-Spizaetus"=""
 "Bron-Spizaetus-<random>"="%WinDir%\ShellNew\bbm-<random>.exe"

[HKCU\Software\Microsoft\Windows\CurrentVersion\Run]
 "Tok-Cirrhatus"=""
 "Tok-Cirrhatus-<random>"="%UserProfile%\Local Settings\Application Data\br<random>on .exe"

[HKLM\Software\Microsoft\Windows NT\CurrentVersion\Winlogon]
 "Shell"="Explorer.exe "%WinDir%\sembako-<random>.exe""

[HKLM\SYSTEM\CurrentControlSet\Control\SafeBoot]
 "AlternateShell"="cmd-bro-<random>.exe"


Once installed, the worm creates a file called sistem.sys in the Windows system directory. This file contains the date and time the worm was installed to the victim machine in the following format: mmddhhmm, where mm stands for the month, dd for the data, hh for the hour, and mm for the minute.

Propagation via email

The worm harvests addresses from the MS Windows address books and from files with the following extensions:

ASP
CFM
CSV
DOC
EML
HTM
HTML
PHP
TXT
WAB


All the harvested addresses are saved to %AppData%\Loc.Mail.Bron.Tok as files with email address names, an .ini extension and the following text:

Brontok.A
By: HVM31
-- JowoBot #VM Community –


A directory called Ok-SendMail-Bron-tok is created, and the addresses which messages are sent to are saved to this file.

When sending infected messages the worm uses its own SMTP engine.

Infected messages

Attachment name (chosen from the list below):

* ccapps.exe
* jangan dibuka.exe
* kangen.exe
* my heart.exe
* myheart.exe
* syslove.exe
* untukmu.exe
* winword.exe


Message text:

The HTML page shown above acts as the text of infected messages.

REMOVAL

The worm checks the header of the open window, and if one of the following strings is present in the header, it will reboot the system:


..
.@
@.
.ASP
.EXE
.HTM
.JS
.PHP
ADMIN
ADOBE
AHNLAB
ALADDIN
ALERT
ALWIL
ANTIGEN
APACHE
APPLICATION
ARCHIEVE
ASDF
ASSOCIATE
AVAST
AVG
AVIRA
BILLING@
BLACK
BLAH
BLEEP
BUILDER
CANON
CENTER
CILLIN
CISCO
CMD.
CNET
COMMAND
COMMAND PROMPT
CONTOH
CONTROL
CRACK
DARK
DATA
DATABASE
DEMO
DETIK
DEVELOP
DOMAIN
DOWNLOAD
ESAFE
ESAVE
ESCAN
EXAMPLE
FEEDBACK
FIREWALL
FOO@
FUCK
FUJITSU
GATEWAY
GOOGLE
GRISOFT
GROUP
HACK
HAURI
HIDDEN
HP.
IBM.
INFO@
INTEL.
KOMPUTER
LINUX
LOG OFF WINDOWS
LOTUS
MACRO
MALWARE
MASTER
MCAFEE
MICRO
MICROSOFT
MOZILLA
MYSQL
NETSCAPE
NETWORK
NEWS
NOD32
NOKIA
NORMAN
NORTON
NOVELL
NVIDIA
OPERA
OVERTURE
PANDA
PATCH
POSTGRE
PROGRAM
PROLAND
PROMPT
PROTECT
PROXY
RECIPIENT
REGISTRY
RELAY
RESPONSE
ROBOT
SCAN
SCRIPT HOST
SEARCH R
SECURE
SECURITY
SEKUR
SENIOR
SERVER
SERVICE
SHUT DOWN
SIEMENS
SMTP
SOFT
SOME
SOPHOS
SOURCE
spam
SPERSKY
SUN.
SUPPORT
SYBARI
SYMANTEC
SYSTEM CONFIGURATION
TEST
TREND
TRUST
UPDATE
UTILITY
VAKSIN
virus
W3.
WINDOWS SECURITY.VBS
WWW
XEROX
XXX
YOUR
ZDNET
ZEND
ZOMBIE


The worm also modifies the contents of autoexec.bat in the C: root directory, adding "pause" to it.






____________________
The more you lose yourself in something bigger than yourself, the more energy you will have!!
Offline Yahoo Messenger View user's profile Send private message Visit poster's website
Download Post Back to top Page bottom
Display posts from previous:   
HideWas this topic useful?

 

You are not authorized to rate this topic

Average Rate Minimum Rate Maximum Rate Number Of Rates
0.00 0 0 0
Share this topic
blinkslist.com blogmarks.net co.mments.com del.icio.us digg.com newsvine.com facebook.com fark.com feedmelinks.com furl.net google.com linkagogo.com ma.gnolia.com meneame.net netscape.com reddit.com shadows.com simpy.com slashdot.org smarking.com spurl.net stumbleupon.com technorati.com favorites.live.com yahoo.com DIGG ITA Fai Informazione KiPapa Ok Notizie Segnalo
HideSimilar Topics
Topic Author Forum Replies Last Post
No new posts Worm.Win32.AutoRun.bnb rssays Lastest News 0 21 Oct 2008 12:36 View latest post
rssays
No new posts What is a computer worm? rssays Q&A 0 24 May 2008 18:52 View latest post
rssays
No new posts Best Free Email Client rssays Lastest News 0 20 May 2008 21:37 View latest post
rssays
No new posts Chain Email Messages rssays Latest News 0 24 Jul 2008 19:36 View latest post
rssays
No new posts How I Use Email Automatic Responders rssays Lastest News 0 25 May 2008 01:26 View latest post
rssays

Post new topic  Reply to topic  Page 1 of 1
 

Users browsing this topic: 0 Registered, 0 Hidden and 1 Guest
Registered Users: None


 
Permissions List
You cannot post new topics in this forum
You cannot reply to topics in this forum
You cannot edit your posts in this forum
You cannot delete your posts in this forum
You cannot vote in polls in this forum
You cannot attach files in this forum
You cannot download files in this forum
You cannot post calendar events in this forum