F-Secure Virus Descriptions : MyDoom.AE
[Summary] | [Detailed Description] | [Detection]
|
|
|
A new variant of MyDoom worm - Mydoom.AE, was found on October
16th, 2004. The worm is similar to previous variants. It
downloads and executes an additional file from a website. This
file is detected as 'Worm.P2P.Scranor'. The Scranor P2P
(peer-to-peer) worm in its turn downloads and runs another file,
that is detected as 'Backdoor.Win32.Rbot.gen'. The MyDoom.AE worm
has a message from Mydoom author(s) to AV vendors.
The worm is a PE executable file 51712 bytes long packed with UPX
file compressor. The unpacked file's size is over 107 kilobytes.
Installation to system
When the worm's file is run, it first creates a mutex named
'My-Game'. Then the worm tries to download a file from the
'www.freewebs.com' website. This file is saved to the root folder
of C: drive as 'Scran.exe' and is then activated. The downloaded
file is a P2P (peer-to-peer) worm called 'Scranor'.
Upon installation the worm copies itself as 'avpr.exe' file to
Windows System Directory and creates a startup key for that file
in System Registry:
[HKLM\Software\Microsoft\Windows\CurrentVersion\Run]
"Avpr" = "%WinSysDir%\avpr.exe"
where "%WinSysDir%" represents Windows System directory. If the
startup key cal not be created in HKLM (local machine) Registry
tree, it is created in HKCU (current user) tree.
Also the worm creates the following key in the Registry:
[HKLM\Software\Microsoft\Windows\DdInfect]
Spreading in e-mails
The worm spreads by sending its infected attachment to all e-mail
addresses found on an infected computer. The worm looks for
e-mail addresses in Windows Address Book and in the files with
the following extensions:
wab
pl
adb
tbb
dbx
asp
php
sht
vbs
cfg
eml
cgi
wsh
msg
uin
xls
jsp
xml
mdx
mbx
html
htm
txt
The worm searches for these files in the following locations:
Desktop folder
Temporary Internet Files folder
My Documents folder
Application Data folders
Program Files folders
Windows System folder
The files are searched on hard disks and RAM drives from C: to Z:.
The worm avoids sending e-mails to e-mail addresses that contain
any of the following substrings:
avp
syma
icrosof
panda
sopho
borlan
inpris
example
mydomai
nodomai
ruslis
.gov
gov.
.mil
foo.
berkeley
unix
math
bsd
mit.e
gnu
fsf.
ibm.com
kernel
linux
fido
usenet
iana
ietf
rfc-ed
sendmail
arin.
ripe.
isi.e
isc.o
acketst
pgp
tanford.e
utgers.ed
mozilla
root
info
samples
postmaster
webmaster
noone
nobody
nothing
anyone
someone
your
you
me
bugs
rating
site
contact
soft
no
somebody
privacy
service
help
not
submit
feste
ca
gold-certs
the.bat
page
admin
icrosoft
support
ntivi
unix
bsd
linux
listserv
certific
google
accoun
The subject of infected e-mails is selected from the following
variants:
Announcement
Details
Re:Details
Information
Re:Information
Important
Re:Important
Fw:Important
Document
Re:Document
Fw:Document
Notification
Re:Notification
Fw:Notification
Warning
Re:Warning
Fw:Warning
read now!
Information
Fw:Information
The body text of infected e-mails is selected from the following
variants:
Daily Report.
your document.
here is the document.
Reply
Important Information.
Kill the writer of this document!
Details are in the attached document.
See the attached file for details
Please see the attached file for details
Check the attached document.
Monthly news report.
Please confirm!.
Please read the attached file!.
Please see the attached file for details.
Waiting for a Response. Please read the attachment.
Please answer quickly!.
The worm's attachment name is selected from the following
variants:
document.doc <spaces> .
report.doc <spaces> .
news.doc <spaces> .
msg.doc <spaces> .
information.doc <spaces> .
letter.doc <spaces> .
message.doc <spaces> .
file.doc <spaces> .
check.doc <spaces> .
error.doc <spaces> .
archive.doc <spaces> .
list.doc <spaces> .
data.doc <spaces> .
text.doc <spaces> .
note.doc <spaces> .
notes.doc <spaces> .
attachment.doc <spaces> .
The extension of an infected file can be any of the following:
.cpl
.scr
.pif
MyDoom.AE worm can also send itself in a ZIP archive.
The worm can attach a fake anti-virus scanning report to the
message it sends:
+++ Attachment: No Virus found
<av_vendor_string>
where <av_vendor_string> string can be one of the following:
+++ MessageLabs AntiVirus - www.messagelabs.com
+++ Bitdefender AntiVirus - www.bitdefender.com
+++ MC-Afee AntiVirus - www.mcafee.com
+++ Kaspersky AntiVirus - www.kaspersky.com
+++ Panda AntiVirus - www.pandasoftware.com
+++ Norman AntiVirus - www.norman.com
+++ F-Secure AntiVirus - www.f-secure.com
+++ Norton AntiVirus - www.symantec.com
The worm fakes the sender's address. It uses the following list
of names to compose the fake address:
Leon
Tom
Marcus
Troy
Walter
Eric
Matthew
Kenneth
Charles
Tommy
Jim
Francisco
Ricky
Dennis
Scott
Jason
George
Richard
Lloyd
Jay
Leroy
Carl
Jerry
Frank
Kevin
Donald
David
Bill
Oscar
Mario
Henry
Joshua
Jeffrey
Anthony
Mark
William
Ronnie
Miguel
Bernard
Douglas
Gregory
Larry
Ronald
Paul
Michael
Jon
Clifford
Alexander
Harold
Raymond
Jose
Brian
Daniel
Robert
Alex
Theodore
Barry
Peter
Andrew
Timothy
Edward
Thomas
John
Calvin
Micheal
Randall
Patrick
Stephen
Gary
Steven
JosephJames
The worm uses the following list of domain names to compose the
fake sender's address:
@microsoft.com
@symantec.com
Backdoor component
Upon installation the worm drops a file named 'TCP5424.dll' to
Windows System folder. The following startup key is created in
the Registry:
[HKCR\CLSID\{E6FB5E20-DE35-11CF-9C87-00AA005127ED}\InprocServer32]
@ = "%WinSysDir%\tcp5424.dll"
where "%WinSysDir%" represents Windows System directory. This DLL
file is a backdoor that listens on TCP port 5424 for remote
commands. The backdoor allows to upload and activate files on an
infected computer.
Payload
The worm modifies the HOSTS file to block access to the following
websites:
www.pandasoftware.com
www.symantec.com
securityresponse.symantec.com
symantec.com
www.sophos.com
sophos.com
www.mcafee.com
mcafee.com
liveupdate.symantecliveupdate.com
www.viruslist.com
viruslist.com
viruslist.com
f-secure.com
www.f-secure.com
kaspersky.com
www.avp.com
www.kaspersky.com
avp.com
www.networkassociates.com
networkassociates.com
www.ca.com
ca.com
mast.mcafee.com
my-etrust.com
www.my-etrust.com
download.mcafee.com
dispatch.mcafee.com
secure.nai.com
nai.com
www.nai.com
update.symantec.com
updates.symantec.com
us.mcafee.com
liveupdate.symantec.com
customer.symantec.com
rads.mcafee.com
trendmicro.com
www.trendmicro.com
Additionally the worm creates the following keys from the
Registry:
[HKLM\Software\Microsoft\Windows\CurrentVersion\Run]
"MsnMsgr"
"ICQ Net"
The message to AV vendors
The worm contains a message to AV vendors in its body:
Lucky's Av's ;P~. Sasser author gets IT security job and we will
work with Mydoom , P2P worms and exploit codes .Also we will
attack f-secure,symantec,trendmicro,mcafee , etc. The 11th of
march is the skynet day lol . When the beagle and mydoom loose,
we wanna stop our activity <== so Where is the Skynet now? lol.
This Will Drop W32.Scran P2P Worm
This message is extracted by the worm to Windows System folder as
'msg15.txt' file.
Mydoom.AE worm variant is detected as 'I-Worm.Mydoom.AA' since
the following FSAV updates:
[FSAV_Database_Version]
Version=2004-10-16_01
Write-Up:
Katrin Tocheva; October 16th, 2004;
Technical Details:
Alexey Podrezov; October 18th, 2004;
F-Secure Corporation
|