|
|
I-Worm.Sobi Viruses Information
| Name: |
I-Worm.Sobi |
| Category: |
Viruses |
| Description:
|
Details
I-Worm.Sobig
Sobig is a worm virus spreading via the Internet as an attachment to infected emails. It also downloads and sets up a Backdoor program.
The worm itself is a Windows PE EXE file about 64 KB in length (when compressed by TeLock), and written in Microsoft Visual C++.
Infected messages have the following characteristics:
From:
big@boss.com
Subject: (one of the following)
Re: Movies
Re: Sample
Re: Document
Re: Here is that sample
Attachment: (one of the following)
Movie_0074.mpeg.pif
Document003.pif
Untitled1.pif
Sample.pif
The worm activates from infected email only if a user clicks on the attached file. Once run it installs itself to the system, runs a spreading routine and payload.
Installing
While installing the worm copies itself to the Windows directory under the name WINMGM32.EXE and registers this file in the system registry auto-run key.
HKLMSoftwareMicrosoftWindowsCurrentVersionRun
"WindowsMGM" = winmgm32.exe
HKCUSoftwareMicrosoftWindowsCurrentVersionRun
"WindowsMGM" = winmgm32.exe
Spreading via E-mail
To send infected messages the worm uses the SMTP server. The worm looks for files with the following extensions - *.WAB, *.DBX, *.HTM, *.HTML, *.EML, *.TXT scans them for email strings.
Spreading via Local Network
The worm enumerates network shares and tries to copy itself to one of the following folders under the name WINMGM32.EXE.
WindowsAll UsersStart MenuProgramsStartUp Documents and SettingsAll UsersStart MenuProgramsStartup
Set-up for the Backdoor Program
The worm downloads a text file that contains a link to the executable PE file. The worm downloads it into the Windows directory under the DWN.DAT name and runs it.
The worm contains the following text strings:
B.ROOT-SERVERS.NET A.ROOT-SERVERS.NET
a+ %s
big@boss.com
[A-Za-z0-9]+[A-Za-z0-9_.-]+@(([A-Za-z0-9-])+[.])+[A-Za-z]+
*.* x: From <%s> "%s" To Subject Date %s %s %c%4.4d H:mm:ss ddd, d MMM yyyy Importance
Microsoft Outlook Express 6.00.2600.0000 X-Mailer Normal X-MSMail-Priority 3 (Normal)
X-Priority ; filename=" attachment inline Content-Disposition:
Content-Transfer-Encoding: %s ; name="%s" Content-Type: %s Content Type
application/octet-stream --%s --%s-- Content-ID: <%s> Content-Transfer-Encoding: ;
charset="%s" text/ Content-Type: -- --%s Content-Type: multipart/alternative;
boundary="%s" CSmtpMsgPart123X456_001_%8.8X %s This is a multipart
message in MIME format %s: %s Message-ID 1.0 MIME-Version " ;
boundary=" mixed alternative related multipart/
CSmtpMsgPart123X456_000_%8.8X Content-
Type = =%2.2X -;.,?! Encoding took %dms all 7bit 8bit
quoted-printable base64 SMTP tcp text/plain iso-8859-1 QUIT
EHLO %s %s Password: Username: AUTH LOGIN MAIL FROM: <%s> RCPT TO: <%s>.
DATA http://www.geocities.com/reteras/reteral.txt 0 Hello Attached
file: Movie_0074.mpeg.pif Document003.pif Untitled1.pif Sample.pif Re:
Movies Re: Sample Re: Document Re: Here is that sample 2003.1.23
Ret code: %d sntmls.dat dwn.dat r WindowsAll UsersStart
MenuProgramsStartUp Documents and SettingsAll UsersStart
MenuProgramsStartup $ @pager.icq.com mail@mail.com Notify
pager.icq.com start WindowsMGM
SOFTWAREMicrosoftWindowsCurrentVersionRun wab dbx htm html eml txt
Worm.X winmgm32.exe Worm.X |
Top Viruses Visited Pages:
Invader. - 239 visits
not-a-virus:RiskWare.Tool.RegPatch. - 72 visits
Worm.P2P.Harex. - 66 visits
not-a-virus:RemoteAdmin.Win32.RAdmin.2 - 60 visits
Small.58. - 56 visits
Coito.64 - 54 visits
I-Worm.Mapson. - 48 visits
Win16.Klon.1177 - 42 visits
Win32.Hidra - 42 visits
Marine.500 - 35 visits
Random Viruses Pages:
I-Worm.Sober.
Spanish.141
Win.Tentacle.195
GoodLuck.30
Macro.Word.Illitera
Vampirus.149
Worm.Win32.Lovesan.
Riot.278.
PathVir.102
Ada.260
|
|