Jul 24, 2008

New Worm - zotob

Free Web Hosting, No Ads > CONTRIBUTE > Computers > Computer Security Issues & Exploits

free web hosting

New Worm - zotob

frony
QUOTE
The worm is a packed PE executable file 22528 bytes long.

Installation to system

When run, the worm copies under %SYSTEM% directory using the name 'botzor.exe' and creates a named mutex 'B-O-T-Z-O-R' for making sure that only one copy of the worm is run at the same time.

Then it adds the following registry entries to ensure that it is started when a user logs on or the system is restarted:


[HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
[HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\RunServices]
"WINDOWS SYSTEM" = "botzor.exe"

The worm also adds the following registry key for diasabling shared access service:


[HKLM\SYSTEM\CurrentControlSet\Services\SharedAccess]
"Start" = "4"

Spreading using Plug and Play service vulnerability

The worm scans for systems vulnerable to Microsoft Windows Plug and Play service (MS05-039) through TCP/445.

It creates 300 threads that connect to random IP addresses within the B-class (255.255.0.0) network of the infected system. First it tests connection to port 445 and if successful, it tries to exploit the vulnerability. If the attack is successful a shell (cmd.exe) is started on port 8888. Through the shell port, the worm sends a ftp script which instructs the remote computer to download and execute the worm from the attacker computer using FTP. The FTP server listens on port 33333 on all infected computers with the purpose of serving out the worm for other hosts that are being infected. The downloaded file is saved as 'haha.exe' on disk.

Here's the summary of the ports used in attack:

Port 445 - The worm scans for systems vulnerable to PnP exploit through this port

Port 33333 - FTP server port on infected systems

Port 8888 - The command shell port opened by the exploit code

The exploit uses fixed offsets inside Windows 2000 version of umpnpmgr.dll. This means that only Windows 2000 systems (SP0-4) are affected.

Please see the following page for detailed information on the vulnerability:

http://www.microsoft.com/technet/security/...n/MS05-039.mspx


Bot functionality

The worm tries to connect to IRC channel at predefined address. The attacker who knows channel password can instruct the bot to execute the following actions:


Disconnect/reconnect from the IRC channel
Request system information
Download and execute files
Remove worm from the system
Manipulate system security settings

Other details

Zotob.A modifies system hosts file in order to disable access to certain sites. Following hostnames are redirected to localhost IP address (127.0.0.1):


avp.com
ca.com
customer.symantec.com
dispatch.mcafee.com
download.mcafee.com
ebay.com
f-secure.com
kaspersky.com
kaspersky-labs.com
liveupdate.symantec.com
liveupdate.symantecliveupdate.com
mast.mcafee.com
mcafee.com
microsoft.com
moneybookers.com
my-etrust.com
nai.com
networkassociates.com
pandasoftware.com
paypal.com
rads.mcafee.com
secure.nai.com
securityresponse.symantec.com
sophos.com
symantec.com
trendmicro.com
updates.symantec.com
update.symantec.com
us.mcafee.com
viruslist.com
virustotal.com
www.amazon.com
www.avp.com
www.ca.com
www.ebay.com
www.f-secure.com
www.grisoft.com
www.kaspersky.com
www.mcafee.com
www.microsoft.com
www.moneybookers.com
www.my-etrust.com
www.nai.com
www.networkassociates.com
www.pandasoftware.com
www.paypal.com
www.sophos.com
www.symantec.com
www.trendmicro.com
www.virustotal.com

The worm also writes the following text to hosts file:


Botzor2005 Made By .... Greetz to good friend Coder. Based On HellBot3
MSG to avs: the first av who detect this worm will be the first killed in the next 24hours!!!




patch
http://www.microsoft.com/technet/security/...n/MS05-039.mspx

Notice from BuffaloHELP:
Fixed title spelling. When you are pasting from another source you can use [quote] tags instead of [code]. URL can be pasted without using any BBcode tags. But thank you for your careful consideration smile.gif

 

 

 


Reply

BuffaloHELP
This subject started in the discussion thread http://www.trap17.com/forums/index.php?sho...ndpost&p=175715 but I'll let this thread live since it provides bit more in depth look into what the worm actually does.

I'll also cross reference to the thread mentioned above.

Topic closed.

Reply



Got an Opinion! Express your Views! (no registration):-
Add your Reply/ Opinion/ Views/ Comments/ Suggestion/ Questions/ Queries etc.
Posts with decent grammar & English will be accepted and please refrain from profanities.
For asking a Question, We recommend you to sign-up (for free) so that you can track the topic easily.

Nature of your Post*: Opinion/ Reply/ Comments
Question/Query
Feedback to us.
       
Name   Email
Title/Question*

(Maximum characters: 10,000)
You have characters left.
Confirm Code:

Similar Topics

Keywords : worm zotob

  1. New Virus Kills Music Files - Nopir.B worm wipes out all mp3 and com files (19)
    http://english.chosun.com/w21data/html/new...0504250004.html Not only does it not differentiate
    between legal and illegal mp3 files, it also doesn't let you reboot your computer. So far,
    it's been circulating only in Europe, but those in the US and Asia had better take caution as
    well. It's only a matter of time......
  2. Alcra D Worm - PLEASE HELP (10)
    I have the Alcra D worm which starts up limewire and disables regedit and other things. If anyone
    knows how to get rid of this tell me. PLEASE. I have adaware, but it never seems to find it. I cant
    use ctrl alt delete and limewire slows my computer down because it opens non stop. SO PLEASE HELP. I
    have tried other things, but they never seem to work. I found a program for the type B worm, but it
    dosnt work for D i tried. Any info on this post back. If you use limewire and it keeps opening this
    is what you have by the way. And i love how limwire's FAQ says you have a ...
  3. New Virus Called Storm Worm Or W32/nuwar@mm Is Out And About - WINZIP/Rar be WARNED (4)
    To think the Microsoft ANI exploit and the botnet things were bad but this just top the charts, this
    new variation of the Storm virus of last year gets a new powerful punch. The virus gets sent
    through a password protected zip fil in which the password is contain in a image file in the email.
    The email subject contains either Worm Alert!" or "Trojan Detected! so do not open and just
    delete it. Also the image file will read something like UrgentNotice.gif" or "AbuseReport.gif. and
    the zip file will read something like "patch-####.zip" or "removal-####.zip.". ...
  4. Skype Worm Jumps To Icq And Msn - (3)
  5. Myspace.com Flash Hack - account hijacked worm and solution (13)
    Well buffaloHELP just mention and I have confirmed it by many articles myspace accounts have been
    hacked or in hte sense that if your account was hijacked then anyone viewing your profile will also
    get infected as well. In a article by chaseandsam.com go into detail on how this happen and a
    solution to it as well Click here for more ---WARNING--- Also this hack is also a virus in
    which a person who is viewing your hacked profile will get their profile hijacked as well. Also
    Symantec mentions about it as well Nortan How it was done ---SOLUTION--- ...
  6. Worm Disguises As Windows Genuine Advantage - be careful of the wgavn service ... (5)
    QUOTE IT security experts have warned of a worm that purports to be Microsoft's Windows
    Genuine Advantage (WGA) anti-piracy tool. WGA has recently been branded as 'spyware' in
    that it collects unnecessary hardware and software data from users' PCs. The Cuebot-K worm
    spreads via AOL Instant Messenger, registering itself as a new system driver service called
    'wgavn'. It carries the display name 'Windows Genuine Advantage Validation
    Notification', and runs automatically during system startup. Once in place the worm disables
    the Wi...
  7. Worm: W32.areses.h@mm - (3)
    QUOTE W32.Areses.H@mm is a mass-mailing worm that opens a back door on the compromised computer
    and may download files. When W32.Areses.H@mm is executed, it performs the following actions:
    Copies itself as the following file: %Windir%\csrss.exe Note: %Windir% is a variable that
    refers to the Windows installation folder. By default, this is C:\Windows or C:\Winnt.
    Adds the value: "Debugger" = " " to the registry subkey:
    HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File
    Execution Options\e...
  8. Nyxem E - Be Safe From This Virus/worm - Latest Mass Mailing Worm (14)
    QUOTE Windows users are being urged to scan their computers before 3rd February 2006 to avoid
    falling victim to a destructive Worm. On that date the Nyxem E Worm is set to delete Word,
    Powerpoint, Excel and Acrobat files on infected machines! Don't get caught out... See
    complete article at http://www.updatexp.com/nyxem-e.html Better get your anti-virus updated by
    3rd Febuary before seeing your files go missing. It's kindda scary worm if not handled properly.
    The date is near so get updated fast. Edited topic title. ...
  9. Microsoft Plugs Windows Worm Holes - 14 flaws in Windows... (3)
    http://news.zdnet.com/2100-1009_22-5893344.html?tag=nl.e589 Here is another proof that the words
    'Windows' and 'Security' simply cannot go together... And yet another good reason
    for installing and start using Linux... Cheers! KoYoda...
  10. New Worm! - Please note! New Worm here! (9)
    OK! Mircosoft has just discovered a new worm. I repeat! NEW WORM! The new worm is called
    "Zotob". It's a worm that can takes weeks, months, to get embeded into your system and take
    over. It digs so deep that it's very difficult to erase. So PLEASE! Listen carefully!
    Zotob -- The worm targets Windows 2000 Computers and once it's embeded, it'll try sending
    itself to other computers! The worm IS *NOT* caught by emails, websites, anything. It's a
    worm that opens itself, so you have to be really carefull now. What it does: Is si...
  11. New Worm, M$ Users, Be Warned! - WORM_ZOTOB.D and WORM_RBOT.CBQ (11)
    New Virus is emerging. Microsoft users, be alerted!. This is one of the reason why i dont really
    like M$ stuff, but still, i need it really much despite of its problems QUOTE Dear Trend
    Micro customer, As of August 16, 2005 5:12 PM (Pacific Daylight Time; GMT-7:00), TrendLabs has
    declared a Medium Risk Virus Alert to control the spread of WORM_ZOTOB.D and WORM_RBOT.CBQ.
    TrendLabs has received several infection reports indicating that this malware is spreading in
    Brazil and the U.S.A. WORM_ZOTOB.D is a memory-resident worm that drops a copy of itself in ...



Looking for worm, zotob

Searching Video's for worm, zotob
advertisement



New Worm - zotob



 

 

 

 

ADD REPLY / Got an Opinion! Remove these ADs! RAPID SEARCH! Free Web Hosting [X]
Express your Opinions, Thoughts or Contribute more info. to help others.
Ask your Doubts & Queries to get answers, So that "Together We can help others!"
Register FREE for AD-FREE forum, Create your own topics, Ask Questions, track topics, setup subscriptions & notifications and Get a Free Website w/ Email and FTP.
500MB Space *No Ads*, CPanel, FTP, PHP, MySQL, EMails - 100% FREE