Email characteristics:
- Subject: (variable)
- Body: (variable)
- Attachment: (variable)
When run this worm will copy itself to the Windows System directory using the file name [SYSTEM]irun4.exe. Registry keys created by the worm:HKCUSOFTWAREDatetime HKCUSOFTWAREMicrosoftWindowsCurrentVersion Run ssate.exe = [SYSTEM]irun4.exe Share/P2P propagationThis worm will copy itself to local and shared network drives. The worm looks for folders containing the string "shar" and copies itself into those folders as: - Microsoft Office 2003 Crack, Working!.exe
- Microsoft Office XP working Crack, Keygen.exe
- Microsoft Windows XP, WinXP Crack, working
- Keygen.exe
- Porno Screensaver.scr
- Porno, sex, oral, anal cool, awesome!!.exe
- Porno pics arhive, xxx.exe
- Serials.txt.exe
- Windown Longhorn Beta Leak.exe
- Windows Sourcecode update.doc.exe
- XXX hardcore images.exe
- Opera 8 New!.exe
- WinAmp 5 Pro Keygen Crack Update.exe
- WinAmp 6 New!.exe
- Matrix 3 Revolution English Subtitles.exe
- Adobe Photoshop 9 full.exe
- Ahead Nero 7.exe
- ACDSee 9.exe
Email propagationThe worm contains its own SMTP engine and will send itself to addresses found on the local computer. These addresses are picked from files of following types: - .wab
- .txt
- .msg
- .htm
- .xml
- .dbx
- .mdx
- .eml
- .nch
- .mmf
- .ods
- .cfg
- .asp
- .php
- .pl
- .adb
- .tbb
- .sht
- .uin
- .cgi
Addresses containing the following strings are avoided: - @hotmail.com
- @msn.com
- @microsoft
- @avp.
- noreply
- local
- root@
- postmaster@
These mails have spoofed FROM: addresses. They will appear to come from addresses like the following: - management@[recipient domain]
- administration@[recipient domain]
- staff@[recipient domain]
- noreply@[recipient domain]
- support@[recipient domain]
Mails subjects are composed from the following:- E-mail account security warning.
- Notify about using the e-mail account.
- Warning about your e-mail account.
- Important notify about your e-mail account.
- Email account utilization warning.
- Notify about your e-mail account utilization.
- E-mail account disabling warning.
Mail bodies are created from multiple parts:1. Intro:- Dear user of [recipient domain],
- Dear user of [recipient domain] gateway e-mail server
- Dear user of e-mail server "[recipient domain]
- Hello user of [recipient domain] e-mail server,
- Dear user of "[recipient domain]" mailing system,
- Dear user, the management of [recipient domain] mailing system wants to let you know that,
2. Main body: - Your e-mail account has been temporary disabled because of unauthorized access.
- Our main mailing server will be temporary unavaible for next two days, to continue receiving mail in these days you have to configure our free auto-forwarding service.
- Your e-mail account will be disabled because of improper using in next three days, if you are still wishing to use it, please, resign your account information.
- We warn you about some attacks on your e-mail account. Your computer may contain viruses, in order to keep your computer and e-mail account safe, please, follow the instructions.
- Our antivirus software has detected a large ammount of viruses outgoing from your email account, you may use our free anti-virus tool to clean up your computer software.
- Some of our clients complained about the spam (negative e-mail content) outgoing from your e-mail account. Probably, you have been infected by a proxy-relay trojan server. In order to keep your computer safe, follow the instructions.
3. More information:- For more information see the attached file.
- Further details can be obtained from attached file.
- Advanced details can be found in attached file.
- For details see the attach.
- For details see the attached file.
- For further details see the attach.
- Please, read the attach for further details.
- Pay attention on attached file.
4. Closing:- The Management
- Sincerely,
- Best wishes,
- Have a good day,
- Cheers,
- Kind regards,
The [recipient domain] team http://www.[recipient domain]
5. Attachment:- Attach
- Information
- Readme
- Document
- Info
- TextDocument
- TextFile
- MoreInfo
- Message
File extension will be EXE, PIF or ZIP. ZIP files are passwordprotected with a 5-digit password, and in these cases the mail will also contain one of the following statements: - For security reasons attached file is password protected. The password is "[password]".
- For security purposes the attached file is password protected. Password is "[password]"
- Attached file protected with the password for security reasons. Password is [password].
- In order to read the attach you have to use the following password: [password].
|