Nume: Worm/SdBot.571392.1 Descoperit pe data de: 20/02/2008 Tip: Vierme ITW: Da Numar infectii raportate: Scazut Potential de raspandire: Mediu spre ridicat Potential de distrugere: Mediu Fisier static: Da Marime: 571.392 Bytes MD5: 672ebe523a7ebd0A884b5cb7d7dd3888 Versiune IVDF: 7.00.02.168
General Metode de raspandire: • Reteaua locala • Peer to Peer Alias: • Mcafee: W32/Sdbot.worm • Kaspersky: Backdoor.Win32.SdBot.cqd • F-Secure: Backdoor.Win32.SdBot.cqd • Sophos: W32/Sdbot-DKD • Grisoft: IRC/BackDoor.SdBot3.YIN • Eset: IRC/SdBot • Bitdefender: Backdoor.SDBot.DFPJ Sistem de operare: • Windows 95 • Windows 98 • Windows 98 SE • Windows NT • Windows ME • Windows 2000 • Windows XP • Windows 2003 Efecte secundare: • Inchide aplicatiile de securitate • Reduce setarile de securitate • Modificari in registri • Profita de vulnerabilitatile softului • Sustrage informatii • Posibilitatea accesului neautorizat la computer Fisiere Se copiaza in urmatoarea locatie: • %WINDIR% \svchost.exe Sterge copia initiala a virusului. Registrii sistemului Urmatoarele chei sunt adaugate in registri pentru a incarca serviciul la repornirea sistemului: – [HKLM\SYSTEM\CurrentControlSet\Services\ Generic Host Process for Win-32 Service] • Type = 110 • Start = 2 • ErrorControl = 0 • ImagePath = %WINDIR% \svchost.exe • DisplayName = Generic Host Process for Win-32 Service • ObjectName = LocalSystem • FailureActions = %valori hex% • Description = Generic Host Process for Win-32 Service – [HKLM\SYSTEM\CurrentControlSet\Services\ Generic Host Process for Win-32 Service\Security] • Security = %valori hex% Urmatoarele chei din registri sunt modificate: – [HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Shell Extensions] Noua valoare: • %combinatie de caractere aleatoare% = %fisier executat% – [HKLM\Software\Microsoft\Windows NT\CurrentVersion\Winlogon] Vechea valoare: • shell = explorer.exe Noua valoare: • shell = explorer.exe %WINDIR% \svchost.exe – [HKLM\Software\Microsoft\Windows NT\CurrentVersion\Winlogon] Noua valoare: • sfcdisable = 1113997 • sfcscan = 0 – [HKLM\Software\Microsoft\Security Center] Noua valoare: • antivirusdisablenotify = 1 • antivirusoverride = 1 • firewalldisablenotify = 1 • firewalloverride = 1 • updatesdisablenotify = 1 – [HKLM\Software\Policies\Microsoft\Windows\WindowsUpdate] Noua valoare: • donotallowxpsp2 = 1 – [HKLM\Software\Symantec\LiveUpdate Admin] Noua valoare: • enterprise security manager = 1 • ghost = 1 • intruder alert = 1 • liveadvisor = 1 • liveupdate = 1 • netrecon = 1 • norton antivirus product updates = 1 • norton antivirus virus definitions = 1 • norton cleansweep = 1 • norton commander = 1 • norton internet security = 1 • norton Systemworks = 1 • norton utilities = 1 • pc handyman and healthypc = 1 • pcanywhere = 1 • rescue disk = 1 • symantec desktop firewall = 1 • symantec gateway security ids = 1 • symevent = 1 – [HKLM\System\CurrentControlSet\Services\wscsvc] Noua valoare: • start = 4 – [HKLM\Software\Microsoft\OLE] Noua valoare: • enabledcom = 78 – [HKLM\Software\Microsoft\Windows\CurrentVersion\WindowsUpdate\ Auto Update] Noua valoare: • auoptions = 1 – [HKLM\System\CurrentControlSet\Control\ServiceCurrent] Noua valoare: • @ = 9 – [HKLM\System\CurrentControlSet\Control] Noua valoare: • waittokillservicetimeout = 7000 – [HKLM\System\CurrentControlSet\Control\LSA] Noua valoare: • restrictanonymous = 1 – [HKLM\System\CurrentControlSet\Services\LanManServer\Parameters] Noua valoare: • autoshareserver = 0 • autosharewks = 0 – [HKLM\System\CurrentControlSet\Services\LanManWorkstation\ Parameters] Noua valoare: • autoshareserver = 0 • autosharewks = 0 – [HKLM\System\CurrentControlSet\Services\Messenger] Noua valoare: • start = 4 – [HKLM\System\CurrentControlSet\Services\RemoteRegistry] Noua valoare: • start = 4 – [HKLM\System\CurrentControlSet\Services\tlntsvr] Noua valoare: • start = 4 Dezactiveaza Windows XP Firewall: – [HKLM\Software\Policies\Microsoft\WindowsFirewall\DomainProfile] Noua valoare: • enablefirewall = 0 – [HKLM\Software\Policies\Microsoft\WindowsFirewall\StandardProfile] Noua valoare: • enablefirewall = 0 Dezactivarea programelor Regedit si Task Manager: – [HKCU\Software\Microsoft\Windows\CurrentVersion\Policies\System] Noua valoare: • disableregistrytools = 1 • disabletaskmgr = 1 P2P Pentru a infecta alte sisteme din retele Peer-to-Peer, efectueaza urmatarele operatii: – Extrage fisierul partajat, folosind urmatoarea cheie de registru: • SOFTWARE\Kazaa\LocalContent\DownloadDir Reţea Pentru a-si asigura raspandirea, programul malware incearca sa contacteze alte sisteme, asa cum este descris in continuare: Exploit: – MS02-061 (Elevation of Privilege in SQL Server Web) – MS04-007 (ASN.1 Vulnerability) –MS06-040 (Vulnerability in Server Service) Procesul de infectare: Se creeaza un script FTP in sistemul afectat, pentru a descarcaun malware pe alt computer controlat la distanta. IRC Pentru a trimite informatii si pentru a fi controlat se conecteaza la serverul IRC: Server: www.worldcasino.to Port: 80 Nick: [P00|USA|%numar% ] – Acest malware poate obtine si trimite infomatii cum ar fi: • Parole retinute • Viteza procesorului • Utilizatorul curent • Informatii despre drivere • Spatiu liber pe disc • Memorie nealocata • Timpul de cand malware-ul a fost lansat in executie • Informatii despre procesele sistemului • Cantitatea de memorie • Utilizator • Informatii despre sistemul de operare – In plus, poate efectua urmatoarele operatii: • Lanseaza atacuri DDoS ICMP • Lanseaza atacuri DDoS SYN • Lanseaza atacuri DDoS UDP • dezactivarea partajarii de resurse in retea • descarcare fisier • editare registru sistem • activarea partajarii de resurse in retea • executarea unui fisier • intrare pe canal IRC • terminare proces • parasire canal IRC • deschidere consola • executare atac DDoS • Scaneaza reteaua • Porneste rutina de raspandire • terminare proces malware • terminare proces Backdoor Servere contactate: Unul dintre: • http://www2.dokidoki.ne.jp/tomocrus/cgi-bin/check/********** • http://www.kinchan.net/cgi-bin/********** • http://www.pistarnow.is.net.pl/********** • http://cgi.break.power.ne.jp/check/********** • http://www.proxy4free.info/cgi-bin/********** • http://69.59.137.236/cgi/********** • http://tutanchamon.ovh.org/********** • http://www.proxy.us.pl/********** • http://test.anonproxies.com/********** • http://www.nassc.com/********** • http://www.littleworld.pe.kr/********** • http://www.anonymitytest.com/cgi-bin/********** • http://tn0828-web.hp.infoseek.co.jp/cgi-bin/********** Astfel se pot transmite informatii si se poate obtine control la distanta. Furt de informatii Incearca sa obtina urmatoarele informatii: – Parole stocate, folosite de functia AutoComplete – Informatii despre contul de email, obtinute din cheia de registru: HKCU\SoftwareMicrosoft\Internet Account Manager\Accounts Alte informatii Cauta o conexiune Internet, contactand urmatorul website: • www.google.com Metode anti-debugging Verfica daca ruleaza unul din urmatoarele programe: • Softice • Wine • FileMon • Regmon Daca gaseste, isi termina executia imediat. Daca reuseste, nu creeaza fisiere. Modificare de fisiere: Pentru a intrerupe Windows File Protection (WFP), poate modifica fisierul sfc_os.dll la 0000E2B8. WFP are ca scop evitarea problemelor cunoscute ce cauzeaza inconsistenta in DLL. Detaliile fisierului Limbaj de programare: Limbaj de programare folosit: C (compilat cu Microsoft Visual C++). Compresia fisierului: Pentru a ingreuna detectia si a reduce marimea fisierului, este folosit un program de compresie runtime.Pentru o descriere scurta click aici . Descriere introdusa de Andrei Gherman la Mon, 16 Jun 2008 10:18 (GMT+1) Descriere actualizata de Robert Harja Iliescu la Thu, 24 Jul 2008 13:15 (GMT+1)