Concept Virus(CV) V.5 - Quick analysis update

From: Olle Segerdahl (olle@defcom.com)
Date: 09/18/01


Message-ID: <3BA76F2E.D775EDA7@defcom.com>
Date: Tue, 18 Sep 2001 17:58:39 +0200
From: Olle Segerdahl <olle@defcom.com>
To: bugtraq@securityfocus.com, incidents@securityfocus.com
Subject: Concept Virus(CV) V.5 - Quick analysis update


More infectation routes:

The worm, upon infecting a new host, goes through all the
shared directories and their subdirecories and plants the
following files in each dir:

sample.nws
sample.eml
desktop.eml
desktop.nws

which are eml messages with copies of itself ("readme.exe")
autoloaded by a html script tag,

riched20.dll

which is a trojan dll version of itself probably designed
to infect people running notepad/wordpad in that dir.

It also infects htm/html/asp files all over the system with
a <SCRIPT> tag appendage that links to a readme.eml file in
the current directory, thus infecting more webservers and
even windows helpsystem and the IE "freindly" error messages.

The worm puts a trojan mmc.exe in the winnt directory that
is a copy of itself in the above "readme.exe" format.....

So in short: This thing spreads vi fileserver shares and
also infects all web content files it sees, it's EVIL.

/olle

----------------------------------------------------------------------------
This list is provided by the SecurityFocus ARIS analyzer service.
For more information on this free incident handling, management
and tracking system please see: http://aris.securityfocus.com



Relevant Pages

  • AIM Worm Spreads; Worse Than Expected
    ... The W32/Sdbot-ADD worm infecting some users of AOL Instant Messenger ... East, according to Facetime researchers. ... The attackers are installing ...
    (comp.dcom.telecom)
  • Re: 1 week of searching FAQ for the answer to these two questions
    ... cause the execution of an infected "subject line" or ... >Many viruses, like the Swen Internet worm, use a MIME ... >to be executed thus infecting the platform.. ... >|>| question in their section on Outlook and virus risk. ...
    (microsoft.public.scripting.virus.discussion)
  • Tricky Windows Worm Wallops Millions [Telecom]
    ... Tricky Windows Worm Wallops Millions ... infected laptop plugged into a vulnerable corporate network can ... But the worm also has methods for infecting systems that are already ...
    (comp.dcom.telecom)
  • Conficker worm biting 50K new Windows systems perday.
    ... Media coverage of the Conficker superworm has died down over recent weeks but variants of the worm are still infecting 50,000 new PCs a day. ... Conficker infects a Windows system by either exploiting systems unprotected against the MS08-067 vulnerability patched by Microsoft back in April, or by taking advantage of weak password security to spread across network shares. ...
    (comp.sys.mac.advocacy)
  • Re: 1 week of searching FAQ for the answer to these two questions
    ... |>Many viruses, like the Swen Internet worm, use a MIME ... |>to be executed thus infecting the platform.. ... |>Then read the Microsoft write-up "Incorrect MIME Header ... |>|>| question in their section on Outlook and virus risk. ...
    (microsoft.public.scripting.virus.discussion)

Quantcast