Archive for the 'peacomm' Category

Forecast - Massive Storms clouded by Rootkits

Friday, April 13th, 2007

Update: July 9th 2007 - see Abnormal activity from your IP…yeah sure 

Over the last 2 days there has been what seems to be a massive Virus outbreak caused by the Storm Worm. The Storm worm was first introduced to us January when large storms were battering Europe a worm was spammed out disguised as important news on the storm with subject lines like “230 dead as storm batters europe”.
The next time the Storm Worm was unleashed was around Valentines Day when emails pretending to be from a lover were spammed out to millions of people across the Internet. Then last weekend a new Storm surge was spammed out as news of World War 3 starting against Iran and love related subjects like “A kiss so gentle” or “I dream of you”.

The latest Storm run was seen on the radar about 6 PM GMT on Thursday and within 24 hours over 55 million emails were sent out by the Worm according to Postini, an email security company. This is over 60 times the normal rate for a “normal” 24 hour period.

The subject lines currently being used are:
Worm Detected!
Virus Detected!ected!
Virus Activity Detected!
ATTN!
Spyware Alert!
Spyware Detected!
Warning!
Trojan Alert!
Trojan Detected!
Worm Activity Detected!
Virus Alert!

The Body of the email may look similar to the following:

From: Customer Support

Dear Customer,
Our robot has detected an abnormal activity from your IP address on sending e-mails.

Probably it is connected with the last epidemic of a worm which does not have official patches at the moment. We recommend you to install this patch to remove worm files and stop email sending, otherwise your account will be blocked. We had archived the patch because the worm can modify unpacked exe files. You should open the archive file, enter the password and run the patch immediately.

Password: {Random}

Customer Support Center Robot.

Attachment: Patch-{Random}.zip
Attachments:

It arrives with 2 attachments. One attachment is normally a gif, more about this later and the other attachment is a zip file with a password.

The format the zip files take is one of the following:
patch-[RANDOM 4 DIGITS].zip
removal-[5 RANDOM DIGITS].zip
hotfix-[5 RANDOM DIGITS].zip
bugfix-[5 RANDOM DIGITS].zip

The use of a password protected zip file is a new tactic used by the Storm Worm. Random numbers and letters are used for each attachment in the email that is sent out. The password for the attachment is given with the email. The file within the zip, when run, will install the Storm Worm on your PC and hide itself from Virus Scanners by using a Rootkit. The Rootkit component is wincom32.sys and from using anti rootkit software it can be seen to ensure its visibility by hooking the following:

Rootkit Elements: 

SSDT
ZwEnumerateKey
C:\WINDOWS\system32\wincom32.sys

SSDT
ZwEnumerateValueKey
C:\WINDOWS\system32\wincom32.sys

SSDT
ZwQueryDirectoryFile
C:\WINDOWS\system32\wincom32.sys

IRP
\Driver\Tcpip->IRP_MJ_DEVICE_CONTROL
\\??\C:\WINDOWS\system32\wincom32.sys

and it also hides registry entries pointing to the wincom32.sys.

Although Anti Virus Scanners will not “see” these files you can get a dedicated Anti-Rootkit program from our Anti-Rootkit Software Page.
Anubis have an extremely in-depth analysis of a sample submitted to them.
http://analysis.seclab.tuwien.ac.at/result.php?taskid=0ce16256cab3e414c180082fafc8d4b4&refresh=1&embedded=1

Tactics:

The reason this particular Storm Worm run has become so massive is that the authors have employed some new tactics and some old trustworthy tactics.The new tactics include using an image file which has the text of the message. This means that anti virus scanners can not scan an email for suspicious text. This tactic has been recently employed by spammers to bypass anti spam mechanisms.
The tactic of the password zip file is not new and has been used in the past by many worms including the infamous Bagle. What is new to the Storm Worm is the polymorphic features of the code. Each worm is going to be slightly different so as to better avoid detection by anti virus email scanners.
The tactic of informing people that they have malware on their PC is not new either but it is effective. This is especially effective because of the limited run a few days before. This run got the Storm Worm in the media and then the Thursday run with all its new mechanisms may have piggy backed on the fear people may have that they are infected.

 

Behind the Scenes:

So what and who is behind the Storm Worm. It is thought that the worm is originating from Eastern Europe and is spammed out so as to get as many victims to start the ball rolling initially. The worm the spreads from PC to PC via its own email program using addresses from the users email address book. Once on a users PC the worm joins the PC up to a massive Botnet comprised of thousands of unsuspecting users PC’s. The Botnet is then used to send out massive amount of what is called Pump and Dump Spam. This is where  Stock is advertised at low prices and it expectant value is very high. When unsuspecting users buy this stock they will help the price of the stock to go up. When the price of the stock goes up the Stock is sold off by the originator of the Pump and Dump spam at emmense profits.

The Storm Worm runs on Windows 98, ME, NT, 2000, XP, and Windows Server 2003.

The fact that this Storm run is so massive just goes to show that PC users all over the world are opening up encrypted zipped attachments from strangers and running the code. :-(

Keep Safe
regards

Steo
www.antirootkit.com

References:

The Eye of the Storm

Storm Worm blows up, breaks records

WORM_NUWAR.AOP

Consumer alert: Massive virus outbreak

Massive spam shot of ‘Storm Trojan’ reaches record proportions

Latest wincom32 peacomm rootkit has bugs

Tuesday, January 23rd, 2007

In a follow up to the post : New Storm-Worm Rootkit creating Botnets here is an update. 

It has been reported that the authors of the Storm Worm which uses a rootkit called wincom32 have changed their code and tactics to try and avoid detection but in doing so have left bugs in the code.

To check your system for this rootkit please download an anti-rootkit scanner.

First of all there are now more subjects attached to the emails containing the worm:

Chinese missile shot down USA aircraft
Chinese missile shot down USA satellite
Fidel Castro dead.
First Nuclear Act of Terrorism!
Happy World Religion Day!
Hugo Chavez dead.
President of Russia Putin dead
Radical Muslim drinking enemies’ blood.
Russian missle shot down Chinese satellite
Russian missle shot down USA aircraft
Russian missle shot down USA satellite
Sadam Hussein alive!
Sadam Hussein safe and sound!
Safe and Sound
The commander of a U.S. nuclear submarine lunch the rocket by mistake.
The Supreme Court has been attacked by terrorists. Sen. Mark Dayton dead!
Third World War just have started!
U.S. Secretary of State Condoleezza Rice has kicked German Chancellor Angela Merkel
U.S. Southwest braces for another winter blast. More then 1000 people are dead.
Venezuelan leader: “Let’s the War beginning”.

and some love related subjects:

A Bouguet of Love
A Day in Bed Coupon
A Monkey Rose for You
A Red Hot Kiss
Against All Odds
All That Matters
Baby, I’ll Be There
Back Together
Breakfast in Bed Coupon
Can’t Wait to See You!
Cyber Love
Dinner Coupon
Dream Date Coupon
Emptiness Inside Me
Fields Of Love
For You
Full Heart
I Believe
I Can’t Function
I Dream of You
I Think of You
Internet Love
It’s Your Move
Kiss Coupon
Love Birds
Love You Deeply
Made for Each Other
Miracle of Love
Moonlit Waterfall
My Invitation
Our Love
Our Love is Free
Our Two Hearts
Passionate Kiss
Pockets of Love
Puppy Love
Red Rose
Sending You My Love
Showers of Love
Someone at Last
Soul Partners
Summer Love
Take My Hand
That Special Love
The Dance of Love
The Long Haul
The Love Bugs
This Day Forward
This Feeling
Till Morning’s Light
Till Morninig’s Light
The Mood for Love
To New Spouse
Together Again
Together You and I
Touched by Love
Twice Blest
Until the Day
We’re a Perfect Fit
Wild Nights
Will you?
When I’m With You
Worthy of You
Wrapped Up
Wrapped in Your Arms
You are our of this world
You Lucky Duck!
You Rock Me!
You Were Worth the Wait

The attachment may now have one of the following names:

GreetingPostcard.exe
MoreHere.exe
FlashPostcard.exe
GreetingCard.exe
ClickHere.exe
ReadMore.exe
FlashPostcard.exe
FullNews.exe

It firstly drops a file called wincom32.sys in one of the following folders:

C:\Windows\System (Windows 95/98/Me)
C:\Winnt\System32 (Windows NT/2000)
C:\Windows\System32 (Windows XP)

It creates a service and creates the following registry entry to start it when the PC starts up:

HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\wincom32

The worm then tries to connect to various other bots and download more malware so that it can do it’s primary job, to send out penny stock spam. Increased spam has been seen in the last few days.

The latest version of the bot now tries to communicate with other bots on port 7871 instead of 4000 as in the previous version.

The authors have included more rootkit functionality to this version. But this rootkit contains a few bugs and has been known to crash some systems.

“It is now capable of hiding several files and registry keys by hooking several kernel functions and patching the tcpip.sys system driver to hide its ports from commands, such as netstat -o or netstat -b. However, due to some mistakes in the rootkit code, running netstat -an lets you see ports 7871 or 4000 open and waiting for connections. It is also important to note that a personal firewall will also notify you of the process services.exe trying to make connections on these ports. Furthermore, the rootkit service can be stopped by running a simple command: net stop wincom32. All files, registry keys, and ports will appear again.”
Symantec

The rootkit also checks to see if the system it is running on is a Windows 2003 machine, as it seems that the authors have not fully tested it on Windows 2003.

This latest attack change is interesting as it shows the attackers are constantly changing their tactics in the light of discoveries by anti malware companies. The attackers are also using new news headlines for the latest attacks and hoping to dupe more people into catching the worm. It seems the attackers are blatantly sticking their noses up at the anti malware industry using their new and expanding peer to peer botnet.

References:

Trojan.Peacomm Part 2 – The Botnet Evolves

Stormy Love

Stay Safe

regards

Steo
www.antirootkit.com