190 likes | 455 Views
Mass Mailing Worm. Powered By: Nikhil Bendre Gauri Jape. What is ‘ Computer Worm’ ?. Programs that reproduce, execute independently and travel across the network connections. The key difference between a virus and worm is the manner in which it reproduces spreads .
E N D
Mass Mailing Worm Powered By: Nikhil Bendre Gauri Jape
What is ‘ Computer Worm’ ? • Programs that reproduce, execute independently and travel across the network connections. • The key difference between a virus and worm is the manner in which it • reproduces • spreads.
Types Of Computer Worms • E-Mail Worms (Mass Mailing Worm) • Instant Messaging Worm • Internet Worm • File Sharing Worm • IRC Worm
Details Of E-Mail Worm • Spread Through Infected E-mail • Consume Valuable Internet Resources • Use As a vehicle for DDoS (Distributed Denial Of Service Attack)
Examples • “ILoveYou” } } spread in 2000-2001 • “AnnaKournikova” } • Latest, • “Here You Have” } 2010
‘Here You Have’ • Subject Line Indicator • Detection in September • 9th Sept 2010 • McAfee Avert Labs • Detects as Virus W32/VBMania@MM
W32/VBMania@MM • Type Virus • Sub Type Worm • Discovery Date 09/09/2010 • Length Varies • Minimum DAT 6101 (09/09/2010) • Updated DAT 6104 (09/12/2010) • Minimum Engine 5.4.00 • Description Added 09/09/2010 • Description Modified 10/26/2010 9:12 AM (PT) • Written in VB
Locations • The worm copies itself into the following locations: • %WINDIR%\system\Administrator CV 2010.exe • %WINDIR%\system\updates.exe • %WINDIR%\Administrator CV 2010.exe • %WINDIR%\csrss.exe • %SYSTEMDRIVE%\Administrator CV 2010.exe • %SYSTEMDRIVE%\open.exe • %Removable Drive%\ open.exe
Registry • HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Services\lanmanserver\Shares\updates'CSCFlags = 0 MaxUses = 100 Path = %WINDIR%\system Permissions = 0 Remark = Public share for update. Type = 0' • HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\<PROCESS name><PROCESS name>\ • Debugger="%WINDIR%\csrss.exe"
Details • .SCR Executable • Starts with "Hello... this is the document I told you about, you can find it here." • “PDF” Link in Email
Worm Looks Like in Inbox • Subject: Here you have or Just For youBody: • Hello:This is The Document I told you about,youcan find it Here.http://www.sharedocuments.com/library/PDF_Document21.025542010.pdf • Please check it and reply as soon as possible. • Cheers,
Infection Here you Have- ‘Virus Attack’
Infection • User downloads the screen saver • Infected, once Downloaded
When Virus Runs • Installs itself as CSRSS.EXE in Windows Directory • Emails the Contents of Address Book • Tries to Download files • Deletes Security Software • Spread Itself
Spread • Through Remote Machines • Mapped Network Drives • Removable Media via Autorun Features • Outlook Express Users
Virus Sighted @ • ABC/ Disney • Google • Coca Cola • NASA • Comcast
Detection • On Thursday 9th Sept 2010 ,at 10 :30 pm Pacific Time Symantec • Started blocking the worm • The screensaver file taken down from multimedia.co.uk(Lycos Service) • Still more than 65000 spams reported
Remedy/ Solution • Do Not Click On suspicious link • Download Updated version of McAfee , Norton having updated virus definitions • Use Microsoft’s Free Security Essentials
END Happy Computer