Skip to main content

worm per Windows


-----BEGIN PGP SIGNED MESSAGE-----
Hash: SHA1

******************************************************************
 
  Alert ID: A-03001C
 
  Data di creazione:  Tue Jan 14 10:50:31 CET 2003

  Titolo: worm per Windows 
 
  Gravita': alta
 
******************************************************************

Salve,
la Befana ha portato un paio di nuovi virus da tenere sotto controllo, oltre
ai tanti che gia' circolavano.

Uno di questi sfrutta il ben noto bug di Outlook nella gestione degli
attachment che consente l'esecuzione degli eseguibili in allegato ai mail in
fase di lettura o preview del messaggio. Maggiori informazioni su questo bug
possono essere reperite all'indirizzo:
http://www.microsoft.com/technet/security/bulletin/MS01-020.asp.
Il worm W32.Lirva.* sfrutta questo bug e si diffonde via email, inviando
anche le password di connessione dial-up e disattivando antivirus e firewall
in esecuzione sulla macchina infettata.

Ecco un estratto di un advisory sull'argomento [1]:

W32.Lirva.C@mm is a mass-mailing worm that also spreads by IRC, ICQ, KaZaA,
and open network shares. It is a variant of W32.Lirva.A@mm . This worm
attempts to terminate antivirus and firewall products. It also emails the
cached Windows 95/98/Me dial-up networking passwords to the virus writer.

The worm connects to a Web site on web.host.kz/ and downloads BackOrifice,
which it executes. W32.Lirva.C@mm also attempts to download another file,
which is currently not present on the Web site.

When Microsoft Outlook receives the worm, it takes advantage of a
vulnerability that allows the attachment to auto-execute when you read or
preview the email. Information on this vulnerability and a patch can be
found at http://www.microsoft.com/technet/security/bulletin/MS01-020.asp.

If the day of the month is the 7th, 11th, or 24th, the worm will launch your
Web browser to www.avril-lavigne.com and display a graphic animation on the
Windows desktop.

Also Known As: Win32.Lirva.B [CA], W32/Avril-B [Sophos], WORM_LIRVA.C
[Trend], I-Worm.Avron.b [KAV], W32/Lirva.c@MM [McAfee]
Type: Worm
Infection Length: 34,815 bytes
Systems Affected: Windows 95, Windows 98, Windows NT, Windows 2000, Windows
XP, Windows Me
Systems Not Affected: Macintosh, OS/2, UNIX, Linux


L'altro e' invece un worm che si propaga cercando sulla rete dischi
condivisi e privi delle necessarie protezioni in scrittura e si invia
anch'esso tramite email in forma di attachment.

Cito dall'advisory [2]:

W32.ExploreZip.L.Worm is a variant of Worm.ExploreZip, a worm that contains
a malicious payload. The file has been repacked to make it more difficult to
detect with older, existing antivirus software. This worm is packed with the
UPX file format, version 0.76.1-1.24.

The worm uses Microsoft Outlook, Outlook Express, or Exchange to mail
itself, by replying to unread messages in the Inbox. The email attachment is
titled Zipped_files.exe.

W32.ExploreZip.L.Worm also searches the mapped drives and network computers
for Windows installations. If they are found, the worm copies itself to the
Windows folder of the remote computer, and then modifies the Win.ini file
of the infected computer.

Definitions dated from January 8, 2003 to January 10, 2003 will detect this
worm as Worm.ExploreZip.

Also Known As: W32/ExploreZip.worm@M [McAfee], I-Worm.ZippedFiles.h [KAV],
WORM_EXPLORZIP.M [Trend], Win32/ExploreZip.Worm [CA], W32/ExploreZip.E
[F-Secure], W32/ExploreZip.worm.210432 [F-Secure], W32/ExploreZi-N [Sophos]
Type: Worm
Infection Length: 91,048 [UPX], 210,432 [uncompressed]
Systems Affected: Windows 95, Windows 98, Windows NT, Windows 2000, Windows
XP, Windows Me
Systems Not Affected: Windows 3.x, Macintosh, OS/2, UNIX, Linux

Per quest'ultimo si puo' arginare il problema filtrando a livello di router
le porte netbios-ssn e affini (l'elenco delle porte lo potete trovare su
http://www.iana.org/assignments/port-numbers ) mentre per il primo e'
necessario eliminare il bug di Windows e utilizzare un antivirus o un
removal tool.

Maggiori informazioni le potrete trovare agli indirizzi riportati di seguito.

cordiali saluti e auguri di buon anno!

massimo ianigro


Riferimenti:
[1]
http://securityresponse.symantec.com/avcenter/venc/data/Questo indirizzo email è protetto dagli spambots. È necessario abilitare JavaScript per vederlo.
[2]
http://securityresponse.symantec.com/avcenter/venc/data/w32.explorezip.l.worm
.html
[3] http://vil.mcafee.com/dispVirus.asp?virus_k=99949
[4]
http://www.microsoft.com/technet/treeview/default.asp?url=/technet/security/b
ulletin/MS01-020.asp
[5] http://www.f-secure.com/v-descs/lirva_b.shtml
[6]
http://www.trendmicro.com/vinfo/virusencyclo/default5.asp?VName=WORM_LIRVA.C


Appendice

  GARR-CERT Home Page:  http://www.cert.garr.it


- - --

 

Alert di GARR-CERT Usata per la segnalazione di allarmi di sicurezza e comunicazioni di interesse generale diretti agli enti GARR. L'iscrizione è aperta e consigliata a tutti, il posting è riservato ai membri di GARR-CERT