Zotob details



Here are some details on the zotob worm (s) culled from several sources….

It copies itself to the Windows system folder as BOTZOR.EXE, it modifies the hosts file to frustrate attempts to access antivirus sites. The .b variant copies itself as csm.exe in the Windows System folder. Both variants create a Mutex so that only one copy can run at a time.

According to Sarc the .b variant adds
“csm Win Updates” = “csm.exe”
to the registry at two locations

HKEY_LOCAL_MACHINESoftwareMicrosoftWindowsCurrentVersionRun
HKEY_LOCAL_MACHINESoftwareMicrosoftWindowsCurrentVersionRunServices

so that it runs at Windows boot. It also modifies
“Start” = “4″

to the registry subkey:

HKEY_LOCAL_MACHINESYSTEMCurrentControlSetServicesSharedAccess
disabling shared access.

It opens an ftp server on port 33333 (TCP), tries to connect to an IRC server to allow remote control of the PC, attempts to spread within the local subnet.

Also it drops 2pac.txt and haha.exe in the system folder.

The host file modifications are as follows:

11. …. Made By …. Greetz to good friend [REMOVED] in the next 24hours!!!

127.0.0.1 www.symantec.com
127.0.0.1 securityresponse.symantec.com
127.0.0.1 symantec.com
127.0.0.1 www.sophos.com
127.0.0.1 sophos.com
127.0.0.1 www.mcafee.com
127.0.0.1 mcafee.com
127.0.0.1 liveupdate.symantecliveupdate.com
127.0.0.1 www.viruslist.com
127.0.0.1 viruslist.com
127.0.0.1 viruslist.com
127.0.0.1 f-secure.com
127.0.0.1 www.f-secure.com
127.0.0.1 kaspersky.com
127.0.0.1 kaspersky-labs.com
127.0.0.1 www.avp.com
127.0.0.1 www.kaspersky.com
127.0.0.1 avp.com
127.0.0.1 www.networkassociates.com
127.0.0.1 networkassociates.com
127.0.0.1 www.ca.com
127.0.0.1 ca.com
127.0.0.1 mast.mcafee.com
127.0.0.1 my-etrust.com
127.0.0.1 www.my-etrust.com
127.0.0.1 download.mcafee.com
127.0.0.1 dispatch.mcafee.com
127.0.0.1 secure.nai.com
127.0.0.1 nai.com
127.0.0.1 www.nai.com
127.0.0.1 update.symantec.com
127.0.0.1 updates.symantec.com
127.0.0.1 us.mcafee.com
127.0.0.1 liveupdate.symantec.com
127.0.0.1 customer.symantec.com
127.0.0.1 rads.mcafee.com
127.0.0.1 trendmicro.com
127.0.0.1 pandasoftware.com
127.0.0.1 www.pandasoftware.com
127.0.0.1 www.trendmicro.com
127.0.0.1 www.grisoft.com
127.0.0.1 www.microsoft.com
127.0.0.1 microsoft.com
127.0.0.1 www.virustotal.com
127.0.0.1 virustotal.com
127.0.0.1 www.amazon.com
127.0.0.1 www.amazon.co.uk
127.0.0.1 www.amazon.ca
127.0.0.1 www.amazon.fr
127.0.0.1 www.paypal.com
127.0.0.1 paypal.com
127.0.0.1 moneybookers.com
127.0.0.1 www.moneybookers.com
127.0.0.1 www.ebay.com
127.0.0.1 ebay.com

This covers a wide net of sites (Amazon Paypal Ebay) beyond the usual security/antivirus sites.

The only difference I can see between .a and .b is the name of the executable (botzor.exe and csm.exe)

News.com also has more coverage.

Related Posts

Blog Traffic Exchange Related Posts
  • Different attitudes towards upgrading and developing software So many times, even in the last few days, I have talked about keeping software up-to-date. For many people that means upgrading to the latest version of windows as soon as it comes out, or Office, or well... fill in the blank. It's a vicious cycle when you think about......
  • McAfee Antivirus gives Windows XP Autoimmune disorder.... Bad day for McAfee antivirus users..... It looks like the corporate users were bit the hardest. An update this morning basically detected svchost.exe as a virus and sent machines (Windows 7 not affected - but XP SP3 was...) into a perpetual reboot cycle. The fix requires manual intervention and some......
  • How to Remove Anti-Virus Elite | Anti-Virus Elite Removal Guide Anti-Virus Elite is a rogue antivirus application. These rogue antivirus applications pose as a legitimate security application, but in reality is a scam to try to trick you out of money. They will find and claim that there are multiple security problems with your computer. They will claim that you......
Blog Traffic Exchange Related Websites
  • Rancho Solano Golf Course Ranch Solano Golf Course is located in Fairfield, CA Phone: 707-429-4653 Website: http://www.fairfieldgolf.com Course History: Rancho Solano is one of the two best courses in Fairfield, CA. It features a Par 72 course stretched out over more than 6,000 yards of playable space. It was designed by Gary Roger Baird......
  • Rehabilitation after Stroke in India Rehabilitation helps stroke survivors relearn skills that are lost when part of the brain is damaged. It helps build strength, coordination, endurance and confidence of the patient. The goal of stroke rehabilitation is to help one learn how to do things that he did before the stroke. In stroke rehabilitation,......
  • Club Med BOOK ONLINE Booking on our website is available 24 hours a day and offers a quick and easy way to book your holiday. Go directly to your Club Med Resort by using the ‘Direct access to resort page’ option at the top right of the homepage, or simply use......
en.pdf24.org    Send article as PDF   

Similar Posts


See what happened this day in history from either BBC Wikipedia
Search:
Keywords:
Amazon Logo

Comments are closed.


Switch to our mobile site