Download TrojanHunter Now
Free 30-day trial!
Latest TrojanHunter Version:
TrojanHunter 5.0
Order Now
License file delivered within minutes.
Welcome, Guest. Please Login or Register.
Jan 8th, 2009, 1:15pm
   Mischel Internet Security Forum
   Malware
   Trojans
(Moderators: Helena, Gavin_Coe, Magnus)
   Mimail.L. Mimail.M, and Gaobot.BK
« Previous topic | Next topic »
Pages: 1  Reply Reply  Notify of replies Notify of replies   Send Topic Send Topic   Print Print
   Author  Topic: Mimail.L. Mimail.M, and Gaobot.BK  (Read 376 times)
Ian
Stole All the Forum Stars
********



Good things come to those who wait ...

   


Posts: 2913
Mimail.L. Mimail.M, and Gaobot.BK
« on: Dec 13th, 2003, 3:18pm »
Quote Quote  Modify Modify

Three worms: the L and M variants of Mimail, and Gaobot.BK.

Mimail.L and Mimail.M spread via e-mail in a message which includes a file which in turn includes another file with a double extension. Both worms use their own SMTP engine to send themselves to all the addresses they find. They also carry out Denial of Service (DoS) attacks against various servers and register themselves as Windows services, to avoid appearing in the list of processes in the task administrator. The differences between the two variants are as follows:
 
- The subject field of the e-mail, as Mimail.L either has no subject field or includes the text "Re[2]we are going to bill your credit card", while the e-mail carrying Mimail.M is titled "Re: GREG" or "Re[3]" followed by a series of random characters.    
 
- The attachment names which include, in the case of Mimail.L, WENDY.ZIP and FOR_GREG_WITH_LOVE.JPG.EXE, while for Mimail.M they could be -in addition to WENDY.ZIP-: only_for_greg.zip, for_greg.jpg.exe and Wendy.Exe.
 
- The servers they attack.
 
- The modifications they make to the Windows registry on the victim computer.
 
Gaobot.BK - in order to spread to as many computers as possible, this exploits the RPC DCOM and WebDAV vulnerabilities. It also spreads by copying itself to shared network resources, which it access by 'guessing' simple or common passwords. A clear indication that Gaobot.BK is affecting a computer is a considerable increase in network traffic in TCP ports 135 and 445, due to the attempts it makes to exploit the security vulnerabilities.
 
When Gaobot.BK runs, it connects to a specific IRC server and waits for control commands. It could allow an attacker to get information from the affected computer, run files, launch Distributed Denial of Service (DDoS) attacks, upload files by FTP, etc. It also terminates processes in antivirus programs, firewalls and system monitoring tools, leaving the PC vulnerable to future attacks from worms and viruses. Gaobot.BK  also terminates processes of Nachi.A, Autorooter.A, Sobig.F and several variants of Blaster.
IP Logged

... but crap arrives pretty much straight away.
claire
Stole All the Forum Stars
********



carpe diem

   


Gender: female
Posts: 3479
Re: Mimail.L. Mimail.M, and Gaobot.BK
« Reply #1 on: Dec 13th, 2003, 11:21pm »
Quote Quote  Modify Modify

Thanks for the info Ian,
 
It's good to see you're back Smiley
IP Logged

Claire
Ian
Stole All the Forum Stars
********



Good things come to those who wait ...

   


Posts: 2913
Re: Mimail.L. Mimail.M, and Gaobot.BK
« Reply #2 on: Dec 15th, 2003, 6:25pm »
Quote Quote  Modify Modify

Yeah, just in time for the Christmas rush!
 
There'll be a New Year sale later, when all of my postings will be available at
half-price half-price half-price half-price half-price half-price half-price half-price half-price half-price half-price half-price half-price half-price
...! Sign up now; this event is not available in the shops Grin
IP Logged

... but crap arrives pretty much straight away.
Pages: 1  Reply Reply  Notify of replies Notify of replies   Send Topic Send Topic   Print Print

« Previous topic | Next topic »
Search
Members
Login
Register