Home→Blog→Incidents→May 29 2012→Flame: Bunny, Frog, Munch and BeetleJuice…
| Beetlejuice | Bluetooth: enumerates devices around the infected machine. May turn itself into a “beacon”: announces the computer as a discoverable device and encode the status of the malware in device information using base64. |
| Microbe | Records audio from existing hardware sources. Lists all multimedia devices, stores complete device configuration, tries to select suitable recording device. |
| Infectmedia | Selects one of the methods for infecting media, i.e. USB disks. Available methods: Autorun_infector, Euphoria. |
| Autorun_infector | Creates “autorun.inf” that contains the malware and starts with a custom “open” command. The same method was used by Stuxnet before it employed the LNK exploit. |
| Euphoria | Create a “junction point” directory with “desktop.ini” and “target.lnk” from LINK1 and LINK2 entries of resource 146 (were not present in the resource file). The directory acts as a shortcut for launching Flame. |
| Limbo | Creates backdoor accounts with login “HelpAssistant” on the machines within the network domain if appropriate rights are available. |
| Frog | Infect machines using pre-defined user accounts. The only user account specified in the configuration resource is “HelpAssistant” that is created by the “Limbo” attack. |
| Munch | HTTP server that responds to “/view.php” and “/wpad.dat” requests. |
| Snack | Listens on network interfaces, receives and saves NBNS packets in a log file. Has an option to start only when “Munch” is started. Collected data is then used for replicating by network. |
| Boot_dll_loader | Configuration section that contains the list of all additional modules that should be loaded and started. |
| Weasel | Creates a directory listing of the infected computer. |
| Boost | Creates a list of “interesting” files using several filename masks. |
| Telemetry | Logging facilities |
| Gator | When an Internet connection becomes available, it connects to the C&C servers, downloads new modules, and uploads collected data. |
| Security | Identifies programs that may be hazardous to Flame, i.e., anti-virus programs and firewalls. |
| Bunny Dbquery Driller Headache Gadget |
The purpose of these modules is not yet known. |
P.S. We have checked the information as suggested in the comments at our blogpost regarding a possible relation to FLAME (Flexible Lightweight Active Measurement Environment) software from Brazil.
Interestingly, the name picked by us fully matches that software, which also uses LUA for implementing business logics. The FLAME software is used to measure network characteristics by deploying measurement agents and collecting data in a central database. Despite some similarities, we think that this software is unrelated as it serves different objectives. Besides the LUA engine, the core of communication in FLAME is XMPP protocol, which is not used in the Flame malware.
The authors might have been inspired by the FLAME project and re-implemented similar architecture - only for the different goal, or this is all just a coincidence. We don't have any other reason to think that it is somehow related to the Flame malware.|
2012 May 30, 04:50
Tilded? It's curious that in the first Flame article (The Flame: Questions and Answers) you state "Flame does not use the Tilded platform." But, in this article the first step to detection of the Flame on a system is to search for "~DEB93D.tmp", which begins with ~D. In a previous Kaspersky Stuxnet/Duqu article it was stated that the platform was called "'Tilded' (because of the tendency of its creators to use files that start with the tilde symbol (~))." |
|
2012 May 30, 05:42
|
|
2012 May 30, 05:47
Re: Re: Tilded? Coincidence or not these duqu/stuxnet and now flame blog posts have been very interesting. Thanks for the great info Aleks! |
|
2012 May 30, 17:42
|
|
2012 May 31, 15:43
Network behaviour Are there any known facts about the network spreading- / scanning- / communication-behavior of Flame? |
|
2012 May 31, 17:14
Estoy infectado Lamentablemente encontre los archivos. Resulta que note muy lenta mi pc y ademas ataques a mi sitio web. Desde diferentes ip intentaban ingresar a mi pc. Uno delos virus era el d1.exe (no se si tiene relacion) pero activando diferentes antivirus bloqueaban muchas ip entonces decidi averiguar sobre este virus y finalmente lo descubri. Me aseguran que con Kaspersky se elimina? y graciaspor toda la info.Unfortunately I found the files. It is very slow to notice my pc and also attacks on my website. From different ip tried accessing my pc. One virus was d1.exe models (not if you have relationship) but activating different antivirus blocked many ip so I decided to find out about this virus and eventually discovered. I say that Kaspersky is removed? Thank youfor and all the info. Edited by Hector Luis, 2012 May 31, 17:28 |
|
2012 May 31, 17:22
No permite utilizar antivirus Olvide comentar que me fue imposible de utilizar el antivirus de Kaspersky en cuanto lo queria instalar me salia una leyenda que era imposible porque faltaban archivos. En estos momentos estoy bajando la version de prueba de Kaspersky Internet Security 2012 y les informare de los sucesos |
|
2012 May 31, 17:56
|
|
2012 May 31, 19:52
You mentioned the source code of the MOF file above; what's the batch file look like? I'm assuming it just starts the malware using rundll32 or some such, but there could be more to it. |
|
2012 May 31, 20:40
install and probe Kaspersky antivirus even after all this shown in HKEY_CURRENT_USER/Software/Microsoft/Search Assistant/Acmru/5630/(all files mentioned in this forum) |
|
2012 May 31, 20:43
search words windows xp They may be the search words you make after reading this forum and these are not files. |
|
2012 May 31, 20:46
|
|
2012 May 31, 22:29
Preventing Spearphishing Users would be less vulnernerable to deception if they used SP Guard from Iconix. |
|
2012 May 31, 23:22
hash MD5: bdc9e04388bda8527b398a8c34667e 18 |
|
2012 May 31, 23:59
Tganks but Kaspersky still does not eliminate di.exe Continuously on startup and detects viruses di.exe |
|
2012 Jun 01, 00:01
Flame Remover Link Download: Edited by Mehdi Ilbeigi, 2012 Jun 01, 00:55 |
|
2012 Jun 01, 09:14
Use Bitdefender Removal Tool http://labs.bitdefender.com/wp-content/uploads/downloads/2012/05/TrojanFlamer_BDRemovalToolDrop per_x86.exe |
|
2012 Jun 01, 13:03
List of C C? Hello, |
|
2012 Jun 02, 18:51
|
|
2012 Jun 02, 18:53
Re: No permite utilizar antivirus Recuerde que también puede desinfectar su máquina con nuestra herramienta gratuita que se llama Kaspersky Virus Removal Tool y que se puede descargar desde http://www.kaspersky.com/antivirus-removal-tool-register No requiere instalación y puede ser utilizada paralelamente a cualquier AV que tenga en su máquina. |
|
2012 Jun 04, 02:02
The article seems really interesting, I myself is a programmer and a kind of hacker (not black hat) and just love coding simple but most effective trojan. |
|
2012 Jun 04, 02:28
Windows only or Mac as well? Does flame only affect the windows operation system, or also mac os x? I ask, as if it does, how could we search for the infection? Thoughts? |
|
2012 Jun 04, 16:50
and does it use ftp.exe to upload data to their server ? |
|
2012 Jun 05, 08:19
Does bunny have any relationship to rabbIT? http://www.khelekore.org/rabbit/ |
|
2012 Jun 12, 19:44
In front of me... I feel that something is weird with that virus.. |
|
2012 Jul 07, 07:29
HelpAssistant and more Couple of things I found curious.. |
|
2013 Jan 02, 00:50
Why is the program several MBs of code? What functionality does it have that could make it so much larger than Stuxnet? How come it wasn’t detected if it was that big? |
Analysis
Blog