Home→Descriptions→Worm.SymbOS.Comwar.a
| Detected | Mar 10 2005 08:09 GMT |
| Released | Dec 19 2005 14:46 GMT |
| Published | Mar 10 2005 08:09 GMT |
This is the first worm for mobiles phones which is able to propagate via MMS.
It infects telephones running under OS Symbian Series 60.
The executable worm file is packed into a Symbian archive (*.SIS). The archive is approximately 27 - 30KB in size. The name of the file varies: when propagating via Bluetooth, the worm creates a random file name, which will be 8 characters long, e.g. bg82o_s1.sis
Once launched, the archive will be unpacked to \system\apps\CommWarrior\:
\system\apps\CommWarrior\commwarrior.exe \system\apps\CommWarrior\commrec.mdl
The commwarrior.exe file will then copy both files, and the original archive to \system\updates\:
\system\updates\commwarrior.exe \system\updates\commrec.mdl \system\updates\commw.sis
The worm propagates via Bluetooth and MMS.
Once launched, the worm will search for accessible Bluetooth devices and send the infected .SIS archive under a random name to these devices. In order to open the attachment (which will consequently infect the telephone) the user will have to confirm several times that he wishes to receive the file.
The worm also sends itself via MMS to all contacts in the address book. The subject and text of the messages varies:
The worm contains the following text:
CommWarrior v1.0b (c) 2005 by e10d0r CommWarrior is freeware product. You may freely distribute it in it's original unmodified form. OTMOP03KAM HET!
The last line, in Russian, means roughly 'No to stupid people!'
Worms spread on computer networks via network resources. Unlike Net-Worms, a user must launch a Worm in order for it to be activated.
This kind of worm searches remote computer networks and copies itself to directories that are read/write accessible (if it finds any). Furthermore, these worms either use built-in operating system functions to search for accessible network directories and/or they randomly search for computers on the Internet, connect to them, and attempt to gain full access to the disks of these computers.
This category also covers those worms which, for one reason or another, do not fit into any of the other categories defined above (e.g. worms for mobile devices).
Worm.