English
The Internet threat alert status is currently normal. At present, no major epidemics or other serious incidents have been recorded by Kaspersky Lab’s monitoring service. Internet threat level: 1

Net-Worm.Win32.Padobot.m

Detected Jun 24 2004 15:50 GMT
Released Jun 24 2004 15:50 GMT
Published Feb 14 2005 10:56 GMT

Technical Details

Padobot.m infects computers running under Windows. The worm itself is a Windows PE EXE file approximately 10KB in size, packed using UPX. The unpacked file is approximately 24KB in size.

The worm propagates by exploiting a vulnerability in Microsoft Windows LSASS. This vulnerability is described in detail in Microsoft Security Bulletin MS04-011

The worm contains a backdoor function.

Installation

Once launched, the worm copies itself to the Windows system directory under a random name. For example:

%System%\gytotrn.exe

Then the worm registers this file as a key in the system registry:

[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Run]
"Cryptographic Service" = "%System%\>random name<.exe"

This ensures that the worm will be launched each time the infected machine is rebooted.

It also creates a registry key:

[HKLM\SOFTWARE\Microsoft\Wireless]
"ID" = "<random value>"

It creates the mutex "uterm19" to flag its presence in the system.

Propagation

The worm starts its propagation routine, selecting IP addresses to attack, and sending a request to TCP port 445. If the remote computer responds, then the worm launches its code on the victim machine, by utilizing the LSASS vulnerability.

Other

The worm opens a random TCP port in order to receive commands. The backdoor function provides a malicious remote attacker with full access to the victim machine.

Padobot.m attempts to receive commands and transmit data, while connecting to several IRC channels:

  • adult-empire.com
  • asechka.ru
  • citi-bank.ru
  • color-bank.ru
  • crutop.nu
  • cvv.ru
  • fethard.biz
  • filesearch.ru
  • kavkaz.tv
  • kidos-bank.ru
  • konfiskat.org
  • master-x.com
  • mazafaka.ru
  • parex-bank.ru
  • roboxchange.com
  • www.redline.ru
  • xware.cjb.net

Bookmark and Share
Share
Net-Worm

Net-Worms propagate via computer networks. The distinguishing feature of this type of worm is that it does not require user action in order to spread.

This type of worm usually searches for critical vulnerabilities in software running on networked computers. In order to infect the computers on the network, the worm sends a specially crafted network packet (called an exploit) and as a result the worm code (or part of the worm code) penetrates the victim computer and activates. Sometimes the network packet only contains the part of the worm code which will download and run a file containing the main worm module. Some network worms use several exploits simultaneously to spread, thus increasing the speed at which they find victims.


Other versions

Aliases

Net-Worm.Win32.Padobot.m (Kaspersky Lab) is also known as:

  • Worm.Win32.Padobot.m (Kaspersky Lab)
  • Worm.Padobot.M (ClamAV)
  • W32/Sality.aa (Panda)
  • W32/Korgo.V (FPROT)
  • Worm:Win32/Korgo.V (MS(OneCare))
  • Win32.Lsabot (DrWeb)
  • Worm.Padobot.BV.Dam (BitDef7)
  • processing error (VirusBuster)
  • Win32:Padobot-Y [Wrm] (AVAST)
  • Net-Worm.Win32.Padobot (Ikarus)
  • W32.Sality.AE (NAV)
  • Korgo.V (Norman)
  • [Suspicious] (Rising)
  • Win32.Sality.BL (VirusBusterBeta)