Submission Summary:

What's been foundSeverity Level
A network-aware worm that uses known exploit(s) in order to replicate across vulnerable networks.
Bugtraq ID 9213: DameWare Mini Remote Control Server Pre-Authentication Buffer Overflow Vulnerability.
MS03-026: DCOM RPC Interface Buffer Overrun Vulnerability - replication across TCP 135/139/445/593 (common for Spybot, Randex, other IRC Bots).
MS04-012: DCOM RPC Overflow exploit - replication across TCP 135/139/445/593 (common for Blaster, Welchia, Spybot, Randex, other IRC Bots).
MS03-007: Microsoft IIS WebDAV Remote Compromise Vulnerability - Unchecked Buffer In Windows Component Could Cause Server Compromise.
MS04-011: LSASS Overflow exploit - replication across TCP 445 (common for Sasser, Bobax, Kibuv, Korgo, Gaobot, Spybot, Randex, other IRC Bots).
Capability to perform DoS attacks against other computers.
Backdoor functionality: connected remote users are able to perform multiple actions on the compromised system.
Capability to join IRC channels and communicate with the remote computers (e.g. with the purpose of notification or remote administration).
Capability to terminate Antivirus, Firewall and other security related processes.
Replication across networks by exploiting weekly restricted shares (common for Randex family of worms).
Creates a startup registry entry.
Contains characteristics of a known security risk.

 

Technical Details:

 

Possible Security Risk

Security RiskDescription
Backdoor.Rbot.Gen Backdoor.Rbot.Gen is an IRC controlled backdoor (or "bot") that can be used to gain unauthorized access to a victim's machine. It can also exhibit worm-like functionality by exploiting weak passwords on network shares.

 

File System Modifications

#Filename(s)Filename SizeFilename MD5Alias
1 %Temp%\C27D8FEF-D7AE-42c0-82E6-F30598265639.exe 3,584 bytes 0x7152446FD31220DD1038B6F7D95AB8A3 Backdoor.Rbot.Gen [PCTools]
Trojan.Win32.KillFiles.im [Kaspersky Lab]
TROJ_KFILES.AK [Trend Micro]
2 %System%\rruxdkf.exe 180,224 bytes 0xE6C4776CB9AFFA027F20CAA9F68A5250 Backdoor.Win32.Rbot.adf [Kaspersky Lab]
W32.Spybot.Worm [Symantec]
BKDR_Generic [Trend Micro]

 

Memory Modifications

Process NameProcess FilenameMain Module Size
rruxdkf.exe%System%\rruxdkf.exe679,936 bytes
[filename of the sample #1][file and pathname of the sample #1]679,936 bytes
C27D8FEF-D7AE-42c0-82E6-F30598265639.exe%Temp%\C27D8FEF-D7AE-42c0-82E6-F30598265639.exe16,384 bytes

 

Registry Modifications

 

Other details

 

Heuristics Analysis

 

 

All content ("Information") contained in this report is the copyrighted work of Threat Expert Ltd and its associated companies ("Threat Expert") and may not be copied without the express permission of Threat Expert.

The Information is provided on an "as is" basis. Threat Expert disclaims all warranties, whether express or implied, to the maximum extent permitted by law, including the implied warranties that the Information is merchantable, of satisfactory quality, accurate, fit for a particular purpose or need, or non-infringing, unless such implied warranties are legally incapable of exclusion. Further, Threat Expert does not warrant or make any representations regarding the use or the results of the use of the Information in terms of their correctness, accuracy, reliability, or otherwise.

Copyright © 2007 Threat Expert. All rights reserved.