
SonicWALL UTM Research team received reports of a new variant of Yahos worm spreading in the wild. It propagates through Instant Messaging application such as Yahoo Messenger, AOL, Skype and MSN as well as in Social Networking site- Facebook. It also includes IRC-based backdoor capability to receive instructions from remote server.
Installation:
Drops a copy of itself:
Drops the following files:
Downloads related Malware:
Creates Mutex to ensure that only one instance of the application runs in the system:
(Note: %Windows% is the Windows folder, which is usually C:Windows or C:WINNT. %User Profile% is the User folder, which is usually C:Documents and Settings{Current User})
Registry Changes:
It adds the following registry entries to ensure that the dropped copy of the malware starts on every system reboot:
Adds following registry entry to bypass firewall restrictions:
Command & Control (C&C) Server connection:
This worm will also join the following IRC Channel to receive instruction:
The screenshot below shows the IRC communication:
Backdoor Functionality:
Network Activity:
This worm may download files and updates from the following addresses:
Propagation:
This worm propagates via the following platforms:
Social Networking site:
Other System Modification:
Terminates the following services:
SonicWALL Gateway AntiVirus provides protection against this worm via the following signatures:

Share This Article

An Article By
An Article By
Security News
Security News