
SonicWALL UTM Research team received reports of a new variant of an IM worm spreading in the wild. It propagates through Instant Messaging application such as Yahoo Messenger, AIM, MSN as well as in Social Networking site- Facebook. There were reportedly multiple rogue Facebook applications that were leading to this worm which are now taken down.
Process of Infection:
An unsuspecting user will receive a message to view a picture purportedly hosted in facebook.com through instant messaging application from an infected machine. A sample of the suspicious message sent via MSN looks like below:
Once the user clicks on the link, it will redirect the user to this facebook.com page:
This is a legitimate facebook.com page and typical when one clicks on a third-party link from within facebook. However, when the user clicks the continue button, the user will be directed to the malicious website.
A screenshot of the malicious website is shown below:
The site is designed to appear that the user is still browsing from within facebook, although the URL shows otherwise. It was also made to appear that the picture the user wants to see was moved and needed to click the "View Photo" button to see it. Clicking the button will download the malicious IM worm.
Installation:
Drops a copy of itself:
Downloads malware component:
Creates Mutex to ensure that only one instance of the application runs in the system:
(Note: %Windows% is the Windows folder, which is usually C:Windows or C:WINNT.)
Registry Changes:
It adds the following registry entries to ensure that the dropped copy of the malware starts on every system reboot:
Adds following registry entry to bypass firewall restrictions:
Command & Control (C&C) Server connection:
This worm will also join the following IRC Channel to receive instruction:
The screenshot below shows the IRC communication:
Backdoor Functionality:
Network Activity:
DNS Request
FTP Server:
Propagation:
This worm propagates via following platforms:
Social Networking site:
Other System Modification:
Terminates the following services:
SonicWALL Gateway AntiVirus provides protection against this worm via the following signatures:
GAV: Yimfoca.AA_3 (Worm)
Share This Article

An Article By
An Article By
Security News
Security News