Home / malwarePDF  

Worm:Win32/Gegitoub.B


First posted on 23 August 2010.
Source: SecurityHome

Aliases :

Worm:Win32/Gegitoub.B is also known as IM-Worm.Win32.QiMiral.ax (Kaspersky), Worm.QiMiral.AF (VirusBuster), Win32.HLLW.Natchs (Dr.Web), Win32/QiMiral.AC (ESET), Trj/Spybot.AJX (Panda), TSPY_SNATCHER.A (Trend Micro).

Explanation :

Worm:Win32/Gegitoub.B is a worm that spreads via the instant messaging program ICQ. It can conduct a pseudo-conversation with a user's contacts by replying certain statements depending on keywords that the contact may write.
Top

Worm:Win32/Gegitoub.B is a worm that spreads via the instant messaging program ICQ. It can conduct a pseudo-conversation with a user's contacts by replying certain statements depending on keywords that the contact may write. Installation Worm:Win32/Gegitoub.B may arrive in the computer posing as a game with the file name "snatch.exe". On execution, it displays the following splash page and proceeds with its malicious routines: Spreads via... Instant messaging programs Worm:Win32/Gegitoub.B attempts to send a copy of itself as a message attachment sent out to all of a user's contact in the Internet Chat application ICQ. It connects to the ICQ server at the address 64.12.201.185. It checks for replies containing several strings or substrings in Cyrillic and can reply with a corresponding message supposedly from the infected ICQ user. For example, if the contact's reply contains any of these strings: Cyrillic Approximate English translation троян Trojan трой Troy вирь Vyr вирус virus Worm:Win32/Gegitoub.B replies with any of these statements: Cyrillic Approximate English translation нет, что Ñ‚Ñ‹? как можно?! ) No, what are you? How do I?! ) нет, глянь ))) No, is))) If the contact's reply contains any of these strings: Cyrillic Approximate English translation чито chito що Scho шо Sho че Che чё Human чо Cho что that Worm:Win32/Gegitoub.B replies with any of these statements: Cyrillic Approximate English translation ну мини игра типа ) Well mini game type ) глянь )) is )) If the contact's reply contains any of these strings: Cyrillic Approximate English translation не могу I can't ринимает ADOPTS Worm:Win32/Gegitoub.B replies with any of these statements: Cyrillic Approximate English translation включи в настройках передачу файлов ) turn it on in preferences file transfers ) If the contact's reply contains any of these strings: Cyrillic Approximate English translation ахуя ahuâ ачем Hy Worm:Win32/Gegitoub.B replies with any of these statements: Cyrillic Approximate English translation а зачем рыбе велосипед? ) and why fish wheel? ) If the contact's reply contains any of these strings: Cyrillic Approximate English translation Бот Boat бот boat Worm:Win32/Gegitoub.B replies with any of these statements: Cyrillic Approximate English translation эээ€¦ сам Ñ‚Ñ‹ бот =\ er... you boat =\ If the contact's reply contains any of these strings: Cyrillic Approximate English translation Сейчас Now сейчас now Теперь Now теперь now Пробуй Try Ану Anu ану anu Передай Pass передай pass Передавай Transfer передавай transfer Кидай Dodge кидай dodge Кинь Kinh кинь kinh Опять Again опять again Снова Once again снова once again Еще More еще more Worm:Win32/Gegitoub.B replies with this statement: file If the contact's reply contains any of these strings: Cyrillic Approximate English translation спам spam Worm:Win32/Gegitoub.B replies with any of these statements: Cyrillic Approximate English translation где это видано чтоб спаммеры файлы слали? это я шлю! Where have you seen so spammers were sending files? I send it! Payload Terminates processes Worm:Win32/Gegitoub.B searches for and terminates the following processes related to instant messenger applications, if found:

  • icq.exe
  • qip.exe
  • infium.exe


  • Analysis by Marianne Mallen

    Last update 23 August 2010

     

    TOP