Trend Micro
Submit

JapanTaiwanChinaKorea

HomeProductsPurchaseSupportSecurity InfoPartnersAbout Us
Security Advisories
Weekly Virus Report
Virus Map
Virus Encyclopedia
>Hoaxes
Test Files
General Virus Information
White Papers
Subscriptions
Webmaster Tools
TrendLabs - R&D

 
WORM_FILI.A
Technical Details
In the wild: Yes
Language: English
Platform: Windows 95, 98, ME, NT, 2000, XP
Encrypted: No
Size of virus: 20,480 Bytes
Pattern file needed: 2.193.14
Scan engine needed: 6.810
DiscoveredOct. 10, 2004
Detection availableOct. 10, 2004

Details:

Installation and Autostart Technique

Upon execution, this worm drops a copy of itself in the Windows system folder as the file PILIF.EXE.

It creates the following registry entry to enable its automatic execution at every system startup:

HKEY_LOCAL_MACHINE\Software\Microsoft\
Windows\CurrentVersion\Run
Pilif = "%System%\PILIF.EXE"

(Note: %System% is the Windows system folder, which is usually C:\Windows\System on Windows 95, 98 and ME, C:\WINNT\System32 on Windows NT and 2000, and C:\Windows\System32 on Windows XP.)

Peer-to-Peer Propagation

This worm drops copies of itself in the following folders found in the Program Files directory, which are default-shared folders of popular peer-to-peer (P2P) applications:

  • \BearShare\Shared
  • \BearShare\Shared\
  • \Edonkey2000\Incoming
  • \Edonkey2000\Incoming\
  • \Grokster\My Grokster
  • \Grokster\My Grokster\
  • \icq\shared files\
  • \Kazaa\My Shared Folder
  • \Kazaa\My Shared Folder\
  • \KMD\Shared Folder
  • \limewire\Shared
  • \limewire\Shared\
  • \Morpheus\My Shared Folder
  • \Morpheus\My Shared Folder\
  • \Shareaza\downloads
  • \WinMX\my shared folder\
  • Shareaza\downloads

It uses the any of the following file names for its dropped copy, followed by an .EXE, .SCR, .PIF, .BAT, or .CMD extension:

  • Anti-hacker Utility
  • Cracks mega warez collection
  • Dark Coderz Alliance
  • Easy credit card validation
  • Free porn sites accounts
  • Kasperky AV Universal Key
  • Norton 2004 crack
  • Sex - totally free porn
  • Webmail official hacker
  • Yahoo hacker

Email Propagation

This worm searches for email addresses in .HTM and .HTML files found on the affected system. It then sends email messages to these addresses using MAPI.

The email it sends out has the following details:

Message body: (any of the following)

Important legal notice!
Do not delete this message. Analyse attachement and reply
as soon as possible with manifesto details.
Thank you!
-------------------

Please help us to save the right of freedom of expression!
All details will be displayed in small attached file. Good luck and thank you.
-------------------

You personal manifesto details are attached. Take good care of them!
-------------------

Help us gather online votes for our anti-censore manifesto
We need you help now! Attachement will automatically send a vote to our
online database once you run it and will be redirected to our webpage!
Thank you!
-------------------

Its curious, its scandalous... dont be so furious!
Life is bitch so dont take it serious.
-------------------

Please help us be free! We need the basic right of expression.
Enable an online vote for our manifesto with the help of the attachement.
Many thanks!
-------------------

Music is beeing censored, journalists are afraid, law has not been
respected for long time. Why? Because of corruption and lack of right of
expression. Help us! Enable the attachement and our voting system will
track and record you help. Many thanks!
-------------------

Parazitii need your help for the anti-censore campaign! See all details
in the attachement. Thank you!
-------------------

Its just hip-hop. Nothing else. Enjoy!
Oh yeah! one more thing: its a censore-related manifesto :)
-------------------

This is my manifesto. You can stop this individual,
but you can't stop us all...after all,we're all alike.
-------------------

Attachment: (any one of the following, followed by an .EXE, .SCR, .PIF, .BAT, or .CMD extension)

ˇ attachement
ˇ details
ˇ freedom
ˇ Freedom of expression
ˇ Goverment issue
ˇ JOS CeNzurA
ˇ manifesto
ˇ Manifesto anti pilif
ˇ Manifesto details
ˇ Parazitii
ˇ pilif
ˇ Simple solution
ˇ stolen rights
ˇ sustain cause

Propagation via Internet Relay Chat (IRC)

This worm drops a modified SCRIPT.INI file in the following folders, if it exists on the infected system:

  • C:\mirc\
  • C:\mirc32\
  • C:\mirc\32
  • %Program Files%\mirc\
  • %Program Files%\mirc32\

(Note: %Program Files% is the Program Files folder, usually C:\Program Files.)

This modified IRC script sends a worm copy to a user that enters the same chatroom as that of the infected user. It displays the following message upon file transfer:

DCA are fighting for free speech. Get their manifesto now!

It then sends out the following file:

    Manifesto Anti Censore Pilif.txt.exe

Other Details

This worm disables the Windows Task Manager to prevent an infected user from terminating its process.

It also displays the Shutdown Windows menu, or the window that pops out when CTRL+ALT+DEL keys are pressed, every few seconds to annoy the user.

                                        
                                             
                                             

Analysis by: Daniel Biado



Description created: Oct. 11, 2004
 
Copyright 1989-2004 Trend Micro, Inc. All rights reserved. Legal Notice | Privacy Policy | Contact Us