|
Details:
Installation and Autostart Technique
Upon execution, this worm drops a copy of itself in the Windows system folder as the file PILIF.EXE.
It creates the following registry entry to enable its automatic execution at every system startup:
HKEY_LOCAL_MACHINE\Software\Microsoft\
Windows\CurrentVersion\Run
Pilif = "%System%\PILIF.EXE"
(Note: %System% is the Windows system folder, which is usually
C:\Windows\System on Windows 95, 98 and ME, C:\WINNT\System32 on
Windows NT and 2000, and C:\Windows\System32 on Windows XP.)
Peer-to-Peer Propagation
This worm drops copies of itself in the following folders found
in the Program Files directory, which are default-shared folders of
popular peer-to-peer (P2P) applications:
- \BearShare\Shared
- \BearShare\Shared\
- \Edonkey2000\Incoming
- \Edonkey2000\Incoming\
- \Grokster\My Grokster
- \Grokster\My Grokster\
- \icq\shared files\
- \Kazaa\My Shared Folder
- \Kazaa\My Shared Folder\
- \KMD\Shared Folder
- \limewire\Shared
- \limewire\Shared\
- \Morpheus\My Shared Folder
- \Morpheus\My Shared Folder\
- \Shareaza\downloads
- \WinMX\my shared folder\
- Shareaza\downloads
It uses the any of the following file names for its dropped copy, followed by an .EXE, .SCR, .PIF, .BAT, or .CMD extension:
- Anti-hacker Utility
- Cracks mega warez collection
- Dark Coderz Alliance
- Easy credit card validation
- Free porn sites accounts
- Kasperky AV Universal Key
- Norton 2004 crack
- Sex - totally free porn
- Webmail official hacker
- Yahoo hacker
Email Propagation
This worm searches for email addresses in .HTM and .HTML files
found on the affected system. It then sends email messages to these
addresses using MAPI.
The email it sends out has the following details:
Message body: (any of the following)
Important legal notice!
Do not delete this message. Analyse attachement and reply
as soon as possible with manifesto details.
Thank you!
-------------------
Please help us to save the right of freedom of expression!
All details will be displayed in small attached file. Good luck and thank you.
-------------------
You personal manifesto details are attached. Take good care of them!
-------------------
Help us gather online votes for our anti-censore manifesto
We need you help now! Attachement will automatically send a vote to our
online database once you run it and will be redirected to our webpage!
Thank you!
-------------------
Its curious, its scandalous... dont be so furious!
Life is bitch so dont take it serious.
-------------------
Please help us be free! We need the basic right of expression.
Enable an online vote for our manifesto with the help of the attachement.
Many thanks!
-------------------
Music is beeing censored, journalists are afraid, law has not been
respected for long time. Why? Because of corruption and lack of right of
expression. Help us! Enable the attachement and our voting system will
track and record you help. Many thanks!
-------------------
Parazitii need your help for the anti-censore campaign! See all details
in the attachement. Thank you!
-------------------
Its just hip-hop. Nothing else. Enjoy!
Oh yeah! one more thing: its a censore-related manifesto :)
-------------------
This is my manifesto. You can stop this individual,
but you can't stop us all...after all,we're all alike.
-------------------
Attachment: (any one of the following, followed by an .EXE, .SCR, .PIF, .BAT, or .CMD extension)
ˇ attachement
ˇ details
ˇ freedom
ˇ Freedom of expression
ˇ Goverment issue
ˇ JOS CeNzurA
ˇ manifesto
ˇ Manifesto anti pilif
ˇ Manifesto details
ˇ Parazitii
ˇ pilif
ˇ Simple solution
ˇ stolen rights
ˇ sustain cause
Propagation via Internet Relay Chat (IRC)
This worm drops a modified SCRIPT.INI file in the following folders, if it exists on the infected system:
- C:\mirc\
- C:\mirc32\
- C:\mirc\32
- %Program Files%\mirc\
- %Program Files%\mirc32\
(Note: %Program Files% is the Program Files folder, usually C:\Program Files.)
This modified IRC script sends a worm copy to a user that enters
the same chatroom as that of the infected user. It displays the
following message upon file transfer:
DCA are fighting for free speech. Get their manifesto now!
It then sends out the following file:
Manifesto Anti Censore Pilif.txt.exe
Other Details
This worm disables the Windows Task Manager to prevent an infected user from terminating its process.
It also displays the Shutdown Windows menu, or the window that
pops out when CTRL+ALT+DEL keys are pressed, every few seconds to annoy
the user.
Analysis by: Daniel Biado
| Description created: Oct. 11, 2004 |
|