Eng
  1. Skip to navigation
  2. Skip to content
  3. Skip to sidebar


Korgo.A


Aliases:


Korgo.A
Worm.Win32.Padobot.b, Padobot

Malware

W32

Summary

Korgo (aka Padobot) is a network worm written by the Russian Hangup Team virus group. It spreads throughout the Internet using a vulnerability in Microsoft Windows LSASS. A description of the vulnerability can be found in Microsoft Security Bulletin MS04-011: http://www.microsoft.com/technet/security/bulletin/MS04-011.mspx



Disinfection & Removal

Automatic Disinfection

Allow F-Secure Anti-Virus to disinfect the relevant files.

For more general information on disinfection, please see Removal Instructions.



Technical Details

The worm is written in C++ and is approximately 10KB in size, packed using UPX.

When launching, the worm copies itself to the Windows system directory under a random name, and registers this file in the system registry auto-run key:

  • [HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Run] WinUpdate = %system%\name of file

It also creates a registry key

  • HKLM\SOFTWARE\Microsoft\Wireless Server = 1

It creates the mutexes "10", "u2" and "uterm5" to flag its presence in the system. The worm chooses the IP-addresses of random machines to infect and attack, similar to other worms which exploit the same LSASS vulnerability.

Once infected, a victim machine will display an error message that the LSASS service has failed. After this error message has been displayed, the computer may reboot.

The worm open TCP ports 113, 3067 and 2041 to receive commands.

It attempts to connect to several IRC servers to receive commands and transmit data.

  • moscow-advokat.ru
  • graz.at.eu.undernet.org
  • flanders.be.eu.undernet.org
  • caen.fr.eu.undernet.org
  • brussels.be.eu.undernet.org
  • los-angeles.ca.us.undernet.org
  • washington.dc.us.undernet.org
  • london.uk.eu.undernet.org
  • lia.zanet.net
  • gaspode.zanet.org.za
  • irc.kar.net






Submit a sample




Wondering if a file or URL is malicious? Submit a sample to our Lab for analysis via the Sample Analysis System (SAS)

Give And Get Advice




Give advice. Get advice. Share the knowledge on our free discussion forum.