F-Secure Virus Descriptions : Leave
| NAME: | Leave |
| ALIAS: | IWorm_Leave, I-Worm.Leave, Worm.Leaveme |
Leave is an Internet worm spreading through vulnerable machines.
The worm works under Win32 systems only. The worm functionality
is based on a special script language that allows remote host to
manage infected computers. The worm also is able (due to these
special script programs) to download and activate more components
(plugins). As a result the worm is able to "upgrade" itself from
Internet Web sites.
When a main worm component is run it copies itself to Windows
directory with REGSV.EXE name and registers that file in auto-run
registry keys. These keys depend on Windows version (Win9x or
WinNT) and look as follows:
HKLM\Software\Microsoft\Windows\CurrentVersion\Run
HKLM\Software\Microsoft\Windows\CurrentVersion\RunServices
regsv = %windir%\regsv.exe
HKCU\Software\Mirabilis\ICQ\Agent\Apps
icqrun = %windir%\regsv.exe
The worm then stays as a hidden (service) process in Windows
memory and is active untill next Windows shutdown.
The main worm components contains a text string that is SubSeven
backdoor master password. So the worm may attack remote systems
already infected by SubSeven backdoor, and install itself there.
To get addresses of victim's machines the worm uses sniffing
(scanning) routine that follows scripts (see below) and scan
Internet for IP addresses of remote computers.
The worm's script language is quite powerful. It allows the worm
to do the following:
- download from Web sites and run EXE files (worm plugins)
- scan IP addresses by requested mask
- connect to IRC servers and execute IRC commands
- create, move, delete, execute files on affected computer
- e.t.c.
The scripts are downloaded by worm from different Web sites, for
example:
http://leavemealoneeeeeeeee.50megs.com
http://k000001.50megs.com
http://slinky.50megs.com
http://h0h0h0.home.dk3.com
http://h0h0h0.spites.com
http://love50gb.50megs.com
http://tonyjameshanks-sux.50megs.com
http://bababuhtml.50megs.com
http://zxcvbnm.com
and from several others.
The script commands in there are encrypted with 64 bits block
cipher. When the worm gets a script from there it first decrypts
it and then follows script instructions.
The worm also contains in its code a default script (that is also
encrypted). That script is dropped to Windows directory with
ACI3.DLL name.
When scripts are accepted, the worm also stores them in encrypted
form in Registry keys:
HKLM\SOFTWARE\Classes\Scandisk\i386\i\
HKLM\SOFTWARE\Classes\Scandisk\i386\s\
The worm performs DoS attack (Denial of Service) to following
sites:
www.hotmail.com
www.internet.com
www.netscape.com
www.lycos.com
www.aol.com
www.msn.com
www.goto.com
www.excite.com
www.yahoo.com
www.altavista.com
In the beginning of July 2001 someone sent out a fake Microsoft
Security Bulletin. That bulletin had a Microsoft-like download
URL inside:
www.microsoft.com@%32%30%37%2E%38%39%2E%31...
The URL pointed to a fake patch program named: cvr58-ms.exe which
was a variant of Leave worm.
F-Secure Anti-Virus with the latest updates detects all known
variants of Leave worm.
[Analysis: Eugene Kaspersky; KL, July 2001]
|