Classification

Category :

Malware

Type :

-

Aliases :

Mabutu, I-Worm.Mabutu.a, W32.Mota.A@mm

Summary

Mabutu is a mass-mailing worm which spreads in short and simple emails with infected attachments.

Mabutu comes with an IRC-controlled backdoor component.

Removal

Based on the settings of your F-Secure security product, it will either move the file to the quarantine where it cannot spread or cause harm, or remove it.

A False Positive is when a file is incorrectly detected as harmful, usually because its code or behavior resembles known harmful programs. A False Positive will usually be fixed in a subsequent database update without any action needed on your part. If you wish, you may also:

  • Check for the latest database updates

    First check if your F-Secure security program is using the latest updates, then try scanning the file again.

  • Submit a sample

    After checking, if you still believe the file is incorrectly detected, you can submit a sample of it for re-analysis.

    Note: If the file was moved to quarantine, you need to collect the file from quarantine before you can submit it.

  • Exclude a file from further scanning

    If you are certain that the file is safe and want to continue using it, you can exclude it from further scanning by the F-Secure security product.

    Note: You need administrative rights to change the settings.

Technical Details

Mabutu arrives in a UPX-packed dropper with the main component as a DLL inside. The main DLL is 49152 bytes in size and is not packed.

System Infection

Upon execution Mabutu copies itself to the Windows Directory as [random character] TWAIN.EXE and drops a DLL, which is the body, as [random character] TWAIN.DLL. The DLL file is added to the registry as

[HKLM\Software\Microsoft\Windows\CurrentVersion\Run]
"winupdt" = "%WindowsDir%\RUNDLL32.EXE [random character] TWAIN.DLL,_mainRD"

%WindowsDir% represents the Windows folder name, for example C:\Windows on Windows XP systems.

Mabutu keeps its configuration data in an scrambled data file called cfg.dat in the Windows Directory.

Email Propagation

Mabutu collects email addresses from various places. It checks Windows Address Book, MSN Messenger Buddy list, Outlook Express mailboxes and files with the following extensions: .WAB, .HTM, .HTML, .TXT

Using its own SMTP engine Mabutu sends infected messages to the collected addresses.

Subject is one of:

Hi
Hello
Important
Hello
I'm in love
Sex
Wet girls
I'm nude
Fetishes
gutted
Ok cunt

Attachment names:

britney
jenifer
photo
creme_de_gruyere

with extensions .{JPG|TXT}[lots of spaces] .SCR or .ZIP.

The message body is either a file path, collected from Kazaa Shared Folder and My Document folders, or one of the following strings:

the_details
the_document
the_message

The mailing routine tests if there is connection to the Internet by connecting to www.google.com. If the user has a screen saver the worm waits until it starts then it activates its mass-mailing code.

Payload

The payload in Mabutu is an IRC-controlled backdoor. The backdoor connects to one of the many predefined IRC servers and after joining a channel it awaits for commands from its creator. Using these commands the attacker can get information from the worm (eg. number of sent infected emails, OS version, etc) and remotely start the mass-mailing routine.

Mabutu has the capability to update itself by downloading and activating a DLL from a predefined web location.