Skip to main content

Feebs

Classification

Category:

Malware

Type:

Trojan

Aliases:

  • Feebs
  • W32/Kmax
  • W32.Feebs
  • Worm.Win32.Feebs.gen

Summary

Feebs is a family of worms that spread using email or P2P networks. Feebs usually comes as HTML application file (HTA) that installs the worm on infected system. Feebs hides itself using rootkit techniques.

Removal

Technical Details

System installation

When the HTML application file (HTA) is opened, it drops the worm main executable file in 'C:\Command.exe' and executes it. The EXE file drops a file with single letter 'a'-'z' on C-drive and activates it. That file is the worm main DLL component. When active, it creates the following files:

  • %System%\ms[random]32.dll %System%\ms[random]32.exe

The main DLL component also creates the following registry values for making sure the worm is activated on system startup:

  • [HKLM\Software\Microsoft\Windows\CurrentVersion\ShellServiceObjectDelayLoad] "%System%\ms[random]32.dll" = "{[random CLSID]}"
  • [HKML\CLSID\{[random CLSID]}\InprocServer32] "(default)" = "%System%\ms[random]32.dll"

Spreading

Feebs can spread sending email attachments containing the HTA dropper. The highly polymorphic HTA file is generated each time when the worm sends it. Feebs can also copy itself on shared folders used by some P2P applications.

Payload

Feebs starts HTTP server listening on port 80 for serving infected HTA files. The worm also starts server on random port which allows the attacker to control infected system. The random port is reported back to attacker using ICQ and HTTP. Feebs also tries to disable several security-related applications.

Rootkit functionality

Feebs can hide its files, registry keys and network connections by utilizing rootkit techniques. The worm main DLL component is injected to all running processes and used for hooking the system library functions.

Protect your devices from malware with F‑Secure Total

Protecting your devices from malicious software is essential for maintaining online security. F‑Secure Total makes this easy, helping you to secure your devices in a brilliantly simple way.

  • Award‑winning antivirus and malware protection

  • Online browsing, banking, and shopping protection

  • 24/7 online identity and data breach monitoring

  • Unlimited VPN service to safe­guard your privacy

  • Password manager with private data protection

Choose how many devices you want to protect to get started.

  • Free customer support

  • Cancel anytime

  • The trial does not obligate you to buy the product

After 30 days your subscription will renew automatically for one year at €69.99.

More Support

Community

Ask questions in our Community.

User guides

Check the user guide for instructions.

Contact Support

Chat with with or call an agent.

Submit a Sample

Submit a file or URL for analysis.