Koobface.ES replicates by sending messages to the friends listed in an infected user's account with a social networking website. The malicious message includes a link to a webpage/website where unsuspecting visitors can be infected in turn. Major social networking websites are targeted by this worm, including Facebook, MySpace, Friendster and Livejournal.
Based on the settings of your F-Secure security product, it will either move the file to the quarantine where it cannot spread or cause harm, or remove it.
On its first execution, the worm installs itself by copying itself to the Windows directory. During the execution, a message box is displayed, which appears as:
Next, the worm looks for and connects to a remote active domain server and starts looking for cookies related to major social networking websites (see the list below). If any relevant cookies are found, the worm will hijack the user's account on the social networking site, in order to go through the respective site and search for the user's friends/contacts.Once information related to the user's friends has been compiled, the worm sends this information to a server, where the data is used to create a message. The message is then sent to the user's friends.The generated message contains a link to a webpage where a copy of the worm can be downloaded. For example, the webpage may be a Fake YouTube page, which comes complete with fake comments. The user name and picture is pulled from the social networking site. Clicking anywhere on the page will download a copy of the worm. Most social networking websites will use Completely Automated Public Turing Test To Tell Computers and Humans Apart (CAPTCHA) to ensure that actual people, rather than computer programs, are creating user accounts. To circumvent the CAPTCHA security, the worm sends the CAPTCHA image back to its servers to be resolved. The answer is then sent back.
During installation, the worm creates a copy of itself in the Windows directory, using the file name freddy35.exe. It also drops a batch file, whose purpose is to delete the worm's own files after its first execution.The worm also makes a number of registry changes. One of the changes made displays MIME (type xhtml+xml without prompt).The worm needs to communicate with a server to function. A few possible server domains the worm can connect to are:
The server is where the following functions are carried out:
During its communication with the server, the worm searches for cookies of these sites:
The server can send the following commands:
Creates these files:
Creates these keys:
Date Created: -
Date Last Modified: -