DARKER, gusano de Correo, redes P2P e IRC, simula contener actualización para MS Outlook Express.  

© Jorge Machado  Lima-Perú

W32.Darker@mm, I.worm.Darker@mm

Darker es un destructivo gusano reportado el 06 de Noviembre del 2003, de alta propagación masiva a través de mensajes de Correo, Redes de archivos compartidos Peer to Peer y se conecta a un canal IRC (Internet Chat Relay) desde el cual recibe comandos remotos del hacker poseedor del software cliente.

Deshabilita antivirus, firewalls y aplicaciones de control del sistema.

Es un PE (Portable Ejecutable) e infecta Windows 95/98/NT/Me/2000/XP, incluyendo los servidores NT/2000/Server 2003, está desarrollado en Borland Delphi, con una extensión de 36.5 KB y comprimido con el utilitario UPX (Ultimate Packer for eXecutables):

http://upx.sourceforge.net

Haciendo uso de las funciones de las librerías MAPI (Messaging Application Programming Interface) se auto-envía a todos los buzones de correo de la Libreta Global de Windows WAB (Windows Address Book). 

El formato de correo es el siguiente:

Al ejecutar el archivo el gusano se auto-copia al directorio %Windir% con el nombre Svchost.exe y para ejecutarse la próxima vez que se inicie el sistema modifica la siguiente llave de registro: 

[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Run]
"Service Process" = "%Windir%\Svchost.exe"

Una vez activado, el gusano termina los procesos de los siguientes antivirus, firewalls o programas de monitoreo que se encuentren instalados, dejando al sistema totalmente vulnerable a los virus y ataques de intrusos:

Pa5ra propagarse a través de las redes P2P KaZaA, Morpheus y Grokster, el gusano se auto-copia a cada una de sus carpetas de descarga con los siguientes nombres:

C:\Program Files\Morpheus\My Shared Folder\Adobe_crack_.exe 
C:\Program Files\Morpheus\My Shared Folder\live_fuck_tv(v2).exe 
C:\Program Files\Morpheus\My Shared Folder\Teen sex Having her breasts fucked and blowjob.exe 
C:\Program Files\Morpheus\My Shared Folder\XP crack setup.exe 
C:\Program Files\Morpheus\My Shared Folder\Xmusic Ultimate porn , games , movies Search engine.exe 
C:\Program Files\Morpheus\My Shared Folder\Porn_Search_engine.exe 
C:\Program Files\Morpheus\My Shared Folder\crack_database(1000scracks).exe 
C:\Program Files\Morpheus\My Shared Folder\Mp3_Mixer(v3).exe 
C:\Program Files\Morpheus\My Shared Folder\Jay z - crazy in love.mov.exe 
C:\Program Files\Morpheus\My Shared Folder\PasswordCracker.exe 
C:\Program Files\Morpheus\My Shared Folder\SlimShady Game.exe 
C:\Program Files\Morpheus\My Shared Folder\Dmx - Who the let the dogs out(funny).exe 
C:\Program Files\Morpheus\My Shared Folder\HotMail_password_hack(NEW!!!).exe 
C:\Program Files\Morpheus\My Shared Folder\PornWebsite_Pass_crack_v1.23beta.exe 
C:\Program Files\Morpheus\My Shared Folder\Msn_instant_messager_pass_crack.exe 
C:\Program Files\Morpheus\My Shared Folder\Password_cracker(doesnt_work_on_nt).exe 
C:\Program Files\KaZaA\My Shared Folder\HotMail_password_hacker.exe 
C:\Program Files\KaZaA\My Shared Folder\Crackdatabase(1000scracks).exe 
C:\Program Files\KaZaA\My Shared Folder\Porn_Search_engine.exe 
C:\Program Files\KaZaA\My Shared Folder\Adobe_crack_.exe 
C:\Program Files\KaZaA\My Shared Folder\Tit_test(Porn_game).exe 
C:\Program Files\KaZaA\My Shared Folder\Kill backstreet boys(Eminem game).exe 
C:\Program Files\KaZaA\My Shared Folder\Jenna jameson Tit Fuck Sex Ultimate porn movie.mpeg.exe 
C:\Program Files\KaZaA\My Shared Folder\Mp3_Mixer.exe 
C:\Program Files\KaZaA\My Shared Folder\PassWordCracker.exe 
C:\Program Files\KaZaA\My Shared Folder\Hotmail_Hacker.exe 
C:\Program Files\KaZaA\My Shared Folder\DjSoftware.exe 
C:\Program Files\KaZaA\My Shared Folder\Hot Pink Pussy Very tight chick fucking her boyfriend on the bed. Great sex clip.exe 
C:\Program Files\KaZaA\My Shared Folder\Windows Xp Crack.exe 
C:\Program Files\KaZaA\My Shared Folder\Teen fucking hard.avi.exe 
C:\Program Files\KaZaA\My Shared Folder\Mp3Mixer(good).exe 
C:\Program Files\KaZaA\My Shared Folder\PornWebsite_Pass_crack_v1.23beta.exe 
C:\Program Files\KaZaA\My Shared Folder\Msn_instant_messager_pass_crack.exe 
C:\Program Files\KaZaA\My Shared Folder\Password_cracker(doesnt_work_on_nt).exe 
C:\Program Files\Grokster\My Grokster\HotMail_password_hacker(NEW!!!).exe 
C:\Program Files\Grokster\My Grokster\Porn_search_engine(2003edition).exe 
C:\Program Files\Grokster\My Grokster\Crack_hack_database(1000sCracksHacks).exe 
C:\Program Files\Grokster\My Grokster\Adobe_crack_.exe 
C:\Program Files\Grokster\My Grokster\Half_life_walk_through_walls_proxy.exe 
C:\Program Files\Grokster\My Grokster\Mp3_Mixer_.exe 
C:\Program Files\Grokster\My Grokster\HalfLife.exe 
C:\Program Files\Grokster\My Grokster\Windows Xp crack.exe 
C:\Program Files\Grokster\My Grokster\PornWebsite_Pass_crack_v1.23beta.exe 
C:\Program Files\Grokster\My Grokster\Msn_instant_messager_pass_crack.exe 
C:\Program Files\Grokster\My Grokster\Password_cracker(doesnt_work_on_nt).exe 
C:\Program Files\KaZaA Lite\My Shared Folder\HotMail_password_hacker(NEW!!!).exe 
C:\Program Files\KaZaA Lite\My Shared Folder\Crackdatabase(1000scracks).exe 
C:\Program Files\KaZaA Lite\My Shared Folder\Porn_Search_engine.exe 
C:\Program Files\KaZaA Lite\My Shared Folder\Adobe_crack_.exe 
C:\Program Files\KaZaA Lite\My Shared Folder\Jenna jameson Tit Fuck Sex Ultimate porn movie.mpeg.exe 
C:\Program Files\KaZaA Lite\My Shared Folder\Mp3_Mixer.exe 
C:\Program Files\KaZaA Lite\My Shared Folder\dr dre & nwa - fuck the police.mp3.exe 
C:\Program Files\KaZaA Lite\My Shared Folder\britney spears tit game (funny as hell).exe 
C:\Program Files\KaZaA Lite\My Shared Folder\Windows Xp Crack.exe 
C:\Program Files\KaZaA Lite\My Shared Folder\Asian-porn-finder.exe 
C:\Program Files\KaZaA Lite\My Shared Folder\PassWordCracker.exe 
C:\Program Files\KaZaA Lite\My Shared Folder\Hotmail_Hacker.exe 
C:\Program Files\KaZaA Lite\My Shared Folder\Xscan setup(Windows Hacker).exe 
C:\Program Files\KaZaA Lite\My Shared Folder\DjSoftware.exe 
C:\Program Files\KaZaA Lite\My Shared Folder\HalfLife Counter strike Auto Aim-v4.3.exe 
C:\Program Files\KaZaA Lite\My Shared Folder\Mp3Mixer(good).exe 
C:\Program Files\KaZaA Lite\My Shared Folder\Great Sex Movie Viewier NO Credit Cards (LESBIAN , HARDCORE , TEENSEX , FUCK ,BLOWJOB).exe 
C:\Program Files\KaZaA Lite\My Shared Folder\PornWebsite_Pass_crack_v1.23beta.exe 
C:\Program Files\KaZaA Lite\My Shared Folder\Msn_instant_messager_pass_crack.exe 
C:\Program Files\KaZaA Lite\My Shared Folder\Password_cracker(doesnt_work_on_nt).exe 

También se conecta a un canal IRC (Internet Chat Relay) desde el cual recibe comandos del hacker poseedor del software Cliente.

Los payloads de este gusano son:

PER ANTIVIRUS® versión 8.3 con registro de virus al 06 de Noviembre del 2003, detecta y elimina eficientemente este gusano.


Ir al menú anterior

Regresar al Portal de PER SYSTEMS