|
W32.Darker@mm, I.worm.Darker@mm
![]() |
Darker es un destructivo gusano reportado el
06
de Noviembre del 2003, de alta propagación masiva a través de mensajes de
Correo, Redes de archivos
compartidos Peer to
Peer y se conecta
a un canal IRC
(Internet Chat Relay)
desde el cual recibe comandos remotos del hacker poseedor del software
cliente.
Deshabilita antivirus, firewalls y aplicaciones de control del sistema. |
Es un PE (Portable Ejecutable) e infecta Windows 95/98/NT/Me/2000/XP, incluyendo los servidores NT/2000/Server 2003, está desarrollado en Borland Delphi, con una extensión de 36.5 KB y comprimido con el utilitario UPX (Ultimate Packer for eXecutables):
Haciendo uso de las funciones de las librerías MAPI (Messaging Application Programming Interface) se auto-envía a todos los buzones de correo de la Libreta Global de Windows WAB (Windows Address Book).
El formato de correo es el siguiente:

Al ejecutar el archivo el gusano se auto-copia al directorio %Windir%
con el nombre Svchost.exe y para ejecutarse
la próxima vez que se inicie el sistema modifica la siguiente llave de
registro:
[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Run]
"Service Process" = "%Windir%\Svchost.exe"
Una vez activado, el gusano
termina los procesos de los siguientes antivirus, firewalls o programas de
monitoreo que se encuentren instalados, dejando al sistema totalmente vulnerable
a los virus y ataques de intrusos:
Pa5ra propagarse a través de las redes P2P KaZaA, Morpheus y Grokster, el gusano se auto-copia a cada una de sus carpetas de descarga con los siguientes nombres:
C:\Program Files\Morpheus\My Shared Folder\Adobe_crack_.exe
C:\Program Files\Morpheus\My Shared Folder\live_fuck_tv(v2).exe
C:\Program Files\Morpheus\My Shared Folder\Teen sex Having her breasts fucked and blowjob.exe
C:\Program Files\Morpheus\My Shared Folder\XP crack setup.exe
C:\Program Files\Morpheus\My Shared Folder\Xmusic Ultimate porn , games , movies Search engine.exe
C:\Program Files\Morpheus\My Shared Folder\Porn_Search_engine.exe
C:\Program Files\Morpheus\My Shared Folder\crack_database(1000scracks).exe
C:\Program Files\Morpheus\My Shared Folder\Mp3_Mixer(v3).exe
C:\Program Files\Morpheus\My Shared Folder\Jay z - crazy in love.mov.exe
C:\Program Files\Morpheus\My Shared Folder\PasswordCracker.exe
C:\Program Files\Morpheus\My Shared Folder\SlimShady Game.exe
C:\Program Files\Morpheus\My Shared Folder\Dmx - Who the let the dogs out(funny).exe
C:\Program Files\Morpheus\My Shared Folder\HotMail_password_hack(NEW!!!).exe
C:\Program Files\Morpheus\My Shared Folder\PornWebsite_Pass_crack_v1.23beta.exe
C:\Program Files\Morpheus\My Shared Folder\Msn_instant_messager_pass_crack.exe
C:\Program Files\Morpheus\My Shared Folder\Password_cracker(doesnt_work_on_nt).exe
C:\Program Files\KaZaA\My Shared Folder\HotMail_password_hacker.exe
C:\Program Files\KaZaA\My Shared Folder\Crackdatabase(1000scracks).exe
C:\Program Files\KaZaA\My Shared Folder\Porn_Search_engine.exe
C:\Program Files\KaZaA\My Shared Folder\Adobe_crack_.exe
C:\Program Files\KaZaA\My Shared Folder\Tit_test(Porn_game).exe
C:\Program Files\KaZaA\My Shared Folder\Kill backstreet boys(Eminem game).exe
C:\Program Files\KaZaA\My Shared Folder\Jenna jameson Tit Fuck Sex Ultimate porn movie.mpeg.exe
C:\Program Files\KaZaA\My Shared Folder\Mp3_Mixer.exe
C:\Program Files\KaZaA\My Shared Folder\PassWordCracker.exe
C:\Program Files\KaZaA\My Shared Folder\Hotmail_Hacker.exe
C:\Program Files\KaZaA\My Shared Folder\DjSoftware.exe
C:\Program Files\KaZaA\My Shared Folder\Hot Pink Pussy Very tight chick fucking her boyfriend on the bed. Great sex clip.exe
C:\Program Files\KaZaA\My Shared Folder\Windows Xp Crack.exe
C:\Program Files\KaZaA\My Shared Folder\Teen fucking hard.avi.exe
C:\Program Files\KaZaA\My Shared Folder\Mp3Mixer(good).exe
C:\Program Files\KaZaA\My Shared Folder\PornWebsite_Pass_crack_v1.23beta.exe
C:\Program Files\KaZaA\My Shared Folder\Msn_instant_messager_pass_crack.exe
C:\Program Files\KaZaA\My Shared Folder\Password_cracker(doesnt_work_on_nt).exe
C:\Program Files\Grokster\My Grokster\HotMail_password_hacker(NEW!!!).exe
C:\Program Files\Grokster\My Grokster\Porn_search_engine(2003edition).exe
C:\Program Files\Grokster\My Grokster\Crack_hack_database(1000sCracksHacks).exe
C:\Program Files\Grokster\My Grokster\Adobe_crack_.exe
C:\Program Files\Grokster\My Grokster\Half_life_walk_through_walls_proxy.exe
C:\Program Files\Grokster\My Grokster\Mp3_Mixer_.exe
C:\Program Files\Grokster\My Grokster\HalfLife.exe
C:\Program Files\Grokster\My Grokster\Windows Xp crack.exe
C:\Program Files\Grokster\My Grokster\PornWebsite_Pass_crack_v1.23beta.exe
C:\Program Files\Grokster\My Grokster\Msn_instant_messager_pass_crack.exe
C:\Program Files\Grokster\My Grokster\Password_cracker(doesnt_work_on_nt).exe
C:\Program Files\KaZaA Lite\My Shared Folder\HotMail_password_hacker(NEW!!!).exe
C:\Program Files\KaZaA Lite\My Shared Folder\Crackdatabase(1000scracks).exe
C:\Program Files\KaZaA Lite\My Shared Folder\Porn_Search_engine.exe
C:\Program Files\KaZaA Lite\My Shared Folder\Adobe_crack_.exe
C:\Program Files\KaZaA Lite\My Shared Folder\Jenna jameson Tit Fuck Sex Ultimate porn movie.mpeg.exe
C:\Program Files\KaZaA Lite\My Shared Folder\Mp3_Mixer.exe
C:\Program Files\KaZaA Lite\My Shared Folder\dr dre & nwa - fuck the police.mp3.exe
C:\Program Files\KaZaA Lite\My Shared Folder\britney spears tit game (funny as hell).exe
C:\Program Files\KaZaA Lite\My Shared Folder\Windows Xp Crack.exe
C:\Program Files\KaZaA Lite\My Shared Folder\Asian-porn-finder.exe
C:\Program Files\KaZaA Lite\My Shared Folder\PassWordCracker.exe
C:\Program Files\KaZaA Lite\My Shared Folder\Hotmail_Hacker.exe
C:\Program Files\KaZaA Lite\My Shared Folder\Xscan setup(Windows Hacker).exe
C:\Program Files\KaZaA Lite\My Shared Folder\DjSoftware.exe
C:\Program Files\KaZaA Lite\My Shared Folder\HalfLife Counter strike Auto Aim-v4.3.exe
C:\Program Files\KaZaA Lite\My Shared Folder\Mp3Mixer(good).exe
C:\Program Files\KaZaA Lite\My Shared Folder\Great Sex Movie Viewier NO Credit Cards (LESBIAN , HARDCORE , TEENSEX , FUCK ,BLOWJOB).exe
C:\Program Files\KaZaA Lite\My Shared Folder\PornWebsite_Pass_crack_v1.23beta.exe
C:\Program Files\KaZaA Lite\My Shared Folder\Msn_instant_messager_pass_crack.exe
C:\Program Files\KaZaA Lite\My Shared Folder\Password_cracker(doesnt_work_on_nt).exe
También se conecta a un canal IRC
(Internet Chat Relay)
desde el cual recibe comandos del hacker
poseedor del software Cliente.
Los payloads de este gusano son:
PER ANTIVIRUS
® versión 8.3 con registro de virus al 06 de Noviembre del 2003, detecta y elimina eficientemente este gusano.