TrendLabs Malware Blog
Glossary
TrendWatch
TrendLabs Twitter
WORM_KOOBFACE.DC
Overview

Malware type: Worm

Aliases: No Alias Found

In the wild: Yes

Destructive: No

Language: English

Platform: Windows 98, ME, NT, 2000, XP, Server 2003

Encrypted: No

Overall risk rating:


Reported infections:

Damage potential:

Low

Distribution potential:

Medium

Description: 

This worm may be downloaded unknowingly by a user when visiting malicious Web sites.

It drops copies of itself. It drops files/components. It terminates the initially executed copy and executes the dropped copy.

It creates a specific file in root folder and executes it to add registry entries as part of its installation routine.

It has the capability to fetch information from the affected system. It sends the gathered information via HTTP POST to the a URL.

It propagates via Twitter by posting a tiny URL in a tweet. The said URL then redirects the unsuspecting user to a site where they can download a copy of the worm.

It deletes itself after execution.

For additional information about this threat, see:
Solution
Technical Details

Description created: Jun. 27, 2009 11:59:33 PM GMT -0800

Search a new malware

Tell us how we did. Take our quick survey.