TrendLabs Malware Blog
Glossary
TrendWatch
TrendLabs Twitter
WORM_NUWAR.AOK
Overview

Malware type: Worm

Aliases: Email-Worm.Win32.Zhelatin.cq (Kaspersky), Trojan.Packed.13 (Symantec), TR/Small.DBY.BS (Avira), Mal/EncPk-E (Sophos),

In the wild: Yes

Destructive: No

Language: English

Platform: Windows 98, ME, NT, 2000, XP, Server 2003

Encrypted: No

Overall risk rating:


Reported infections:

Damage potential:

High

Distribution potential:

High

Infection Channel 1 : Propagates via email


Description: 

Barely three weeks into the new year, as the storm "Kyrill" ravaged Central Europe, another "storm" brewed. The new storm was a deluge of spammed email messages that promised to bring information about Europe's most severe winter storm since 1999, with subject lines such as "230 dead as storm batters Europe", among others.

That is how this Trojan, arriving as attachment to the said email messages, came to be dubbed the "Storm" malware. But this Trojan is more than just a malware with a clever social engineering technique. Tagging WORM_NUWAR.CQ along, it created a partnership that staged a complex attack.

To read a comprehensive article about the routines and ultimate goals of the TROJ_SMALL.EDW-WORM_NUWAR.CQ tandem, click here: TROJ_SMALL.EDW Storms into Inboxes, Teams Up with NUWAR to Create Unique Network.

To get a one-glance comprehensive view of the behavior of this malware, refer to the Behavior Diagram shown below.

WORM_NUWAR.AOK Behavior Diagram

Malware Overview

This worm spreads by attaching a copy of itself to an email message, which it sends using its own Simple Mail Transfer Protocol (SMTP) engine. Having its own SMTP engine allows it to send messages without using any mailing application, such as MS Outlook.

The email message it sends out has the following details:

Subject: (any of the following)
• Iran Just Have Started World War III
• Israel Just Have Started World War III
• Missle Strike: The USA kills more then 1000 Iranian citizens
• Missle Strike: The USA kills more then 10000 Iranian citizens
• Missle Strike: The USA kills more then 20000 Iranian citizens
• USA Declares War on Iran
• USA Just Have Started World War III
• USA Missle Strike: Iran War just have started

Message body: {blank}

Attachment: (any of the following)
• Click Here.exe
• Click Me.exe
• More.exe
• Movie.exe
• News.exe
• Read Me.exe
• Read More.exe
• Video.exe

It spoofs the From field of an email message by using a list of common names followed by a spoofed domain name. Users may be tricked into thinking that the email message is from a trusted source.

When executed, it drops a randomly-named file in the folder where it first executes. It also drops the file WINCOM32.SYS in the Windows system folder. Both files are detected by Trend Micro as TROJ_SMALL.EDW. As a result, malicious routines of the dropped Trojan are exhibited on the affected system.

It terminates processes, most of which are related to antivirus and security applications. The said routine allows this worm to avoid easy detection and consequent removal.

In addition, it disables Internet Connection Sharing (ICS) and Windows Firewall by modifying a related registry entry. Disabling ICS prevents users within the affected network to share a single Internet connection. Disabling Windows Firewall makes the system vulnerable to further attacks.

For additional information about this threat, see:
Solution
Technical Details

Description created: Apr. 8, 2007 2:59:17 PM GMT -0800

Search a new malware

Tell us how we did. Take our quick survey.