TrendLabs Malware Blog
Glossary
TrendWatch
TrendLabs Twitter
WORM_RINBOT.E
Overview

Malware type: Worm

Aliases: Backdoor.Win32.VanBot.bh (Kaspersky), W32/Sdbot.worm.gen.ai (McAfee), W32.Rinbot.A (Symantec), BDS/VanBot.AY.11 (Avira), W32/Sdbot-DBA (Sophos), Trojan:Win32/Ircbrute (Microsoft)

In the wild: Yes

Destructive: No

Language: English

Platform: Windows 98, ME, NT, 2000, XP, Server 2003

Encrypted: No

Overall risk rating:


Reported infections:

Damage potential:

High

Distribution potential:

High

Infection Channel 1 : Propagates via network shares


Infection Channel 2 : Propagates via software vulnerabilities


Description: 

This worm propagates via network shares. It does the said routine by dropping a copy of itself in the IPC$ folder, which is a default share. If the share is password-protected, it uses a list of user names and passwords to gain access.

It also takes advantage of the SQL Server 7.0 Service Pack Password vulnerability to propagate across networks. For more information regarding the said vulnerability, refer to the following Microsoft Web page:

Moreover, this worm usually arrives on a system as a file downloaded from the Internet by unsuspecting users when visiting malicious Web sites, or as a file dropped by other malware.

Upon execution, it drops a copy of itself as SYMMEC.EXE in the Windows system folder. It also drops a file named JPB.EXE, which is detected by Trend Micro as BKDR_IRCBOT.TY, in the root folder (usually C:\). It then creates a particular registry entry so that it automatically executes whenever Windows restarts.

It also has backdoor capabilities. It opens random TCP ports and waits for several commands from a remote malicious user. Once a connection is established, it executes the said commands locally, such as termination of processes and logging of keystrokes, effectively compromising the affected system.

For additional information about this threat, see:
Solution
Technical Details

Description created: Mar. 1, 2007 2:48:20 PM GMT -0800

Search a new malware

Tell us how we did. Take our quick survey.