PDA

View Full Version : Another reason to stress. . . .


trees
02-01-2006, 09:41 PM
This has been found on a number of University machines. Well worth your time to make sure you're clean. Unless, of course, you want a nice clean, empty hard drive. . . .

Begin forwarded message:

From: Abraham Kuo - SIRT <akuo@ms.Telcom.Arizona.EDU>
Date: February 1, 2006 4:43:12 PM MST
To: NETDISCUSS@LISTSERV.ARIZONA.EDU
Subject: [NETDISCUSS] Blackworm (nyxem, kama sutra, etc)
Reply-To: UA Network Managers Discussion <NETDISCUSS@LISTSERV.ARIZONA.EDU>

Hi, all. As has been widely publicized, machines infected with Blackworm are due to have the payload activate on Friday (2/3). The payload, in short, overwrites a large number of user files, such as .doc, .xls, .pdf, etc. If you're not already familiar with what Blackworm does, there's a good summary here:

http://isc.sans.org/blackworm

If you haven't already done so, it would be a *very* good idea to update your antiviruses and do a full system scan today or tomorrow (before 2/3), and do an additional backup. This is even more critical if a machine has recently been blocked by SIRT, and was cleaned up but not backed up and reformatted (or not cleaned up and kept offline, since the payload that deletes files doesn't necessarily need network connectivity).

Keep in mind that another symptom of Blackworm (and many other worms) is that it interferes with AV operation, so if you're having difficulty updating your AV or doing the system scan, it would be worthwhile to investigate further, as always.

If you have any questions or concerns, please feel free to send us an email (sirt@arizona.edu), or give us a call (626 0100).

Abraham Kuo
CCIT Security Incident Response Team
(520) 626 0100 SIRT
(520) 626 9736 Desk

jharriso
02-02-2006, 01:51 AM
Whooooo, yeah, I've been hearing about this one for a while. Be interesting to see how many calls the Underground gets on friday reporting that "EVERYTHING IS GONE!!!!"

sfontes
02-02-2006, 08:19 AM
Just outta curiousity..I've read all the stuff and the like, just b/c I've got two windows machines at home that aren't mine so I don't monitor like a hawk..what would be the best way for an early detection? Or would Sophos pick it up since it remote updates itself?

moser
02-02-2006, 09:39 AM
Thanks Josh...now you've done it.:D Just ask the guys what happens whenever I mention that walkins seem to be going fairly slow on a Tuesday or Thursday. However I have a feeling deep down in my gut that Tuesday and Thursday this week will be very busy days.

moser
02-02-2006, 10:07 AM
I recieved an email from Zone Alarm about upgrading to Zone Alarm Internet Security Suite and it looks like Blackworm can come as "MyWife.d". Figured I should let you guys know.

moser
02-02-2006, 10:19 AM
I was looking around AVG's website and this is what they came up with for Blackworm. It gives the names of some of the files that Blackworm would drop into an infected machine.

http://free.grisoft.com/doc/7/lng/us/tpl/v5/idv/285850

jharriso
02-02-2006, 01:17 PM
I recieved an email from Zone Alarm about upgrading to Zone Alarm Internet Security Suite and it looks like Blackworm can come as "MyWife.d". Figured I should let you guys know.

/me makes obligatory "Take my wife, please!" joke.