Malware City/Blog/

Jan
24
Filed Under:
ALERTS

Virus infects worm by mistake

24 January 2012
New malware morphs into different shapes unattended by humans

Ten years ago, there was a clear-cut distinction between Trojans, viruses and worms. They all had their own features specific to one family of malware only. As more people connected to the internet, cyber-criminals started mixing ingredients to maximize impact. And here I’m thinking Trojans with worm capabilities or viruses with Trojan features, and so on.

Now, another “practice” has silently emerged: the file infector that accidentally parasites another e-threat. A virus infects executable files; and a worm is an executable file. If the virus reaches a PC already compromised by a worm, the virus will infect the exe files on that PC - including the worm. When the worm spreads, it will carry the virus with it. Although this happens unintentionally, the combined features from both pieces of malware will inflict a lot more damage than the creators of either piece of malware intended.

While most file infectors have inbuilt spreading mechanisms, just like Trojans and worms (spreading routines for RDP, USB, P2P, chat applications, or social networks), some cannot replicate or spread between computers. And it seems a great idea to “outsource” the transportation mechanism to a different piece of malware (i.e. by piggybacking a worm).

Most likely these Frankenmalware, or “malware sandwiches,” take place spontaneously. The virus actually infects by mistake another piece of malware and ends up using its capabilities to spread. Bitdefender’s Antimalware Lab identified no less than 40,000 such malware symbioses out of a sample pool of 10 million files. One such case is the Virtob file infector, whose malicious code has been found infecting worms like OnlineGames, the ancient Mydoom or the more advanced Bifrose backdoor Trojan.

From the numerous samples of worms infected by viruses, we picked out the Win32.Worm.Rimecud -Win32.Virtob pair.

A few words about Win32.Worm.Rimecud

Win32.Worm.Rimecud is your typical worm with a state-of-the-art spreading apparatus. For propagation it uses file-sharing applications (Ares P2P, BearShare, iMesh, Shareaza. Kazaa, DC++, eMule, LimeWire), USB devices, Microsoft MSN Messenger (sends all contacts links to sites that host malware) and network drives mapped locally. Once on the system, Rimecud injects its code into explorer.exe and steals passwords pertaining to e-banking, on-line shopping, social networking or e-mail accounts from Mozilla Firefox and Internet Explorer. In the meantime its backdoor component enables it to connect to the C&C servers and fetch commands such as flood, download and execute further malware on the compromised PC. On top of that, the worm looks for a VNC server (remote control software) that would allow the attacker remote access and control of the compromised PC.

And certain details about Win32.Virtob

Bitdefender labs have recently seen attached a file infector to the above mentioned worm - Win32.Virtob. This virus is known to infect executable files with .exe or .scr extensions by affixing a piece of malicious code to those files. The worm is an executable file, so chances are it also gets infected by the virus if it’s on the same computer. Virtob then instructs the compromised executable files to firstly run the viral code (by changing the entry point) and only afterwards gives control back to the original file. Certainly this also applies to the worm - its code will be executed only after the virus code has been launched. When its code is successfully loaded into the memory, Virtob connects to two IRC servers that are in fact C&C servers, and with the help of its backdoor component, the virus is ready to receive commands from a remote attacker via the Internet.

By injecting its code into winlogon.exe and then adding this process to the firewall exception list, the virus makes sure it is granted complete Internet access and ensures its persistence – Winlogon is a critical process that, if terminated, will crash the computer.  Afterwards, it infects HTML, HTM, PHP, ASP files by injecting IFrames that might silently load content from malware-laden pages.

Now, imagine these two pieces of malware working together - willingly or not - from and on the same compromised system. That PC faces a twofold malware with twice as many command and control servers to query for instructions; moreover, there are two backdoors open, two attack techniques active and various spreading methods put in place. Where one fails, the other succeeds.  

Multiple Frankenware infections possible:

If, by utter bad luck, the computer has more than one worm that applies to the virus specifications, the virus could infect more than one worm on the system. However, the virus might as well only infect the executable files in certain system locations, or of a certain length. Other viruses look for certain strings that pertain to other pieces of malware which will remain uninfected if found on the compromised system. So, one worm can be infected while others on the same system are not.

If one of the two (whether the virus or the worm) is caught by the AV, the other might pass undetected. Perhaps if we think of an infected file (possibly the virus) that needs to be analyzed separately and a piece of code is taken out and looked at, maybe then someone discovers also the worm. If the worm is detected based on a signature, the worm is simply wiped out from the compromised system, without any further analysis. This would make it easier for the virus to pass unseen. There’s no rule.

And two hypothetical scenarios:

Hypothetical scenario No. 1:

Imagine a worm like Downadup, that has been spreading constantly around the world for three years now (70,000 infected systems in the last six months alone), being infected with a virus. On the one hand, Downadup prevents the system from updating the OS and the AV solution locally installed; and on the other hand the virus may have rootkit capabilities and open a backdoor. Downadup spreads around the world constantly, which makes it a great propagation tool; not to mention that it took AVs more than half a year, and almost a million infections, to discover it. If this had carried along a virus, all those users would have suffered greater damage. And disinfection would be more complicated.

Hypothetical scenario No. 2:

Imagine that a worm is infected by a file infector (virus). And an AV detects the file infector first and tries to disinfect the files, which include the worm. In some rare cases disinfecting compromised files leaves behind clean files that are at the same time altered (not identical to the original anymore). They maintain their functionality but are slightly different in form. As most files are detected according to signatures and not based on their behavior (heuristically), an altered worm (disinfected along with other files that have been compromised by a file infector and disinfected by an antivirus) may not be caught anymore by the signature applied to the original file (that had been modified after disinfection). Disinfection might this way lead to a mutation that can actually help the worm.

This article is based on the technical information provided courtesy of Doina Cosovan & Răzvan Benchea, Bitdefender VirusAnalysts.

All product and company names mentioned herein are for identification purposes only and are the property of, and may be trademarks of, their respective owners.




Loredana sees in BitDefender a new challenge and a fresh approach to her professional development. Her enthusiasm, curiosity and, of course, lots of research, are some of the features that make her a competitive player in the security industry.

Comments:

Cory said on Jan-25-2012 13:38

This is dumb.

BlackNet said on Jan-25-2012 19:32

Not sure why someone would say this is dumb. This is happening more and more in cyberspace, as is viruses that are being being detected right away.

Cory said on Jan-26-2012 16:35

Given this powerful, content-full rebuttal I must now retract my claim that this is dumb!

Foofus said on Jan-26-2012 16:46

Cory: You're just not being visionary enough. What about when worms infected with viruses then infect the CLOUD! You'll have spore-ware!

Next thing you know it, the spore-ware has infected our critical infrastructure, and you end up with viruses in worms in clouds in SCADA!

The headline will read "Germ'd Worm stands firm; Spore Scores, Whole 'net reset".

Junga said on Jan-29-2012 09:03

Cory, are you saying this is "dumb" because cyber-criminals are doing this to harm everyone/ or are you saying it because you are not worrying about the risk these viruses can cause? We all need to protect ourselves if we want to enjoy surfing the internet.

Rick Noel said on Jan-29-2012 13:38

Interesting article Loredana. Sounds like a pretty dangerous 1-2 punch, much like mutating, anti-biotic resistant viruses in the biological sense. Social media and gaming are great distribution channels for the mutated malware menaces. Smartphones are also probably fertile ground for these kind of hybrid threats as well. Yeah, there is an app for that ?;-) The key is education on the risks, likelihood of infection, impact of an infection and understanding how to protect yourself with the appropriate counter measures based on that information. For example, If you do online banking on a particular device for instance, you should minimize risky activities on that device, which one can only do if they know what constitutes a "risky activity." The last thing anyone needs is to have a critical account username/password compromised as each account may have different liability for the account owner in the case of online theft.

Darren Martyn said on Jan-31-2012 06:16

From a biologists perspective this was just waiting to happen. What I wonder is whether it is parasitic or symbiotic.
Example. File infecting banking trojan infects a worms .exe file. Worm spreads, also spreading banking trojan/file infector virus. Does the spread-ed version of the trojan/worm hybrid then spread farther spreading the worm with it, making it symbiotic, or is it merely parasitic where the virus piggybacks the worm?

Kind of like evolution. You could have a dozen pieces of malware colliding and "sharing" spreading techniques rather easily.

This article kind of proves an idea I had a while back :)

Br.Bill said on Jan-31-2012 10:58

In computing, as in biology, the best defense is a diversity of hosts, preventing the spread of and destruction by a single virulent strain of malware. Currently 3 operating systems dominate with >99% saturation, all running on the x86 architecture.

This is not enough diversity. One could argue that there are a lot of different linux variants, but percentagewise few people are using them. The result is that the dominant host OS, Windows, is ripe for widespread infection. You can keep inoculating Windows system all you want, but there's always another potential infiltrator (and as this article explains, possibly piggybacked agents) about to attack.

Helio Perroni FIlho said on Jan-31-2012 11:22

Programs hacking programs...

Impossible? Inevitable!

Dave Stevens said on Jan-31-2012 12:21

I think this provides an opprotunity to help fight malware. This calls for development of a virus that does just this, and then kills the worm and itself. Think of antibiotics for computers

Whatever said on Jan-31-2012 15:08

Skynet is waiting to be born.

Felicity Pilchard said on Feb-2-2012 11:40

Worms infecting viruses, reminds me of the beginnings of terrestrial life when mitochondria infected primitive cells forming symbiotes with much greater capabilities, that could eventually evolve into us.

Is this the start of Artificial Life? As "Whatever" said... skynet :-/

I imagine some descendant of these, a virtual St. Augustine, trying to visualise the programmers that created his universe, and a virtual Nietzsche saying that "programmer is dead". Unfortunately, by then he may be right.

jogos online said on Feb-5-2012 16:30

We have delivered thousands of fans, followers, likes and views to thousands of pages. Boost your online social marketing efforts with quality,

mdd3958504 said on Feb-16-2012 00:19

I’m so jealous!

beach wedding dresses said on Feb-16-2012 00:20

I always enjoy reading your frugal ideas. They are inspiring and helpful. Thanks for another great article.

Cartier Love Bracelet Replica said on Feb-18-2012 04:19

Great post for us artists, thank you for posting it! Cheers!7@gmail.com

Comment on this

Name:

Email:

Website:

Your email adress will not be published.