When the worm executes, it creates the following files:
- %Temp%\hsperfdata_[USER NAME]\[RANDOM DIGITS]
- %Temp%\hsperfdata_[USER NAME]\[SYSTEM EXECUTABLE FILE NAME].exe
- %Temp%\hsperfdata_[USER NAME]\[RANDOM LETTERS].dll
- %Temp%\jar_cache[RANDOM DIGITS].tmp
Next, it creates the following registry entry:
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Active Setup\Installed Components\{175975F5-C68F-0875-C827-9225E76EAC65}\"StubPath" = "cmd /q /c start "" /I /B javaw -classpath %Temp%\jar_cache[NUMBERS].tmp"
The worm spreads through removable and mapped drives by creating the following files:
- %DriveLetter%\RECYCLER\[SID]\[RANDOM LETTERS].[THREE RANDOM LETTERS]
- %DriveLetter%\RECYCLER\[SID]\desktop.ini
- %DriveLetter%\autorun.inf
It then downloads a module from the following location:
[RANDOM LETTERS].[DOMAIN NAME]:[RANDOM PORT NUMBER]
Note: [DOMAIN NAME] is one of the following:
- zapto.org
- servequake.com
- servegame.com
- 3utilities.com
- serveirc.com
- myftp.org
- myvnc.com
- servecounterstrike.com
- servebeer.com
- redirectme.net
- no-ip.org
- serveftp.com
- servemp3.com
- no-ip.info
- hopto.org
- serveblog.net
- no-ip.biz
- servehalflife.com
- servepics.com
- myftp.biz
- servehttp.com
- sytes.net
The threat then opens a random UDP port on the compromised computer that the downloaded module uses.
It accesses a website chosen from the following list to calculate sleep time:
- thepiratebay.org
- msn.com
- bing.com
- alibaba.com
- paypal.com
- photobucket.com
- imageshack.us
- youporn.com
- go.com
- xhamster.com
- blogspot.com
- hotfile.com
- facebook.com
- live.com
- megaupload.com
- doubleclick.com
- apple.com
- google.com
- livejasmin.com
- adobe.com
- megavideo.com
- myspace.com
- mediafire.com
- bbc.co.uk
- amazon.com
- godaddy.com
- yieldmanager.com
- nytimes.com
- 4shared.com
- wordpress.com
- linkedin.com
- cnet.com
- conduit.com
- rapidshare.com
- about.com
- orkut.com
- microsoft.com
- craigslist.org
- flickr.com
- livejournal.com
- pornhub.com
- mozilla.com
- tube8.com
- wikipedia.org
- twitter.com
- aol.com
- cnn.com
- tumblr.com
- ebay.com
- yahoo.com
- youtube.com
- ask.com
- xvideos.com
- imdb.com
Symantec Security Response encourages all users and administrators to adhere to the following basic security "best practices":