Via E-mail
Zafi.B sends itself to e-mail addresses collected from the affected machine. It harvests e-mail addresses from files with extension htm, wab, txt, dbx, tbb, asp, php, sht, adb, mbx, eml or pmr on local fixed drives C, D, E, F, G and H.
When searching these files, it ignores addresses containing any of these strings:
win use info help admi webm micro msn hotm suppor syma vir trend panda yaho cafee sopho google kasper
It also searches the Windows Address Book (WAB) file, which it finds by checking this registry value:
HKCU\Software\Microsoft\WAB\WAB4\Wab File Name\(Default)
It creates five files in the %System% directory to store these addresses in. These files have randomly-generated names and the extension ".DLL".
E.g. "C:\WINDOWS\System32\gcwaaaaq.dll"
The worm uses its own SMTP engine to send e-mails. It carries several templates in different languages to format e-mails. The attachment has extension ".PIF", ".EXE" or ".COM".
Please see below for examples of e-mail generated by the worm:




Via Network Share
The worm copies itself to directories with "share" or "upload" in the directory name, assuming these directories are network shares, using these filenames:
winamp 7.0 full_install.exe Total Commander 7.0 full_install.exe
Return to top
|