GFI
English Deutsch Français Italiano Nederlands Español
GFI SecurityLabs > News 2003 > Fizzer.A - infecting through email and KaZ...

Fizzer.A - infecting through email and KaZaA leaving system wide open

We have reports of a new worm called W32/Fizzer.A which is in the wild, i.e., reported to be infecting a good number of computers. This worm arrives as an e-mail attachment and requires users to run the executable. The worm also acts as a backdoor and allows the author of the worm to execute commands on the infected computer.

Subject line:
The subject is randomly selected from the following list:

I thought this was interesting...
rather psychedelic...
found this on the net, you might like it...
discotheque
imbrue
Damn it feels good to be gangsta.
The way I feel - Remy Shand
Paradigm Shift
WASSUP!
Know Thyself
Hell
I love you
Please discard if you don't like or agree with our present leadership...
little popup remover
B cannot remember
Yo, WASSUP, B?
an interesting program...
You might not appreciate this...
I think you might find this amusing...
LOL
check this out... hehehe
question...
see you tomorrow.
how are you?
you need to lose weight.
why?
kind of simple, but fun nonetheless.
check it out.
I sent this program (Sparky) from anonymous places on the net.
The way to gain a good reputation is to endeavor to be what you desire to appear.
There is only one good, knowledge, and one evil, ignorance.
Watchin' the game, having a bud.
Did you ever stop to think that viruses are good for the economy? Maybe the primary creators of the world's worst viruses are the companies that make the Anti-Virus software.
Today is a good day to die...
so, how are you?
the attachment is only for you to look at
you must not show this to anyone...
delete this as soon as you look at it...
Let me know what you think of this...
If you don't like it, just delete it.
thought I'd let you know
you don't have to if you don't want to.

Message body:
The body is randomly selected from the following list:

I sent this program (Sparky) from anonymous places on the net.
The way to gain a good reputation is to endeavor to be what you desire to appear.
There is only one good, knowledge, and one evil, ignorance.
Watchin' the game, having a bud.
Did you ever stop to think that viruses are good for the economy? Maybe the primary creators of the world's worst viruses are the companies that make the Anti-Virus software.
Today is a good day to die...
so, how are you?
the attachment is only for you to look at
you must not show this to anyone...
delete this as soon as you look at it...
Let me know what you think of this...
If you don't like it, just delete it.
thought I'd let you know
you don't have to if you don't want to.

Attachment filename:
Makes use of the following file extensions:
.exe
.pif
.com
.scr

Attachment size:
Around 220k

If the user runs the executable the worm will send infected emails to addresses found in the Windows Address Book, Cookies, Internet Temporary Files folder, "My Documents folder" and stores them in data1-2.cab file in Windows folder.
W32/Fizzer.A makes use of the default MAPI program to send itself to the harvested email address. This worm also does the following:

  • Spreads through the KaZaA file sharing network
  • Runs a backdoor HTTP server on port 81
  • Uses ports 2018, 2019, 2020 and 2021 for a Remote Access Trojan
  • Tries to update itself from a website at Geocities
  • Tries to connect to several IRC servers to allow the worm author to send commands to the infected hosts.
  • Closes or kills AntiVirus products
  • Installs a keylogger

Severity:
Installs a backdoor on the infected system and kills Security and AntiVirus programs.

Avoidance Action:
Make sure your virus definition files are up to date. Block all incoming and outgoing .exe, .pif, .com, .scr files.

For more updated information: http://www.gfi.com/security


References:
http://www.norman.com/virus_info/w32_fizzer_a_mm.shtml
http://www.bitdefender.com/virusi/virusi_descrieri.php?virus_id=137
http://vil.nai.com/vil/content/v_100295.htm

About GFI
GFI is a leading software developer that provides a single source for network administrators to address their network security, content security and messaging needs. With award-winning technology, an aggressive pricing strategy and a strong focus on small-to-medium sized businesses, GFI is able to satisfy the need for business continuity and productivity encountered by organizations on a global scale. Founded in 1992, GFI has offices in Malta, London, Raleigh, Hong Kong, and Adelaide which support more than 200,000 installations worldwide. GFI is a channel-focused company with over 10,000 partners throughout the world. GFI is also a Microsoft Gold Certified Partner. More information about GFI can be found at http://www.gfi.com.

All product and company names herein may be trademarks of their respective owners.



 Check out GFI's product range
>  GFI MailEssentials for Exchange/SMTP
>  GFI MailSecurity for Exchange/SMTP
>  GFI MailArchiver for Exchange
>  GFI FAXmaker for Exchange/SMTP
>  GFI LANguard Network Security Scanner
>  GFI EventsManager
>  GFI EndPointSecurity
>  GFI Network Server Monitor
>  GFI WebMonitor for ISA Server

   © 2008. All rights reserved. GFI Software Home Products Download trials Support Ordering Site map About us Contact us
GFI solutions: Exchange anti spam filter - exchange anti virus - isa server - network vulnerability scanner - event log management - USB security software - exchange archiving - fax server software