Security Forums

Log in

FAQ | Search | Usergroups | Profile | Register | RSS | Posting Guidelines | Recent Posts

New Virus Swen-A W32/Gibe-F - I-Worm.Swen - W32/Swen.A@mm

Users browsing this topic:0 Security Fans, 0 Stealth Security Fans
Registered Security Fans: None
Goto page 1, 2  Next
Post new topic   Reply to topic   Printer-friendly version    Security Forums Index -> Viruses // Worms

Special offer!

TechGenix and SolarWinds have partnered to provide a fully-functional, free 21-day trial version of SolarWinds ipMonitor, the WindowsNetworking.com Readers' Choice Award Winner for monitoring applications, servers, and network devices to all visitors who join Security Forums. Sign up to Security Forums and get your copy today! Existing members can pick up a copy from the Members Area.

View previous topic :: View next topic  
Author Message
ShaolinTiger
Forum Fanatic
Forum Fanatic


Joined: 18 Apr 2002
Posts: 2762
Location: Kuala Lumpur, Malaysia

Offline

PostPosted: Fri Sep 19, 2003 1:57 am    Post subject: New Virus Swen-A W32/Gibe-F - I-Worm.Swen - W32/Swen.A@mm Reply with quote

As a follow on from: http://www.security-forums.com/forum/viewtopic.php?t=8446

Known as W32/Gibe-F - I-Worm.Swen - W32/Swen.A@mm W32/Gibe.C.worm W32.Swen-A

Unusually Messagelabs currently has nothing on this one, only stats for W32/Gibe-E not W32/Gibe-F which is this variant.Looks realistic too has a nice icon and installs as below:







It's an exe attachment with a HTML e-mail so as always, if you've taken our advice before and blocked all executable extensions at the e-mail gateway this wont effect you Twisted Evil
_________________
Share your knowledge, it's a
way to achieve Immortality.

Quit Smoking - Darknet Hacking

Kung-Fu Geekery


Last edited by ShaolinTiger on Tue Sep 23, 2003 5:59 pm; edited 2 times in total
Back to top
View user's profile Send private message Visit poster's website
werem00se
New Member
New Member


Joined: 28 Aug 2002
Posts: 40
Location: U.S.A (west)

Offline

PostPosted: Fri Sep 19, 2003 2:04 am    Post subject: Reply with quote

I've had numerous calls on this today. (content filtering at the firewall is cool Razz ). The attachments vary a bit in name. Clever bit of effort involved in the social engineering end...
_________________
#include <stdio.h>
int main(void)
{
int count;
for(count=1;count<=500;count++);
printf("I will play nice with others.");
return 0;
}
Back to top
View user's profile Send private message
PhiBer
Trusted SF Member
Trusted SF Member


Joined: 11 Mar 2003
Posts: 1092
Location: Your MBR

Offline

PostPosted: Fri Sep 19, 2003 2:16 am    Post subject: Reply with quote

Ya, i think alot of people who dont know much about computers are gunna open this one!!! Confused
Our district is still getting flooded with spam mail that has virus attachments!
_________________
"The ultimate measure of a man is not where he stands in moments of comfort, but where he stands at times of challenge and controversy" –Martin Luther King
Back to top
View user's profile Send private message
hugo
Forum Junky
Forum Junky


Joined: 14 Jun 2003
Posts: 944
Location: Netherlands, Europe

Offline

PostPosted: Fri Sep 19, 2003 9:00 am    Post subject: Reply with quote

I've also read that the virus /worm in question hits a web-counter everytime it infects a machine, which is on itself quite interesting.

The URL of the counter was also posted on Full-Disclosure, but as visiting it also increases the hits, the number it states does not really represent the number of actual infections..
_________________
-- sig!
Back to top
View user's profile Send private message
Rottz
Frequent Member
Frequent Member


Joined: 29 Mar 2003
Posts: 196
Location: East Coast, USA

Offline

PostPosted: Fri Sep 19, 2003 6:28 pm    Post subject: New virus alert: W32/Gibe.E-mm (aka W32/Swen.A-mm) Reply with quote

New virus alert: W32/Gibe.E-mm (aka W32/Swen.A-mm) - HIGH LEVEL

On 14th September 2003, MessageLabs the email security company intercepted several copies of a
new mass-mailing virus, which were initially identified as a new variant of the Gibe family of
viruses.

The initial copies all originated from Slovakia, and some later copies originated from the Netherlands.

The proportion of emails carrying this virus have risen to 1 in 355 in the last 24-hours, and
MessageLabs have therefore classified this as a high-level outbreak situation.

Name: W32/Swen.A-mm
Aliases: W32/Gibe.F-mm, W32/Swen.A-mm
Number of copies intercepted so far: 616,665
Time & Date first Captured: 14 Sep 2003 19:30 GMT
Peak infection date: 23 Sep 2003
Origin of first intercepted copy: Slovak Republic
Countries stopped in: 172
Most affected countries: USA (36%), UK (39%), Netherlands (9%)
Peak infection ratio: 1 / 86

Stats as of: 9/24/03 4:10pm EST

Characteristics

Initial analysis would suggest that this strain is a mass-emailing virus, and is similar to the
earlier Gibe strain of viruses, however, there latterly may be sufficient differences to give
rise to a new family and further analysis will be required. The emails appear to be different,
and the attachment name may vary.

MessageLabs detected all strains of this virus proactively, using its unique and patented
Skeptic predictive technology. This virus was also detected heuristically by NAI.

More Info: W32/Swen.A-mm
--------------------------------------------------------------------------------------
AusCERT Update AU-2003.015
New email virus/worm "Swen" masquerades as Microsoft Update

Users and system administrators should be aware of a new mass-mailer worm
that purports to be the "September 2003, Cumulative Patch" for MS Internet
Explorer, MS Outlook and MS Outlook Express. The worm arrives as an
attachment with a .exe extension. In addition to email vectors, Swen will
attempt to spread through file-sharing networks and will attempt disable
antivirus programs and personal firewall programs on an infected computer.

This particular executable may be detected by anti-virus systems as the
W32/Gibe-F virus. It may also arrive in an email message appearing to be
a qmail delivery failure notice.

Some email subject lines that Swen may use are:
  • New Internet Security Update
  • net security upgrade
  • New Net Critical Update
  • Mail: User unknown
REFERENCES:

[1] Protecting your computer from malicious code
http://www.auscert.org.au/render.html?it=3352

[2] Information on Bogus Microsoft Security Bulletin E-mails
http://www.microsoft.com/technet/security/news/patch_hoax.asp

[3] F-Secure Virus Descriptions
http://www.europe.f-secure.com/v-descs/swen.shtml

[4] Symantec Security Response - W32.Swen.A@mm
http://securityresponse.symantec.com/avcenter/venc/data/w32.swen.a@mm.html

[5] Computer Associates Virus - Win32.Swen.A
http://www3.ca.com/virusinfo/virus.aspx?ID=36939

[6] McAfee Security
http://us.mcafee.com/virusInfo/default.asp?id=description&virus_k=100662

[7] Trend Micro
http://www.trendmicro.com/vinfo/virusencyclo/default5.asp?VName=WORM_SWEN.A&VSect=T

[8] Sophos virus analysis: W32/Gibe-F
http://www.sophos.com/virusinfo/analyses/w32gibef.html

[9] MessageLabs
http://www.messagelabs.com/viruseye/info/default.asp?virusname=W32%2FGibe%2EE%2Dmm

When possible, upgrade all anti-virus software to use the latest definition
files as soon as they become available.

Ensure that all network file shares are disabled unless necessary and if
possible ensure that active shares are password protected.

AusCERT advises members to disseminate and take action on this information
to prevent any undesirable activity by this virus within their sites. Users
should be again reminded that unsolicited attachments should not be opened.

Full Advisory: http://www.auscert.org.au/render.html?it=3455&cid=1
--------------------------------------------------------------------------------------
The Email about the Web Counter from Richard M Smith is [url=lists.netsys.com/pipermail/full-disclosure/2003-September/010442.html]here[/url].

Virus in the News:

Updated 9/24: Updated MessageLab Stats and Name, Added More Virus News


Last edited by Rottz on Wed Sep 24, 2003 10:15 pm; edited 1 time in total
Back to top
View user's profile Send private message Visit poster's website AIM Address Yahoo Messenger MSN Messenger
Rottz
Frequent Member
Frequent Member


Joined: 29 Mar 2003
Posts: 196
Location: East Coast, USA

Offline

PostPosted: Wed Sep 24, 2003 10:03 pm    Post subject: Responds from Microsoft Reply with quote

Today I had my usual bunch of emails with the Swen virus, and I'm getting sick of receiving them like everyone else, so I decided to follow the advice of Jason Coombs in his Swen Really Sucks post on Full Disclosure list, and forward all of them to secure@microsoft.com just to annoy them like I am annoyed! Evil or Very Mad

Then I actually got a reply! Surprised Shocked

Here it is:
secure@microsoft.com wrote:
From: Microsoft Security Response Center <secure@microsoft.com>
To: <rottz@securityflaw.com>
Cc: Microsoft Security Response Center <secure@microsoft.com>
Subject: RE: New Network Security Pack (fwd) [st]

Hi,

Thanks, we're aware of this and have posted a page on it at:

http://www.microsoft.com/technet/security/virus/alerts/swen.asp

Secure@microsoft.com
Back to top
View user's profile Send private message Visit poster's website AIM Address Yahoo Messenger MSN Messenger
Anub!$
Forum Addict
Forum Addict


Joined: 23 Sep 2003
Posts: 251
Location: Computer Chair

Offline

PostPosted: Fri Sep 26, 2003 3:01 am    Post subject: Responds from Microsoft Reply with quote

A friend of mine said that this week his works e-mail accounts recieved many e-mails with attachments which were detected as Worm.Automat.AHB.

Which as you know is the W32/Swen.A-mm, But it just goes to show how vulnerable many networks are from this sort of thing.

simple lesson is never open an e-mail attachment unless you know what it is for absolute certian.
Back to top
View user's profile Send private message
browolf
Trusted SF Member
Trusted SF Member


Joined: 19 Apr 2002
Posts: 590


Offline

PostPosted: Fri Sep 26, 2003 10:00 am    Post subject: Reply with quote

i never previously got emails with virus in at work and now i'm getting like 20 a day of these. They're harmless but the time they reach here as our upstream provided virus checks all mail.

they all arrive looking like:
------------------ Virus Warning Message (on sweeper3) Found virus WORM_SWEN.A in file Install.exe The uncleanable file is deleted. ---------------------------------------------------------

Smile
_________________
azjol nerub 60 rogue
Back to top
View user's profile Send private message
oeb
Frequent Member
Frequent Member


Joined: 17 Mar 2003
Posts: 151
Location: That Island of drunks over there

Offline

PostPosted: Fri Sep 26, 2003 10:20 am    Post subject: Reply with quote

Ha, you think you are bad.

I got 111 emails between 7pm last night and 9am this morning

18 were spam
2 were from clients
91 were gibe.


This sucks.
_________________
Quidquid latine dictum sit, altum viditur
http://www.4o3.net - A work in progress
Back to top
View user's profile Send private message Visit poster's website MSN Messenger
NTidd
New Member
New Member


Joined: 11 Sep 2003
Posts: 27
Location: Office

Offline

PostPosted: Fri Sep 26, 2003 2:19 pm    Post subject: Reply with quote

I nearly had to reload my machine, somehow it got infected, after I deleted the infected file, most of my executables wouldn't run. After I finally figured it out, I just had to change some values back in the registry. I think that I had a variant of some sort because I never received any of those Microsoft messages until after I somehow got infected. The virus also didn't do everything that the AV sites said. It also did some extra stuff. My antivirus wouldn't detect it at the time even tho my defs were up to date, but the process may of not been running at all.
Back to top
View user's profile Send private message AIM Address Yahoo Messenger MSN Messenger
Anub!$
Forum Addict
Forum Addict


Joined: 23 Sep 2003
Posts: 251
Location: Computer Chair

Offline

PostPosted: Fri Sep 26, 2003 7:16 pm    Post subject: New Virus Swen-A W32/Gibe-F - I-Worm.Swen - W32/Swen.A-at-mm Reply with quote

Do you use kazaa or anything Question

It spreads through that aswell.
Back to top
View user's profile Send private message
Mongrel
Trusted SF Member
Trusted SF Member


Joined: 30 May 2002
Posts: 1347


Offline

PostPosted: Fri Sep 26, 2003 9:44 pm    Post subject: Interesting twist on W32.Swen.A@mm Reply with quote

I've been getting dozens of these disguised as undeliverable E Mail.

The recipient is led to believe they sent an emiai to some fictitious
address. Since most mail systems treat the original undelivered message
as an attachment, the user is tricked into opening what they think will be
an E Mail they sent when in actuality they are installing the virus.

Many many variations. Here's a few examples:

This one was from "mail delivery service <lmailbot@microsoft.com>"
addressed to "mail user <receiver@smtpserver.net>" with a subject
of "Failure Advice"

"This is the qmail program

I'm afraid the message returned below could not be delivered to the
following addresses:

Undelivered message to elrsnp@microsoft.com

Message follows:"

This one was from "Admin <umaildaemon@freemail.com>" addressed
to "Network Client <recipient@emaildomain.com>"
with a subject of "Mail Returned To Sender"

"This is the qmail program

I'm sorry to have to inform you that I wasn't able to deliver your
message to one or more destinations.

Undelivered message to lzsuwea@freemail.com

Message follows:"


Last edited by Mongrel on Fri Sep 26, 2003 9:52 pm; edited 3 times in total
Back to top
View user's profile Send private message
NTidd
New Member
New Member


Joined: 11 Sep 2003
Posts: 27
Location: Office

Offline

PostPosted: Fri Sep 26, 2003 9:45 pm    Post subject: Re: New Virus Swen-A W32/Gibe-F - I-Worm.Swen - W32/Swen.A-a Reply with quote

Aviator wrote:
Do you use kazaa or anything Question

It spreads through that aswell.


Nope, it is my machine at werk, don't run much of anything on it except outlook and dreamweaver.
Back to top
View user's profile Send private message AIM Address Yahoo Messenger MSN Messenger
Rottz
Frequent Member
Frequent Member


Joined: 29 Mar 2003
Posts: 196
Location: East Coast, USA

Offline

PostPosted: Fri Sep 26, 2003 11:34 pm    Post subject: Re: New Virus Swen-A W32/Gibe-F - I-Worm.Swen - W32/Swen.A-a Reply with quote

NTidd wrote:
Nope, it is my machine at werk, don't run much of anything on it except outlook and dreamweaver.

Also spreads thru network shares, which I assume you have at work, so someone on your network might have got the email and opened it and now has infected your whole network, you might want to contact your IT Security department and notify them so they can try to disinfect the systems and stop it from spreading.

Here is some info from Symantec's Swen.A page
Transmission through mapped drives
When attempting to spread through mapped drives, W32.Swen.A@mm does so to the following locations:
  • \Win98\Start menu\Programs\Startup
  • \Win95\Start menu\Programs\Startup
  • \WinMe\Start menu\Programs\Startup
  • \Windows\Start menu\Programs\Startup
  • \Documents and Settings\All Users\Start menu\Programs\Startup
  • \Documents and Settings\Administrator\Start menu\Programs\Startup
  • \Documents and Settings\Default User\Start menu\Programs\Startup
  • \Winnt\Profiles\All Users\Start menu\Programs\Startup
  • \Winnt\Profiles\Administrator\Start menu\Programs\Startup
  • \Winnt\Profiles\Default User\Start menu\Programs\Startup
Back to top
View user's profile Send private message Visit poster's website AIM Address Yahoo Messenger MSN Messenger
NTidd
New Member
New Member


Joined: 11 Sep 2003
Posts: 27
Location: Office

Offline

PostPosted: Sat Sep 27, 2003 12:35 am    Post subject: Reply with quote

Yeah, I am part of the IT Department, we do consulting for other businesses, anyways, I don't have any mapped drives on my pc, nobody else in the office is having problems, this was last Wednesday when it all happened. I sometimes toy with different things like that on my pc, but wasn't doing anything in particular that day, who knows what happened, I was just glad that I found out what virus it was before I decided to reload it. Just had to fix some of the registry keys, it was modified to open a particular executable when any executable is ran, after I deleted that, then nothing would run unless I ran it from a command prompt.
Back to top
View user's profile Send private message AIM Address Yahoo Messenger MSN Messenger
Mongrel
Trusted SF Member
Trusted SF Member


Joined: 30 May 2002
Posts: 1347


Offline

PostPosted: Sat Sep 27, 2003 4:33 am    Post subject: Reply with quote

NTidd - yeh - aint it fun to play around at work and ... errrr .

Recently I was bringing up the network after the blackout - and one
server would not connect to the outside. Long story short, I temporarily
opened up the firewall as a test. It stayed open for long enough to let mr.
blaster in.

Doooooh!
Back to top
View user's profile Send private message
Display posts from previous:   

Post new topic   Reply to topic   Printer-friendly version    Security Forums Index -> Viruses // Worms All times are GMT + 2 Hours
Goto page 1, 2  Next
Page 1 of 2


 
Jump to:  
You cannot post new topics in this forum
You cannot reply to topics in this forum
You cannot edit your posts in this forum
You cannot delete your posts in this forum
You cannot vote in polls in this forum

Community Area

Log in | Register