Threat behavior
Win32/BlackAngel.D sends a link to itself to contacts listed in MSN Messenger, using one of the following messages:
“jaja look a that [link to infected file]”
“mira este video [link to infected file] jaja”
Clicking the link results in a download of fantasma.zip, which contains a file named fantasma.avi.exe. The use of the double extension may cause the filename to appear as fantasma.avi on some versions of Microsoft Windows. The file displays an icon typically associated with the Windows Media Player, thus facilitating the worm's masquerade as an .avi file.
When fantasma.avi.exe is executed, it displays a window titled 'ami' with a message in Spanish that roughly translates to "In the first day you are frightened, in the second you are hopeless, in the third you look for help and in the fourth you die."
Win32/BlackAngel.D takes the following actions:
C:\AUTOEXEC.BAT.exe
C:\CONFIG.SYS.exe
<Windows folder>\cursors\wam.exe
- Creates a test file c:\autor.txt which contains details that may relate to the worm's author.
- Drops the file ‘lstx.bat’ to the Windows system folder.
- Modifies the registry so that a copy of the worm is loaded each time Windows is started:
Adds value: "axel"
with data: "<Windows folder>\cursors\wam.exe"
in registry key: HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Run
- Modifies the registry as follows to prevent Task Manager from running:
Adds value: "disabletaskmgr"
with data: "1"
in registry key: HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Policies\system
- Modifies the registry as follows to provide markers for the worm:
Adds value: "nday"
with data: "12"
in registry key: HKEY_CURRENT_USER\Software\VB and VBA Program Settings\day\number
-and-
Adds value: "virus"
with data: "infectado"
in registry key: HKEY_CURRENT_USER\Software\VB and VBA Program Settings\ok\ami
- Periodically writes and runs a batch file to terminate the following processes:
_AVPCC, ACKWIN32, AD-AWARE, ADMINTOOL, ADVXDWIN, AGENTA, AGENTSVR, ALERTSVC, ALOGSERV, AMON9X, ANTI-TROJAN, ANTITROJ, ANTIVIRUS, APIMONITOR APLICA32, APVXDWIN, ASHDISP,, ASHQUICK, ATGUARD, ATRO55EN, ATUPDATER, ATWATCH, AUTODOWN, AUTOTRACE, AVCONSOL, AVENGINE, AVGCC32, AVGCTRL, AVGSERV, AVGSERV9, AVGUARD, AVKPOP,, AVKSERV, AVKSERVICE AVKWCTL, AVKWCTL9, AVSCHED32, AVSYNMGR, AVWINNT, AVXGUI, AVXLIVE, AVXMONITOR9X,, AVXMONITORNT, AVXQUAR, BD_PROFESSIONAL, BIDSERVER, BLACKD, BLACKICE, BOOTSCAN, BOOTWARN, CCEVTMGR, CFGINTPR, CFGWIZ, CFIADMIN, CFIAUDIT, CFINET, CFINET32, CLAW95, CLAW95CF, CLEANER, CLEANER3, CLEANPC, CMGRDIAN, CMON016, CONNECTIONMONITOR, CPFNT206, CWNB181, CWNTDWMO, DEFSCANGUI DEFWATCH, DEPUTY, DPATROL, DRWEB32, DRWEBSCD, ECENGINE,, EFPEADM, ESCANH95, ESCANHNT, ESCANV95, ESPWATCH, ETRUSTCIPE EXANTIVIRUS-CNET, EXPERT F-AGNT95, F-PROT F-PROT95, F-STOPW, FAMEH32, FINDVIRU, FIREWALL, FLOWPROTECTOR, FNRB32, FP-WIN, FSAV32 FSAV530STBYB, FSAVSTRT, FSGK32, FSMA32, FSMB32, GBMENU, GBPOLL, GENERICS, GLADIATOR, GUARDDOG, GUARDER, HACKERELIMINATOR, HACKTRACERSETUP IAMAPP IAMSERV IAMSTATS, IBMASN, IBMAVSP, ICLOAD95, ICLOADNT, ICSUPP95, ICSUPPNT, IOMON98, IPARMOR, ISRV95, JAMMER, KAVLITE40ENG, MCVSSHLD, MFW2EN MGAVRTCL, MGAVRTE, MGHTML, MGUTIL, MINILOG, MONITOR, MOOLIVE, MPFTRAY, MSSMMC32, MWATCH, N32SCANW, NAVAPSVC, NAVAPW32, NAVLU32, NAVSTUB, NAVW32, NAVWNT, NEOWATCHLOG, NEOWATCHTRAY, NETARMOR, NETINFO, NETMON, NETSCANPRO, NETSPYHUNTER-1.2, NETUTILS, NISSERV, NORMIST, NPFMESSENGER, NPSSVC, NSCHED32, NTRTSCAN, NTXCONFIG, NVARCH16, NWSERVICE, NWTOOL16, OSTRONET, OUTPOST, PADMIN, PANIXK, PAVFIRES, PAVPROXY, PAVSRV51, PCCCLIENT, PCCGUIDE, PCCIOMON, PCCNTMON, PCCPFW, PCCWIN97, PCCWIN98, PCFWALLICON, PCSCAN, PERISCOPE, PERSFW, PFWADMIN, PINGSCAN, PLATIN, POP3TRAP, POPROXY, PORTDETECTIVE, PORTMONITOR, PPVSTOP, PRAZNA, PROCMAN, PROGRAMAUDITOR, PROPORT, PROTECTX, PVIEW95, QCONSOLE, QSERVER, QTTASK, RAPAPP, RAV7WIN, RAV8WIN32ENG, RAVMON, RAVWIN8, REALMON, RMVTRJAN, RRGUARD, RSHELL, RTVSCN95, RULAUNCH, SAFEWE, SBSERV, SCAN32, SCANPM, SCRSCAN, SGSSFW32, SPHINX, SS3EDIT, SUPFTRL, SUPPORTER5, SWEEP95, SWNETSUP, SYMPROXYSVC, TASKALERT, TAUMON, TAUSCAN, TBSCAN, TDS2-NT, THGUARD, TITANIN, TITANINXP, TRJSCAN, TROJAN, TROJANHUNTER, TROJANTRAP3, TUCONF, TWEAK-XP, UMXAGENT, UMXLDRA, V530WTBYB, VBCMSERV, VBCONS, VBWIN9X, VBWINNTW, VETTRAY, VIR-HELP, VNLAN300, VPFW30S, VPTR AY, VPTRAY, VSCAN40, VSCHED, VSECOMR, VSHWIN32, VSMAIN, VSSTAT. WATCHDOG, WATCHER, WEBSCANX, WEBTRAP, WFINDV32, WGFE95, WIMMUN32, WINGATE WINRECON, WINROUTE, WRADMIN, WRCTRL, WSBGATE, XCOMMSVR, XPF202EN, ZATUTOR, ZAUINST, ZONALM2601
- Creates and runs a batch file named win_nt.bat, which forces Windows to shutdown.
Prevention