: W32.Sobig.F@mm ˹͹ÍÔ¹à·ÍÃìà¹çµ (worm)

¤é¹¾ºàÁ×èÍ : 19/08/2003
»ÃѺ»ÃاàÁ×èÍ : 20/08/2003
ÃдѺ¤ÇÒÁÃØ¹áç : »Ò¹¡ÅÒ§

¤Óá¹Ð¹Ó㹡Òûéͧ¡Ñ¹Ë¹Í¹ª¹Ô´¹ÕéÀÒÂã¹Í§¤ì¡Ã (ÊÓËÃѺ¼Ùé´ÙáÅÃкº)
¼Ùé´ÙáÅÃкºà¤Ã×Í¢èÒ¤ÇôÓà¹Ô¹¡Òôѧ¹Õé
- »Ô´¡Ñé¹¢éÍÁÙÅ·Õèà¢éÒÁÒ¼èÒ¹¾ÍÃìµ 990/UDP ¶Ö§ 999/UDP
- »Ô´¡Ñé¹¢éÍÁÙÅ·ÕèÍ͡仼èÒ¹¾ÍÃìµ 8998/UDP
- µÃǨ¨Ñº¡ÒÃÃéͧ¢Í NTP (¾ÍÃìµ 123/UDP) ·ÕèÍÒ¨¨ÐÁÒ¨Ò¡à¤Ã×èͧ·Õè¶Ù¡Ë¹Í¹¤Ø¡¤ÒÁ «Ö觨ÐÊè§¡ÒÃÃéͧ¢Í·Ø¡æ ªÑèÇâÁ§
- ¶éÒã¹Ãкºà¤Ã×Í¢èÒ¢ͧ·èÒ¹ÁÕà«ÔÃì¿àÇÍÃì·ÕèãËéºÃÔ¡ÒÃÍÕ-àÁÅìãËé·Ó¡ÒáÃͧÍÕ-àÁÅì·ÕèÁÕËÑÇ¢éÍÍÕ-àÁÅì´Ñ§¹Õé

 

¢éÍÁÙÅ·ÑèÇä»

W32.Sobig.F@mm ÊÒÁÒöá¾Ãè¡ÃШÒ¼èÒ¹·Ò§ÍÕ-àÁÅì â´Â¤é¹ËÒÍÕ-àÁÅìáÍ´à´Ãʢͧ¼ÙéÃѺ¨Ò¡ä¿Åì·ÕèÁÕ¹ÒÁÊ¡ØÅ´Ñ§µèÍ仹Õé
.dbx /.eml /.hlp /.htm /.html /.mht /.wab /.txt
˹͹ª¹Ô´¹ÕéÁÕ¤ÍÁâ¾à¹¹µìÊÓËÃѺ¡ÒÃÊè§ÍÕ-àÁÅì´éǵÑÇàͧ ¼èÒ¹â¾ÃⵤÍÅ·Õèãªé㹡ÒÃÊè§ÍÕ-àÁÅìª×èÍ Simple Mail Transfer Protocol (SMTP) â´ÂÍÒÈÑÂà¤Ã×èͧ·Õè¶Ù¡Ë¹Í¹ª¹Ô´¹Õ館¡¤ÒÁà»ç¹¾ÒËÐÊÓËÃѺ¡ÒÃÊè§ÍÕ-àÁÅì·ÕèṺä¿Åì¢Í§Ë¹Í¹ª¹Ô´¹ÕéÍÍ¡ÁÒã¹»ÃÔÁÒ³ÁÒ¡ áÅÐÁÕ¤ÇÒÁÊÒÁÒö㹡ÒÃá¾Ãè¡ÃШÒ¼èÒ¹¡ÒÃáªÃìä¿Åì

àÁ×èÍà¤Ã×èͧ¶Ù¡Ë¹Í¹ª¹Ô´¹Õ館¡¤ÒÁ¨Ð¶Ù¡à»Ô´¾ÍÃìµ 99x/UDP à¾×èÍÃÍÃѺ¢éÍÁÙÅ áÅÐÊè§¡ÒÃÃéͧ¢Íä»Âѧà«ÔÃì¿àÇÍÃì·ÕèãËéºÃÔ¡Òà NTP

¡ÒÃá¾Ãè¡ÃШÒ¢ͧ˹͹ª¹Ô´¹Õé¼èÒ¹·Ò§ÍÕ-àÁÅì¹Ñ鹨ÐÁÕÅѡɳТͧÍÕ-àÁÅì´Ñ§¹Õé

ª×èͼÙéÊè§ÍÕ-àÁÅì
[email protected]

ËÑÇ¢éÍÍÕ-àÁÅì Re: Details
Re: Approved
Re: Re: My details
Re: Thank you!
Re: That movie
Re: Wicked screensaver
Re: Your application
Thank you!
Your details

ä¿Åì·ÕèṺÁҡѺÍÕ-àÁÅì
application.zip (contains application.pif)
details.zip (contains details.pif)
document_9446.zip (contains document_9446.pif)
document_all.zip (contains document_all.pif)
movie0045.zip (contains movie0045.pif)
thank_you.zip (contains thank_you.pif)
your_details.zip (contains your_details.pif)
your_document.zip (contains your_document.pif)
wicked_scr.zip (contains wicked_scr.scr)

¢éͤÇÒÁã¹ÍÕ-àÁÅì
See the attached file for details
Please see the attached file for details.

ÇÔ¸Õ¡ÒÃá¾Ãè¡ÃШÒÂ

˹͹ª¹Ô´¹ÕéÊÒÁÒöá¾Ãè¡ÃШÒ¼èÒ¹·Ò§ÍÕ-àÁÅì «Öè§Ë¹Í¹ª¹Ô´¹ÕéÁÕ STMP ·ÕèãªéÊè§ÍÕ-àÁÅìä´é´éǵÑÇàͧ áÅÐÂѧÊÒÁÒöá¾Ãè¡ÃШÒ¼èÒ¹¡ÒÃáªÃìä¿Åì´éÇÂ

ÃÒÂÅÐàÍÕ´·Ò§à·¤¹Ô¤

àÁ×èÍ˹͹ W32.Sobig.F@mm ¶Ù¡àÍç¡«Ô¤Ôǵì ˹͹¨ÐÁÕ¡Ãкǹ¡Òôѧ¹Õé
1. ¤Ñ´ÅÍ¡µÑÇ˹͹àͧä»Âѧ [color=green}%Windir%\winppr32.exe
ËÁÒÂà赯 %Windir% à»ç¹µÑÇá»Ã á·¹â¿Åà´ÍÃì Windows â´Â·ÑèÇä»áÅéǨÐÍÂÙè·Õè C:\Windows ËÃ×Í C:\Winnt

2. ÊÃéÒ§ä¿ÅìãËÁèª×èÍ %Windir%\winsst32.dat
3. à¾ÔèÁ¤èÒ

"TrayX"="%Windir%\winppr32.exe /sinc"
ã¹àèÔÊ·ÃÕÂì¤ÕÂì
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run
´Ñ§¹Ñé¹Ë¹Í¹¨ÐÃѹµÑÇàͧàÁ×èÍÁÕ¡ÒÃà»Ô´à¤Ã×èͧ

˹͹ W32.Sobig.F@mm ÊÒÁÒö´ÒǹìâËÅ´ä¿Åìã´æ ÁÒà¡çºäÇéã¹à¤Ã×èͧ·Õè¶Ù¡Ë¹Í¹á¾Ãè¡ÃШÒÂáÅÐàÃÕ¡ãªé§Ò¹ä¿Åì´Ñ§¡ÅèÒÇ «Öè§¼Ùéà¢Õ¹˹͹¨Ðãªé¤ÇÒÁÊÒÁÒö¹Õé¢Í§Ë¹Í¹ã¹¡ÒââÁ¢éÍÁÙÅÊӤѭ¢Í§Ãкº áÅеԴµÑé§à¤Ã×èͧ¹ÕéãËéà»ç¹°Ò¹ã¹¡ÒÃÊè§ÍÕ-àÁÅìµèÍä»Âѧà¤Ã×èͧÍ×è¹´éÇ (Spam Relay Server)

¤ÇÒÁÊÒÁÒö¢Í§Ë¹Í¹·Õèä´é¡ÅèÒÇä»áÅéǹÑé¹ Âѧ¨Ðãªé㹡ÒÃÍѾവµÑÇ˹͹àͧ â´ÂÀÒÂãµéÊÀÒÇзÕèàËÁÒÐÊÁ ˹͹ª¹Ô´¹Õé¨Ð¾ÂÒÂÒÁµÔ´µèÍä»Âѧà«ÔÃì¿àÇÍÃìËÅÑ¡Êѡ˹Öè§à¤Ã×èͧ·Õè¼Ùéà¢Õ¹˹͹à»ç¹¼Ùé¤Çº¤ØÁ áÅéÇ˹͹¡ç¨ÐàÍÒ URL ·Õèä´éÁÒ¹Ñé¹ä»µÃǨÊͺ·Õè·Õè¨Ð´ÒǹìâËÅ´ÁéÒâ·Ã¨Ñ¹áÅеԴµÑé§ã¹à¤Ã×èͧ

ÊÀÒÇзÕè˹͹ÊÒÁÒö´ÒǹìâËÅ´ä´é¡ç¤×Í Çѹ¨Ñ¹·Ãì¶Ö§ÇÑ¹ÈØ¡Ãì µÑé§áµèàÇÅÒ 19.00 ¹.¶Ö§ 23.59.59 ¹. (à·ÕºàÇÅÒµÒÁ UTC) «Ö觤èÒàÇÅÒ UTC ·Õè˹͹ä´éÃѺ¹Ñé¹ÁÒ¨Ò¡à«ÔÃì¿àÇÍÃì·Õè·Ó˹éÒ·ÕèãËéºÃÔ¡Òà NTP ¼èÒ¹â¾ÃⵤÍÅ NTP ËÃ×;ÍÃìµ 123/UDP

ËÁÒÂà赯 NTP ÂèÍÁÒ¨Ò¡ Network Time Protocol à»ç¹â¾ÃⵤÍÅ·Õèãªé㹡ÒõÑé§àÇÅÒã¹à¤Ã×èͧãËéµÃ§¡Ñ¹ÀÒÂã¹à¤Ã×Í¢èÒÂ

˹͹àÃÔèÁµé¹¡ÒôÒǹìâËÅ´â´Â¡ÒÃÊè§¢éÍÁÙÅä»Âѧ¾ÍÃìµ 8998/UDP ¢Í§à«ÔÃì¿àÇÍÃìËÅÑ¡ (¢Í§¼Ùéà¢Õ¹˹͹ª¹Ô´¹Õé) ¨Ò¡¹Ñé¹à¤Ã×èͧà«ÔÃì¿àÇÍÃì¨ÐµÍº¡ÅѺ´éǤèÒ URL ·Õè˹͹ÊÒÁÒö¨Ðä»´ÒǹìâËÅ´ä¿ÅìÁÒàÍç¡«Ô¤Ôǵì

·Õèà¤Ã×èͧ·Õè¶Ù¡Ë¹Í¹¤Ø¡¤ÒÁÍÂÙè¨Ðà»Ô´¾ÍÃìµµèÒ§æ µèÍ仹Õé à¾×èÍÃÍÃѺ¢éÍÁÙÅ·Õèà»ç¹ UDP datagrams ¼èÒ¹à¢éÒÁÒã¹¾ÍÃìµàËÅèÒ¹Õé «Öè§ datagram ·Õèä´éÃѺ¹Ñé¹ËÅÒ¡ËÅÒÂáÅШТÖé¹ÍÂÙè¡Ñº signature ´éÇÂ

- 995/UDP
- 996/UDP
- 997/UDP
- 998/UDP
- 999/UDP
¼Ùé´ÙáÅÃкºà¤Ã×Í¢èÒ¤Ç÷ӵÒÁ´Ñ§¹Õé

- »Ô´¡Ñé¹¢éÍÁÙÅ·Õèà¢éÒÁÒ¼èÒ¹¾ÍÃìµ 990/UDP ¶Ö§ 999/UDP
- »Ô´¡Ñé¹¢éÍÁÙÅ·ÕèÍ͡仼èÒ¹¾ÍÃìµ 8998/UDP
- µÃǨ¨Ñº¡ÒÃÃéͧ¢Í NTP (¾ÍÃìµ 123/UDP) ·ÕèÍÒ¨¨ÐÁÒ¨Ò¡à¤Ã×èͧ·Õè¶Ù¡Ë¹Í¹¤Ø¡¤ÒÁ «Ö觨ÐÊè§¡ÒÃÃéͧ¢Í·Ø¡æ ªÑèÇâÁ§
- ¶éÒã¹Ãкºà¤Ã×Í¢èÒ¢ͧ·èÒ¹ÁÕà«ÔÃì¿àÇÍÃì·ÕèãËéºÃÔ¡ÒÃÍÕ-àÁÅìãËé·Ó¡ÒáÃͧÍÕ-àÁÅì·ÕèÁÕËÑÇ¢éÍÍÕ-àÁÅì´Ñ§¹Õé

ÇԸաӨѴ˹͹ª¹Ô´¹Õé

- ¡ÒáӨѴ˹͹ẺÍѵâ¹ÁÑµÔ ÇÔ¸Õ·Õè 1
1. ´ÒǹìâËÅ´â»Ãá¡ÃÁ Sysclean.com ¨Ò¡àÇçºä«µì http://www.trendmicro.com/ftp/products/tsc/sysclean.com
2. ´ÒǹìâËÅ´ä¿Åì pattern ª×èÍ lptxxx.zip ¨Ò¡ http://www.trendmicro.com/download/pattern.asp
ËÁÒÂà赯 xxx á·¹µÑÇàÅ¢àÇÍÃìªÑ¹ÅèÒÊØ´¢Í§ä¿Åì pattern
3. ᵡä¿Åì lptxxx.zip ¹Óä¿Åìª×èÍ lpt$vpn.xxx à¡çºäÇéã¹â¿Åà´ÍÃìà´ÕÂǡѺä¿Åì Sysclean.com ·Õèä´é¨Ò¡¢éÍ 1
4. µÑ´¡ÒÃàª×èÍÁµèÍà¤Ã×Í¢èÒÂ
5. ËÂØ´¡Ò÷ӧҹ·Ø¡â»Ãá¡ÃÁ ÃÇÁ·Ñé§â»Ãá¡ÃÁ»éͧ¡Ñ¹äÇÃÑÊ´éÇÂ
6. ¨Ò¡¹Ñé¹Ãѹä¿Åì Sysclean.com ¨Ð»ÃÒ¡¯ä´ÍÐÅçÍ¡ãËé·Ó¡ÒÃÊ᡹â´Â¡´»ØèÁ Scan
7. àÃÔèÁµé¹¡ÒÃãªé§Ò¹â»Ãá¡ÃÁ»éͧ¡Ñ¹äÇÃÑÊÍÕ¡¤ÃÑé§
8. ·Ó¡ÒûÃѺ»Ãا°Ò¹¢éÍÁÙÅäÇÃÑÊ·ÕèãªéÍÂÙèáÅéÇ·Ó¡ÒÃÊ᡹ÍÕ¡¤ÃÑé§à¾×èÍãËéá¹èã¨ÇèÒà¤Ã×èͧ·Õèãªé§Ò¹ÍÂÙèäÁèÁÕäÇÃÑÊ

- ¡ÒáӨѴ˹͹ẺÍѵâ¹ÁÑµÔ ÇÔ¸Õ·Õè 2
1. ´ÒǹìâËÅ´â»Ãá¡ÃÁ sobigsfx.exe ¨Ò¡àÇçºä«µì http://www.sophos.com/misc/sobigsfx.exe
2. Ãѹä¿Åì´Ñ§¡ÅèÒÇà¾×è͵ԴµÑé§ «Ö觤èÒ default â»Ãá¡ÃÁ¹Õé¨ÐµÔ´µÑé§äÇé·Õè C:\SOPHTEMP
3. µÑ´¡ÒÃàª×èÍÁµèÍà¤Ã×Í¢èÒÂ
4. àÃÕ¡ãªé§Ò¹â»Ãá¡ÃÁ command.com ÊÓËÃѺÃкº»¯ÔºÑµÔ¡ÒÃÇÔ¹â´ÇÊì 95/98/ME áÅÐâ»Ãá¡ÃÁ cmd.exe ÊÓËÃѺÃкº»¯ÔºÑµÔ¡ÒÃÇÔ¹â´ÇÊì NT/2000/XP
5. ãªé¤ÓÊÑ觴ѧµèÍ仹Õéà¾×èÍ·Ó¡ÒõÃǨËÒ˹͹ª¹Ô´¹Õé
cd c:\sophtemp
resolve -DF=SOBIG.DAT
6. ·Ó¡ÒûÃѺ»Ãا°Ò¹¢éÍÁÙÅäÇÃÑÊ·ÕèãªéÍÂÙèáÅéÇ·Ó¡ÒÃÊ᡹ÍÕ¡¤ÃÑé§à¾×èÍãËéá¹èã¨ÇèÒà¤Ã×èͧ·Õèãªé§Ò¹ÍÂÙèäÁèÁÕäÇÃÑÊ

ÇÔ¸Õ»éͧ¡Ñ¹µÑÇàͧ¨Ò¡Ë¹Í¹ª¹Ô´¹Õé

1. ¤ÇÃźÍÕ-àÁÅì·Õè¹èÒʧÊÑÂÇèÒÁÕäÇÃÑÊṺÁÒ ÃÇÁ·Ñé§ÍÕ-àÁÅì¢ÂÐáÅÐÍÕ-àÁÅìÅÙ¡â«è·Ô駷ѹ·Õ
2. ËéÒÁÃѹä¿Åì·ÕèṺÁҡѺÍÕ-àÁÅì«Öè§ÁÒ¨Ò¡ºØ¤¤Å·ÕèäÁèÃÙé¨Ñ¡ËÃ×ÍäÁèÁÑè¹ã¨ÇèÒ¼ÙéÊè§à»ç¹ã¤ÃáÅÐäÁè·ÃÒºÇèÒä¿Åì´Ñ§¡ÅèÒǹÑé¹à»ç¹ä¿ÅìÍÐäà µÅÍ´¨¹ä¿Åì·Õè¶Ù¡Êè§´éÇÂâ»Ãá¡ÃÁ»ÃÐàÀ·áªçµ (Chat) µèÒ§æ àªè¹ IRC, ICQ ËÃ×Í Pirch à»ç¹µé¹
3. µÔ´µÑé§â»Ãá¡ÃÁµè͵éÒ¹äÇÃÑÊ áÅеéͧ·Ó¡ÒûÃѺ»Ãا°Ò¹¢éÍÁÙÅäÇÃÑÊà»ç¹µÑÇÅèÒÊØ´ÍÂÙèàÊÁÍ
4. ÊÃéÒ§á¼è¹¡ÙéÃкº©Ø¡à©Ô¹ (Emergency disk) ¢Í§â»Ãá¡ÃÁ»éͧ¡Ñ¹äÇÃÑÊ áÅлÃѺ»Ãا°Ò¹¢éÍÁÙÅã¹á¼è¹ÍÂÙèàÊÁÍ
5. µÔ´µÑé§â»Ãá¡ÃÁ»ÃѺ»ÃاªèͧâËÇè (patch) ¢Í§·Ø¡«Í¿µìáÇÃìÍÂÙèàÊÁÍ â´Â੾ÒÐ Internet Explorer áÅÐÃкº»¯ÔºÑµÔ¡Òà ãËéà»ç¹àÇÍÃìªÑè¹ãËÁè·ÕèÊØ´
IE 6.0 Service Pack 1
Windows 2000 Service Pack 4
Windows XP Service Pack 1a
6. µÔ´µÑé§â»Ãá¡ÃÁ»éͧ¡Ñ¹äÇÃÑÊ áÅеéͧ·Ó¡ÒûÃѺ»Ãا°Ò¹¢éÍÁÙÅäÇÃÑÊà»ç¹µÑÇÅèÒÊØ´ÍÂÙèàÊÁÍ
7. µÑ駤èÒ security zone ¢Í§ Internet Explorer ãËéà»ç¹ high ´Ñ§¤Óá¹Ð¹Ó·Õè http://thaicert.nectec.or.th/paper/virus/zone.php
8. ·Ó¡ÒÃÊÓÃͧ¢éÍÁÙÅã¹à¤Ã×èͧÍÂÙèàÊÁÍ áÅÐàµÃÕÂÁËÒÇÔ¸Õ¡ÒÃá¡éä¢àÁ×èÍà¡Ô´à˵آѴ¢éͧ¢Öé¹
9. µÔ´µÒÁ¢èÒÇÊÒÃá¨é§àµ×͹à¡ÕèÂǡѺäÇÃÑʵèÒ§æ «Öè§ÊÒÁÒö¢ÍãªéºÃÔ¡ÒÃÊè§¢èÒÇÊÒüèÒ¹·Ò§ÍÕ-àÁÅì¢Í§·ÕÁ§Ò¹ ThaiCERT ä´é·Õè http://thaicert.nectec.or.th/mailinglist/register.php
10. ÊÒÁÒöÍèÒ¹ÃÒÂÅÐàÍÕ´à¾ÔèÁàµÔÁà¡ÕèÂǡѺÇÔ¸Õ»éͧ¡Ñ¹µÑÇàͧ¨Ò¡äÇÃÑÊ·ÑèÇä»ä´éã¹ËÑÇ¢éÍ ÇÔ¸Õ»éͧ¡Ñ¹µÑÇàͧãËé»ÅÍ´ÀѨҡäÇÃÑʤÍÁ¾ÔÇàµÍÃì

 

 

¡ÅѺ˹éÒáá¤èÐ

 

Hosted by www.Geocities.ws

1