Categorized | Security

A Short Visit To Worm Palevo

I decided to continue my "a short visit to" series, with a brief analysis of the worm Palevo. Don´t expect too much it is just a summary of findings i came across…the PDF file is here.

Abstract:
This paper describes a short manual analysis of the worm Palevo. We show how we first noticed the worm at our honeypot installation and describe the currently broken propagation mechanism that exploits the MS08-067 vulnerability. We then briefly discuss Palevos general features, analyse the botnet channel, and describe the propagation mechanisms that are used. To be conform with the majority of anti-virus vendors regarding the naming of the malware, we use Palevo as the name throughout the paper. Note, that Palevo is also often called Pushbot by some anti-virus vendors.

View full post on Virus Blog

Related Posts
  • Twitter worm Profile Spy spreading fast.
    It appears that a new Twitter scam is making its way in lots of innocent users twitter account. We call this a Profile Spy worm app. Its basically a rogue Twitter application known as Profile Spy whi...
  • Worm Poses as a Font File, Uses LNK Vulnerability to Propagate
    We recently encountered a malware posing as a legitimate font file. Detected as WORM_OTORUN.ASH, the worm is a .DLL file that uses .FON as extension name. To propagate, it drops copies of itself into ...
  • New Yahoo! Messenger worm
    We have recently learned about the existence of a new Yahoo! Messenger worm doing the rounds. Potential victims receive instant messages from contacts in their list, containing a link claiming to be a...
  • Memories of the Anna Kournikova worm
    It's ten years ago today since the Anna Kournikova worm spread around the world, offering the promise of pictures of the Teutonic tennis temptress but in reality infecting your Windows computer with a...
  • New Facebook worm – don’t click da’ button baby!
    Thanks to a tip-off from colleague Gadi Evron, I've just spent some time looking into the latest Facebook worm after he alerted Facebook about it. Like so many past worms, this one uses a suggesti...
  • Introducing: Palevo Tracker
    Today we are going to talk about a nasty worm called Palevo. Palevo (also known as Rimecud, Butterfly bot or Pilleuz) made some big press in 2009 when Panda Security announced the coordinated takedown...
  • Keeping Money Mule Recruiters on a Short Leash – Part Five
    http://3.bp.blogspot.com/_wICHhTiQmrA/TUPgagiKx-I/AAAAAAAAE0c/wxcM0dZCpFY/s72-c/mule_recruitment_test_1.bmp With money mule recruitment continuing to represent the most actively used risk-forwarding t...
  • Blog: New Twitter worm redirects to Fake AV
    A new Twitter worm is spreading fast, using the “goo.gl” URL shortening service to distribute malicious links Full story: Securelist / All Updates...
  • Israel tested Stuxnet worm, says report
    The Stuxnet worm that disrupted Iran's ability to enrich uranium into bomb-grade nuclear fuel was reportedly created by Israel and the U.S. Full story: Computerworld Security News...
  • Facebook photo album chat messages spreading worm
    A new variant of the Koobface worm was making the rounds today on Facebook. This is particularly bad news. Most of the Facebook scams we report on do not infect your computer with malware; they simpl...

worm palevo

Comments are closed.

Security Status

Beware Facebook "Timeline" scams http://t.co/W5EW0cVv
1 month ago
Nigerian government (unknowingly) hosts phishing website http://t.co/uQd42ENw
1 month ago
PCMag Awards McAfee All Access its Editors’ Choice: SANTA CLARA, Calif.--(BUSINESS WIRE)--McAfee today announced... http://t.co/FakV7Vd8
1 month ago
RT @mikko: I hadn't noticed Google Maps has added 3D models of buildings. Here's a (very accurate) view of F-Secure HQ in Helsinki http://t.co/IKfAZlak
1 month ago
North Koreans aren't known for their online presence. But others may be lured into clicking Kim Jong-Il 'videos' too http://t.co/yQOon6YT
1 month ago
How to Protect Your Professional Reputation on Facebook Timeline http://t.co/I4bcR2VN
1 month ago
This is pretty impressive from @Softpedia: Facebook scans 2 trillion link clicks and blocks 220 million posts each day http://t.co/vKsn9gNl
1 month ago
Need for integrated approach to security in industrial control systems - http://t.co/tPBCNOow with @PikeResearch
1 month ago
Some free-based music we play at work http://t.co/xu5agZfc
1 month ago
Japan’s cyber defense weapon: a virus. It includes quotes by @Luis_Corrons via @InfosecurityMag
1 month ago