<?xml version="1.0" encoding="UTF-8"?>
<rss version="2.0"
	xmlns:content="http://purl.org/rss/1.0/modules/content/"
	xmlns:wfw="http://wellformedweb.org/CommentAPI/"
	xmlns:dc="http://purl.org/dc/elements/1.1/"
	xmlns:atom="http://www.w3.org/2005/Atom"
	xmlns:sy="http://purl.org/rss/1.0/modules/syndication/"
	xmlns:slash="http://purl.org/rss/1.0/modules/slash/"
	xmlns:itunes="http://www.itunes.com/dtds/podcast-1.0.dtd"
	xmlns:media="http://search.yahoo.com/mrss/"
>

<channel>
	<title>Fortinet Security Blog &#187; hybrid</title>
	<atom:link href="http://blog.fortinet.com/tag/hybrid/feed/" rel="self" type="application/rss+xml" />
	<link>http://blog.fortinet.com</link>
	<description>Real Time Network Protection</description>
	<lastBuildDate>Fri, 27 Jan 2012 11:59:33 +0000</lastBuildDate>
	<language>en</language>
	<sy:updatePeriod>hourly</sy:updatePeriod>
	<sy:updateFrequency>1</sy:updateFrequency>
	<generator>http://wordpress.org/?v=3.1.3</generator>
	<!-- podcast_generator="podPress/8.8" -->
		<copyright>&#xA9;Fortinet Product Marketing </copyright>
		<managingEditor>rpopko@fortinet.com (Fortinet Product Marketing)</managingEditor>
		<webMaster>rpopko@fortinet.com(Fortinet Product Marketing)</webMaster>
		<category>Fortinet Product Information</category>
		<ttl>1440</ttl>
		<itunes:keywords>forti-gate, anti-spam, anti-virus, fortigate</itunes:keywords>
		<itunes:subtitle>The latest news and information about Fortinet products and services for Real Time Network Protection.</itunes:subtitle>
		<itunes:summary>Fortinet is a leading provider of Unified Threat Management (UTM) network security solutions for enterprise and service provider environments. The Fortinet FortiCast delivers news, information, and tutorials about products, services, and industry trends. Fortinet's FortiGate product line and FortiGuard security subscription services provide an array of integrated network security functions including antivirus, firewall, virtual private networking, intrusion prevention (IPS), web filtering, antispam and traffic optimization. </itunes:summary>
		<itunes:author>Fortinet Product Marketing</itunes:author>
		<itunes:category text="Technology"/>
<itunes:category text="Technology">
  <itunes:category text="Tech News"/>
</itunes:category>
		<itunes:owner>
			<itunes:name>Fortinet Product Marketing</itunes:name>
			<itunes:email>rpopko@fortinet.com</itunes:email>
		</itunes:owner>
		<itunes:block>No</itunes:block>
		<itunes:explicit>no</itunes:explicit>
		<itunes:image href="http://blog.fortinet.com/wp-content/uploads/2009/01/forticast-300x300.jpg" />
		<image>
			<url>http://blog.fortinet.com/wp-content/uploads/2009/01/forticast-144x144.jpg</url>
			<title>Fortinet Security Blog</title>
			<link>http://blog.fortinet.com</link>
			<width>144</width>
			<height>144</height>
		</image>
		<item>
		<title>Virut infecting worms, hitching a ride</title>
		<link>http://blog.fortinet.com/virut-infecting-worms-hitching-a-ride/</link>
		<comments>http://blog.fortinet.com/virut-infecting-worms-hitching-a-ride/#comments</comments>
		<pubDate>Mon, 16 Mar 2009 17:40:09 +0000</pubDate>
		<dc:creator>DManky</dc:creator>
				<category><![CDATA[Research]]></category>
		<category><![CDATA[Security]]></category>
		<category><![CDATA[hybrid]]></category>
		<category><![CDATA[parasitic infector]]></category>
		<category><![CDATA[piggyback]]></category>
		<category><![CDATA[propagate]]></category>
		<category><![CDATA[virut]]></category>

		<guid isPermaLink="false">http://blog.fortinet.com/?p=199</guid>
		<description><![CDATA[Back in 2004, several mass mailing worms spread in unprecedented fashion: MyDoom, Bagle, and Netsky. Netsky had instructions to remove MyDoom and Bagle, leaving this message in one of its variants: &#8220;We are the skynet&#8211;you can&#8217;t hide yourself&#8212;we kill malware&#8230;MyDoom.f is a thief of our idea!&#8221;. This turf war was not the only one to [...]]]></description>
			<content:encoded><![CDATA[<p>Back in 2004, several mass mailing worms spread in unprecedented fashion: MyDoom, Bagle, and Netsky. Netsky had instructions to remove MyDoom and Bagle, leaving this message in one of its variants: &#8220;We are the skynet&#8211;you can&#8217;t hide yourself&#8212;we kill malware&#8230;MyDoom.f is a thief of our idea!&#8221;. This turf war was not the only one to happen, Storm took a similar approach to Warezov/Stration in late 2007.</p>
<p>Here we are in 2009, five years later; Netsky is still quite prevalent. It is commonly used as a benchmark, and has persistently been in our top ten ranking of malware on a monthly basis. While MyDoom and Bagle have not quite enjoyed the same dominating success, there has been another interesting virus which indeed has: Virut. <a id="q0pv" title="W32/Virut.A" href="http://www.fortiguardcenter.com/VirusEncyclopedia/search/encyclopediaSearch.do?method=viewVirusDetailsInfo&amp;fid=252377">W32/Virut.A</a> has consistently been in our malware top 10 (frequently positioned in the top 5) for one year solid now. While we have highlighted Virut in our reports, I decided to have another look at this family. Nicolas Brulez, by the way, has two excellent write-ups on Virut which are worth a read (<a id="gaad" title="part 1" href="http://securitylabs.websense.com/content/Blogs/2595.aspx">part 1</a> and <a id="d9p7" title="part 2" href="http://securitylabs.websense.com/content/Blogs/3300.aspx">part 2</a>).</p>
<p>The main characteristic of W32/Virut.A is that it is a parasitic file infector, which is fairly uncommon when compared to the mass amounts of trojans/droppers and worms we see today. Virut also contains a bot component, connecting to a single IRC server domain to await further commands. Due to the high volume we have seen with Virut, the authors must be enjoying quite a bit of control through this component. File infectors will typically infect many executables on a system, as well as others connected (via shares, USB drives). So, cleansing can be a bit of a process since it is not just registry entries and one or two loaded components on boot; every single infected file must be cleaned &#8211; and this certainly helps Virut be persistent as we have seen. Persistent, but why so prevalent? One of the first samples I looked at for W32/Virut.A exhibited some familiar behavior when executed in a safe environment. Yes, it attempted to establish a connection to the hardcoded IRC server as expected; however, it also spawned multiple SMTP sessions. What&#8217;s this, a mass mailing component with Virut.A? Could that explain how Virut has been spreading so vigorously? Indeed it would help&#8230; The question though, is not what component it is, but <em>who&#8217;s</em> component it is. After further analyzing this particular sample, the answer became clear.</p>
<p><img class="alignnone size-full wp-image-206" title="netsky" src="http://blog.fortinet.com/wp-content/uploads/2009/03/netsky.png" alt="MyDoom's Message to Netsky (Circa 2004)" /></p>
<p>The sample was UPX packed, very standard stuff &#8211; after unpacking, some familiar strings popped up from the past: &#8220;to netsky&#8217;s creator(s): imho, skynet is a decentralized &#8230;&#8221;. Yes! This looked like a MyDoom sample. Internally, we have the ability to scan samples through all possible signatures / detection names. While we primarily detected this one as W32/Virut.A, we also detect it as W32/MyDoom.H@mm. Indeed, this was a hybrid of sorts. W32/MyDoom.H opens up a backdoor on TCP port 1080 to await commands, while W32/Virut.A establishes an IRC connection on TCP port 65520 to report to its herder. Both of these conditions occurred. Moreover, the MyDoom malcode was sending copies of this hybrid through its SMTP engine. In a nutshell, here is what happened:</p>
<ol>
<li>MyDoom infects a system</li>
<li>Virut infects the same system</li>
<li>Virut (the parasitic file infector) infects the UPX packed MyDoom sample</li>
<li>When the hybrid virus (MyVirut?) executes, it uses the modified entry point (Virut&#8217;s addition in a .rsrc segment)</li>
<li>Virut executes its infection routine, and passes back control to the UPX decompressing segment (original entry point)</li>
<li>UPX decompressing executes as normal, unpacking MyDoom and executing the original virus</li>
<li>MyDoom drops itself (really the hybrid), makes multitudes of copies (various filenames, extensions) of what it *thinks* is itself (again, the double infected hybrid) and starts sending these off to victims using its own SMTP engine; propagating both MyDoom and Virut to the victim.</li>
<li>On system startup, both Virut and MyDoom are executed independently {and transparently in this case}</li>
</ol>
<p>Virut has effectively (and possibly inadvertently) hitched a free ride on another worm &#8212; this is quite interesting indeed.</p>
]]></content:encoded>
			<wfw:commentRss>http://blog.fortinet.com/virut-infecting-worms-hitching-a-ride/feed/</wfw:commentRss>
		<slash:comments>7</slash:comments>
		</item>
	</channel>
</rss>

