Trojan attacks Microsoft's emergency patch vuln
Transforms self into worm
A day after Microsoft released an emergency patch for a critical flaw that could allow self-replicating attacks, researchers have identified a nasty trojan that attempts to exploit the vulnerability.
Variants of the data-stealing trojan known by names including Gimmiv.A and Spy-Agent.da have morphed over the past few weeks to exploit a major weakness in virtually all versions of the Windows operating system. If successful, the exploit could transform the malware into a virulent worm that allows a single infected machine to contaminate any other vulnerable machine over a local network without requiring any interaction on the part of the end users.
At the moment, the part of the trojan that exploits the weakness in the Windows server service isn't especially reliable, researchers said. It generally succeeds only when code custom-built for a specific version and language of the OS encounters its intended target. But the limited success has prompted security experts to take seriously Microsoft's warning that the vulnerability is wormable.
"This could actually be one of the bigger monsters of the last couple years," Alex Eckelberry, president of security provider Sunbelt Software, said of the flaw. "Researchers are going to be burning the midnight oil over the next couple days to understand what the real issues are."
According to this post from the ThreatExpert Blog, Gimmiv.A rifles through a victim's Windows machine for system information and passwords and then posts them to a remote server.
More recently, it has begun dropping a basesvc.dll file onto infected machines that searches through a local network for unpatched Windows machines. When it finds one it "then attempts to exploit other machines by sending them a malformed RPC request and relying on a vulnerable Server service," the post said.
Craig Schmugar, a threat researcher at McAfee Avert Labs, said there are enough defenses built into more recent Windows versions to contain the threat. Those include firewalls and features such as data execution protection that have been turned on by default ever since Microsoft rolled out Service Pack 2 of Windows XP. Still, he warns that people who have posted exploit code to the Milw0rm website have hinted they may have additional capabilities. (McAfee's Avert Labs, has also blogged about the trojan here.)
The trojan and Milw0rm release aren't the only pieces of code to exploit the weakness. Within a few hours of Microsoft's patch release on Thursday, Kostya Kortchinsky, a researcher at penetration testing firm Immunity, published code that successfully exploits the flaw on Windows 2000 machines. The exploit code, which is used by security professionals to identify vulnerable machines, only works against more recent Windows versions in very limited circumstances. That means it's not wormable, he said.
Even so, there's reason to believe the trojan could be only the beginning. Jose Nazario, a researcher at security provider Arbor Networks, said it has been in circulation for more than two weeks, giving the attackers an advantage on white hats, who only learned about the vulnerability on Thursday. What's more, the crude nature of Grimmev leads him to think the code portions that attack the vulnerability have been stolen from someplace else and "bolted" on to the trojan.
"If that's true, then there's someone using this as a 0day prior to this patch release and all of this attention," Nazario wrote here.
McAfee's Schmugar agrees, saying malware writers are likely taking baby steps toward their goal of perfecting code that reliably exploits the flaw on a widespread scale.
"Even if there are certain stumbling blocks that don't allow for ideal exploitations that the bad guys would want, they will likely keep plugging away to try and refine those exploits, he said. "People should expect that [attacks] will evolve." ®
The AV companies name them, not the VXers.
Why do the worm writers.......
Always use such names?
I mean, Spy-Agent.da why not Fluffy-Bunnies.da or something less obvious?
Re: what's the surprise
Towards the end of the article there's a suggestion that at least one of these worms was not produced "the day after" MS went public, but somewhat earlier. I think *that's* the surprise, at least for some people. The bad guys appear to have found this hole first.