Feeds

New table-munching worm ravages Iranian biz databases

Iranian CERT: It's really no biggie

Choosing a cloud hosting partner with confidence

A new strain of malware is thrashing corporate databases in the Middle East, claiming the vast majority of its victims in Iran.

Narilam is "causing chaos" by targeting and modifying corporate databases, according to Symantec. The worm spreads through removable drives and network shares.

Network worms are relatively commonplace, but Narilam packs an unusual punch, functionality to update a Microsoft SQL database if it is accessible by OLEDB (Object Linking and Embedding, Database). The worm specifically targets SQL databases with three distinct names: alim, maliran, and shahd.

However Iran's Computer emergency Response Tema said in a statement that the Narilam malware was two years old, "not a major threat" and only corrupted the databases of an unnamed Iranian accountancy software package:

The malware called "Narilam" by Symantec was an old malware, previously detected and reported online in 2010 by some other names. This malware has no sign of a major threat, nor a sophisticated piece of computer malware. The sample is not wide spread and is only able to corrupt the database of some of the products by an Iranian software company, those products are accounting software for small businesses. The simple nature of the malware looks more like a try to harm the software company reputation among their customers.

According to Symantec, some of the object/table names that can be accessed by the threat include Hesabjari ("current account" in Arabic/Persian), Asnad (“financial bond” in Arabic), R_DetailFactoreForosh ("forosh" means "sale" in Persian), pasandaz ("savings" in Persian), End_Hesab ("hesab" means "account" in Persian) and Vamghest (“instalment loans” in Persian) as well as tables such as "holiday".

The threat replaces certain items in the database with random values. Some of the items that are modified by the threat include Asnad.SanadNo ("sanad" means "document" in Persian), Asnad.LastNo, Asnad.FirstNo, and Pasandaz.Code (“pasandaz” means “savings” in Persian), refcheck.amount and buyername.Buyername.

Narilam also deletes tables including ones with names including A_Sellers, person and Kalamast.

The malware lacks any functionality to steal information from infected systems and appears to be programmed specifically to damage the data held within the targeted database, Symantec concludes.

"Given the types of objects that the threat searches for, the targeted databases seem to be related to ordering, accounting, or customer management systems belonging to corporations," it adds.

Without well-managed backups, affected databases will be very difficult to restore. The malware is likely to cause significant disruption even if backups are available, according to Symantec. ®

Internet Security Threat Report 2014

More from The Register

next story
FYI: OS X Yosemite's Spotlight tells Apple EVERYTHING you're looking for
It's on by default – didn't you read the small print?
Russian hackers exploit 'Sandworm' bug 'to spy on NATO, EU PCs'
Fix imminent from Microsoft for Vista, Server 2008, other stuff
Edward who? GCHQ boss dodges Snowden topic during last speech
UK spies would rather 'walk' than do 'mass surveillance'
Microsoft pulls another dodgy patch
Redmond makes a hash of hashing add-on
'LulzSec leader Aush0k' found to be naughty boy not worthy of jail
15 months home detention leaves egg on feds' faces as they grab for more power
China is ALREADY spying on Apple iCloud users, claims watchdog
Attack harvests users' info at iPhone 6 launch
Carders punch holes through Staples
Investigation launched into East Coast stores
prev story

Whitepapers

Forging a new future with identity relationship management
Learn about ForgeRock's next generation IRM platform and how it is designed to empower CEOS's and enterprises to engage with consumers.
Why and how to choose the right cloud vendor
The benefits of cloud-based storage in your processes. Eliminate onsite, disk-based backup and archiving in favor of cloud-based data protection.
Three 1TB solid state scorchers up for grabs
Big SSDs can be expensive but think big and think free because you could be the lucky winner of one of three 1TB Samsung SSD 840 EVO drives that we’re giving away worth over £300 apiece.
Reg Reader Research: SaaS based Email and Office Productivity Tools
Read this Reg reader report which provides advice and guidance for SMBs towards the use of SaaS based email and Office productivity tools.
Security for virtualized datacentres
Legacy security solutions are inefficient due to the architectural differences between physical and virtual environments.