Similar Searches

  • Password Survey Results (March 26, 2010)

    I am convinced that the readers of the Symantec Security Response blog are the smartest around! The results from our Password Survey prove it. Actually, the number of responses itself proves it to me. At best, I thought 20 or

  • Word usage in spam (March 16, 2010)

    Posted on behalf of Mathew Nisbet, Malware Data Analyst, Symantec Hosted ServicesThere is a huge variety in the types of spam that are sent all over the internet, but there are patterns to be found in the chaos.   One

  • PDF container threat (August 9, 2010)

    Last year I wrote a blog entry entitled The Fight Against Malicious PDFs Using the ASCII85Decode Filter, which is about a threat that uses the ASCII85Decode filter to hide itself. Since that time, some Adobe Reader vulnerabilities have been

  • Username: “administrator,” Password: “password” – yer pwned (December 3, 2009)

    For years there has been a collective wisdom about creating strong passwords. Briefly:-- don’t use a word found in the dictionary-- don't use a word found in the dictionary with a "1"or other number after it--

  • Make Your Password Secure (November 25, 2009)

    No matter how sophisticated security gets, we still need to handle the basics properly. One of the most basic tasks is to create and use secure passwords. You need them to log onto your computer, reach internal applications, and enter

Related News

  • Password Survey Results (March 26, 2010)

    I am convinced that the readers of the Symantec Security Response blog are the smartest around! The results from our Password Survey prove it. Actually, the number of responses itself proves it to me. At best, I thought 20 or

  • Word usage in spam (March 16, 2010)

    Posted on behalf of Mathew Nisbet, Malware Data Analyst, Symantec Hosted ServicesThere is a huge variety in the types of spam that are sent all over the internet, but there are patterns to be found in the chaos.   One

  • PDF container threat (August 9, 2010)

    Last year I wrote a blog entry entitled The Fight Against Malicious PDFs Using the ASCII85Decode Filter, which is about a threat that uses the ASCII85Decode filter to hide itself. Since that time, some Adobe Reader vulnerabilities have been

  • Username: “administrator,” Password: “password” – yer pwned (December 3, 2009)

    For years there has been a collective wisdom about creating strong passwords. Briefly:-- don’t use a word found in the dictionary-- don't use a word found in the dictionary with a "1"or other number after it--

  • Make Your Password Secure (November 25, 2009)

    No matter how sophisticated security gets, we still need to handle the basics properly. One of the most basic tasks is to create and use secure passwords. You need them to log onto your computer, reach internal applications, and enter

Password-Protected Word Document In W32.Zimuse

While analyzing W32.Zimuse recently I was surprised to find two different passwords used within the threat: one of these decrypts a Word document that contains information about some members of a Slovakian motorbike forum.

In order to spread via USB drives, W32.Zimuse copies the file zipsetup.exe to removable drives. If zipsetup.exe is run with no parameters it shows the following message box:


The zipsetup.exe dialog box

This is not a real WinZip dialog box, just a password box made to look like the WinZip message box. The user has 10 chances to enter the correct password, after which the application will close. Entering "2008_15_12" (without quotes) decrypts a Word document named zoznam.doc:

 
Decrypted Word document

The document is written in Slovakian. Using an online translator, the first two lines translated to:

We found on the internet:
(for the purpose of investigation and monitoring provide administrators these urls : and , these addresses were given to law enforcement authorities)

The document then lists pictures, nicknames and, in some cases, real names and addresses of several motorbike enthusiasts along with the URL of a motorbike forum in which they participate. It is not clear why these pictures are included with the worm. At the time of this writing, the forum mentioned in the Word document

Continue reading...


Write a Comment

Copyright © 2010 The Security Blog. All rights reserved.