Home / malwarePDF  

Small.DAM


First posted on 01 March 2007.
Source: SecurityHome

Aliases :

Small.DAM is also known as Trojan-Downloader.Win32.Small.dam, Trojan.Downloader-647, Trojan.DL.Tibs.Gen!Pac13, Trojan-Downloader:W32/Small.DAM, Storm Worm.

Explanation :

Small.DAM, a variant of Small, is a Trojan that arrives on the system as attachment file to spam emails. Small.DAM loads a malicious service named "wincom32" in the affected machine.

Small.DAM arrives on the system as an attachment file to spam e-mails.

Here's a sample of an e-mail:



It may use any of the following strings as its Subject:


Attachments may be any of the following filenames:


Small.DAM drops the following files upon execution:


It also installs itself as a service with the name "wincom32" by creating the following registry keys:


The kernel mode driver is an advanced payload injector. It carries a user-mode PE executable file and when the driver executes, it changes the services.exe process context and allocates new memory for the payload. It then copies the PE executable from kernel memory to the address space of services.exe and prepares the image for execution. Finally, it queues an Asynchronous Procedure Call (APC) for services.exe to execute the payload in its context.

This is the injected PE executable file trojan downloader in action and affected machines exhibits sending UDP packets with source port 4000 to IP addresses and destination ports taken from the decoded initialization file's "peers" section. The initialization file also maintains a "blacklist" section.

Additional information can be found from our weblog.

Last update 01 March 2007

 

TOP

Malware :

Family: