Worm_sohanad.dr


 
Thread Tools Search this Thread
Special Forums Cybersecurity Malware Advisories (RSS) Worm_sohanad.dr
# 1  
Old 08-11-2008
Worm_sohanad.dr

To get a one-glance comprehensive view of the behavior of this malware, refer to the Behavior Diagram shown below.


ImageMalware Overview

This worm arrives as attachment to email messages spammed by another malware or a malicious user. It may be dropped by other malware.

It may be downloaded from a remote site. This worm drops copies of itself. Note that the drop paths are harcoded within this worm's code. However, this dropping routine fails to execute on systems running Windows 2000 and Windows NT.

This worm creates registry entries to enable its automatic execution at every system startup.

This worm sends email using MAPI (Messaging Application Programming Interface) via MS Outlook. It sends email to all addresses listed in the MS Outlook address book with copies of itself as attachments.

It may also connect to Web sites to download an updated copy of itself. However, the said Web sites are inaccessible as of this writing.



More...
Login or Register to Ask a Question

Previous Thread | Next Thread
Login or Register to Ask a Question
GENWORM(1)						      General Commands Manual							GENWORM(1)

NAME
genworm - generate a RADIANCE description of a functional worm SYNOPSIS
genworm mat name 'x(t)' 'y(t)' 'z(t)' 'r(t)' nseg [ -e expr ][ -f file ] DESCRIPTION
Genworm produces a RADIANCE scene description of a worm defined by the parametric equations x(t), y(t), z(t), and r(t) (the radius). T will vary from 0 to 1 in steps of 1/nseg. The surface will be composed of nseg cones or cylinders and nseg+1 spheres. The expressions are of the same type used in RADIANCE function files. Auxiliary expressions and/or files may be specified in any number of -e and -f options. EXAMPLE
To generate a banana: genworm yellow banana '0' '5*sin(t)' '5*cos(t)' '.4-(.5-t)*(.5-t)' 20 AUTHOR
Greg Ward BUGS
Since the worm is constructed of intersecting surfaces, only opaque materials should be used with this object. Also, a worm cannot double back inside itself without making a mess. SEE ALSO
genrbox(1), genrev(1), gensurf(1), icalc(1), rpict(1), rvu(1), xform(1) RADIANCE
11/15/93 GENWORM(1)