Cloud Antivirus > Activity Monitor > Gaobot.OXI

Virusinformationen - Details zuGaobot.OXI

Alle details, beschreibungen und Wirkungen von  Gaobot.OXI

CLOUD ANTIVIRUS - Share/Bookmark
Trivialnamen: Gaobot.OXI
Technische Namen:
Alias:
   
Typ: WORM
Größe: 174325 Bytes
   

ERKENNUNGEN

Anzahl der Sichtungen:
Datum der ersten Sichtung: November 18, 2010 at 08:46 AM
Land der ersten Sichtung:
Land der letzten Sichtung:
   

Brief Description

Gaobot.OXI is a worm that spreads by copying itself, without infecting other files.

 

It captures certain information entered or saved by the user, with the corresponding threat to privacy: passwords saved by certain Windows services; keystrokes, in order to obtain information for accessing online banking services, passwords and other confidential information.

 

It affects productivity, preventing tasks from being carried out:

  • In the affected computer: it converts the computer into a platform for taking malicious action surreptitiously: spam sending, launch of Denial of Service attacks, malware distribution, etc.
  • In the local network: it generates a large amount of network activity and consumes bandwidth.

 

It reduces the security level of the computer: it notifies the attacker that the computer has been compromised and is ready to be used maliciously; it awaits remote-control orders received through IRC; it changes system permissions, decreasing the security level.

 

It uses stealth techniques to avoid being detected by the user:

  • It deletes the original file from which it was run once it is installed on the computer.

 

It uses several methods in order to avoid detection by antivirus companies:

  • It terminates its own execution if it detects that it is being executed in a virtual machine environment, such as VMWare or VirtualPC.
  • It terminates its own execution if it detects that a memory dump program is running, such as Procdump.
  • It terminates its own execution if it detects that a debugging program is active.

 

Gaobot.OXI uses the following propagation or distribution methods:

  • Exploiting vulnerabilities with the intervention of the user: exploiting vulnerabilities in file formats or applications. To exploit them successfully it needs the intervention of the user: opening files, viewing malicious web pages, reading emails, etc.
  • Via Internet, exploiting remote vulnerabilities: attacking random IP addresses, in which it tries to insert a copy of itself by exploiting one or more vulnerabilities.
  • IRC: It sends a copy of itself to all users connected to the channel to which the infected user is connected.
  • Computer networks (mapped drives): it creates copies of itself in mapped drives.
  • Computer networks (shared resources): it creates copies of itself in shared network resources to which it has access.
  • It is dropped or downloaded to the computer by other malware specimens, for example: MultiDropper.RDJ.

 

EFFECTS

The main objective of Gaobot.OXI is to spread and affect other computers.

 

It avoids being detected by the user by using the following techniques:
  • It deletes the original file from which it was run once it is installed on the computer.

 

It uses the following techniques to impede detection by antivirus companies:
  • It terminates its own execution if it detects that it is being executed in a virtual machine environment, such as VMWare or VirtualPC.
  • It terminates its own execution if it detects that a memory dump program is running, such as Procdump.
  • It terminates its own execution if it detects that a debugging program is active.

 

It captures certain information entered or saved by the user, with the corresponding threat to privacy:

  • Passwords saved by certain Windows services.
  • Keystrokes, in order to obtain information for accessing online banking services, passwords and other confidential information.

 

It affects productivity, preventing tasks from being carried out:

  • It turns the computer into a platform for malicious action against remote computers surreptitiously.

 

It causes a loss of productivity in the local network to which the compromised computer belongs:

  • It generates a large amount of network activity and consumes bandwidth.

 

It reduces the security level of the computer:

  • It notifies the attacker that the computer has been compromised and is ready to be used maliciously.
  • It changes system permissions, decreasing the security level.

 

http://www.pandasecurity.com/homeusers/security-info/about-malware/encyclopedia/overview.aspx?idvirus=Weitere Informationen zu Gaobot.OXI finden Sie in der Enzyklopädie