Home > Support > Global Security Advisor 

Virus Detail

Win32.Sasser.D

Date Published:
3 May 2004

Last Updated:
13 Jul 2004

Threat Assessment

Overall Risk:   Low
Wild:  Low
Destructiveness:  Medium
Pervasiveness:  High

Characteristics

Type : Worm

Category : Win32

Also known as:  Win32.Sasser!FTP, Bat/Sasser.A.Componenet.Trojan, W32/Sasser.D (F-Secure), W32.Sasser.D (Symantec), WORM_SASSER.D (Trend), Win32/Sasser.D.Worm, W32/Sasser.worm.d (McAFee), Worm.Win32.Sasser.c (Kaspersky)

Immediate Protection Info

 
SignatureProductRemoval Instructions
23.65.07
eTrust Antivirus v7/8* (InoculateIT Engine)
11.x/8315
eTrust Antivirus v7/8* (Vet Engine)
6.1x/5433
eTrust EZ Antivirus 6.1x
6.2x/8315
eTrust EZ Antivirus 6.2x
47.07
Inoculan/InoculateIT 4.x
10.5x/5433
Vet Anti-Virus 10.5x
10.6x/8315
Vet Anti-Virus 10.6x
 
 
 

Description

Win32.Sasser.D is a worm that spreads by exploiting a vulnerability in the LSASS service on Windows 2000, XP and 2003 server. It is a 16,384-byte executable, packed with PECompact.

Back to top

Method of Infection

When executed, Sasser.D copies itself to:

%Windows%\skynetave.exe


and modifies the registry to ensure that this copy is executed at each Windows start:


HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Run\skynetave.exe = "%Windows%\skynetave.exe"


Note: '%Windows%' is a variable location. The worm determines the location of the current Windows folder by querying the operating system. The default installation location for the Windows directory for Windows 2000 and NT is C:\Winnt; for 95,98 and ME is C:\Windows; and for XP is C:\Windows.


The worm also creates mutexes called "Jobaka3" and "SkynetSasserVersionWithPingFast".


Back to top

Method of Distribution

Sasser.D scans random IP addresses, attempting connections on TCP port 445. If it connects successfully, it then attempts the exploit the "Microsoft Windows LSASS buffer overflow vulnerability". For more information on this vulnerability, please see:


http://www3.ca.com/threatinfo/vulninfo/vuln.aspx?ID=27886


The Microsoft security bulletin for this vulnerability is available here:


http://www.microsoft.com/technet/security/Bulletin/MS04-011.mspx


Microsoft have also published some additional instructions for dealing with this threat here: http://www.microsoft.com/security/incident/sasser.asp


The worm uses this to open a remote shell, listening on port 9995. It connects to this port and uses the shell to create an ftp script called "cmd.ftp" on the remote machine. The file will be created in the System directory. Sasser.D runs a basic ftp server on each infected machine, on port 5554. It runs ftp.exe on the target system, using the ftp script to download the worm executable. The executable is saved in the System directory will the file name "<random number>_up.exe". For example:


C:\WINDOWS\system32\12756_up.exe
C:\WINDOWS\system32\10831_up.exe


As a side effect of infection, the LSASS service may crash, displaying a message like the following:



The worm creates 128 threads to scan for vulnerable systems, and logs IP addresses it has infected to the file c:\win2.log.


For each of these threads, there is a 50% chance it will generate completely random IP addresses. There is a 25% chance it will generate addresses with the first octect the same as the host, and a 25% chance it will use the first two octets from the host address. The worm is capable of scanning more than 200 addresses per second.


Analysis by Hamish O'Dea


Back to top

Recommendations

Cleaning Utility Available: To download clnsasser.zip -  a utility that cleans a local machine affected by Win32.Sasser and its variants, please click here.


This utility may be especially useful for those who either do not use CA Antivirus solutions, or who may be using products based on older technology that does not support system cleaning. Please view the Removal Instructions for your CA Antivirus Solution (below) to ascertain whether you require the cleaning utility.


Warning: Before running ClnSasser.com, please ensure that you carefully review the ReadMe.txt instruction file that accompanies this utility. 


Back to top

CA Global Security Advisor

Current threat condition: Low
Low
Find Threats
Viruses Spyware
Vulnerabilities All

Security Resources

 
 
Page Tools