Computer Crime Research Center

Bugbear eats credit cards, passwords
(By Robert Vamosi)

Bugbear is an Internet worm with a Trojan horse that attempts to steal your passwords and credit card information. Bugbear (w32.bugbear@mm), also known as Tanatos, is about 50KB long and is compressed with the UPX file compressor. Users of Internet Explorer 5.01 or 5.5 who have not patched the Incorrect Mime header flaw are vulnerable to the worm's e-mail attack.

All versions of Windows are vulnerable to this worm's ability to arrive via open file sharing. Users of Macintosh, Linux, and Unix are not at risk. Since Bugbear sends infected e-mail and contains a potentially dangerous Trojan horse, it ranks a 6 on the ZDNet Virus Meter.

How it works Bugbear arrives via e-mail with no distinct characteristics except for an attached file that is always 50,688 bytes long. The subject line and text may be taken from existing e-mail. Bugbear also arrives through network file sharing.

When run, Bugbear adds itself to the System subdirectory of the Windows folder as four random letters followed by .exe (for example, windows\System\zayb.exe). It also changes the Registry in order to run each time Windows is loaded, once again using random letters. Finally, it adds itself to the Startup folder as three random letters followed by .exe (for example, Startup\zay.exe).

The Trojan horse part of this worm first terminates many popular firewall and antivirus programs. The Trojan then launches a keystroke-logging program whose filename is a variable number of random letters followed by .dll (for example, avbxcydz.dll). Keystroke-logging programs memorize the keystrokes typed when filling out login information (passwords) or filling out shopping forms online (credit card information). Files saved by these programs can later be accessed remotely by malicious users. The Trojan component of this worm opens port 36794.

Prevention Users of Internet Explorer 6 should be safe from the e-mail portion of this worm. Users of IE 5.01 and 5.5 who have not installed the Infected Mime header patch found in MS01-020 should do so. If you do not need to share files on a network, you should also turn off file sharing within Windows.


Home | What's New | Articles | Links
Library | Staff | Contact Us

Copyright Computer Crime Research Center 2001, 2002 All Rights Reserved.
Contact the CCRC Office at 380-612-735-907

Rambler's Top100 Rambler's Top100