Ads

SymbOS.Lasco.A PDF Print E-mail
Tuesday, 11 January 2005
SymbOS.Lasco.A is a Symbian Series 60 Bluetooth worm that also infects .sis archives. The worm is based on SymbOS.Cabir, except it also searches for .SIS files on the device and adds itself to them. SymbOS.Lasco.A is transmitted through Bluetooth as a .sis file.

When the worm arrives on a target device the following may happen:


The device displays a message similar to the following, asking the user to accept a message from a particular device:

Receive message via Bluetooth from [device name]?


The user will be notified that they have received a new message.


The user will be prompted with a message similar to the following:

Application is untrusted and may have problems. Install only if you trust provider.


If the user chooses Yes, the user will be prompted to install the worm.

Install Velasco?


The worm creates the following files on the phone:


SYSTEMAPPSVELASCOVELASCO.APP
SYSTEMAPPSVELASCOVELASCO.RSC
SYSTEMAPPSVELASCOMARCOS.MDL
C:SYSTEMSYMBIANSECUREDATAVELASCOVELASCO.APP
C:SYSTEMSYMBIANSECUREDATAVELASCOVELASCO.RSC
C:SYSTEMSYMBIANSECUREDATAVELASCOVELASCO.SIS
C:SYSTEMRECOGSMARCOS.MDL
C:SYSTEMINSTALLSVELASCO.SIS


The worm attempts to send itself to other Bluetooth-enabled devices it finds, regardless of the type of device.


The worm searches the device for all .sis files and appends itself to those files. When an infected .SIS file is installed, the worm will automatically install along with the original application.


The worm executes every time the device is turned on.
 
< Prev   Next >