Worm.Brontok
Worm.Brontok Description
Worm.Brontok is a mass mailing worm that is spread through an email attachment. The subject of the infected email will be either “Fotoku yg Paling Cantik” or “My Best Photo”. The Worm.Brontok’s email text reads:
From: “angelina_ph@[recipient’s domain]” or “jennifer_sh@[recipient’s domain]”
Subject: “Fotoku yg Paling Cantik” or “My Best Photo”
Message text:
“Hi,
Aku lg iseng aja pengen kirim foto ke kamu.
Jangan lupain aku ya !.
Thanks”
or
“Hi,
I want to share my photo with you.
Wishing you all the best.
Regards,”
Attachment name: Photo.zip
Once the Worm.Brontok file is executed it replicates itself to Windows system folder and to other folders such as:
csrss.exe
inetinfo.exe
lsass.exe
services.exe
smss.exe
norBtok.exe
cvt.exe
IDTemplate.exe
3D Animation.scr
A.kotnorB.com
Empty.pif
KANGEN.EXE
winlogon.exe
The Worm.Brontok also changes the registry run section so it may load automatically on subsequent startups. Below are the registry modifications:
HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Run Tok-Cirrhatus = “%UserProfile%\Application Data\smss.exe”
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run
Bron-Spizaetus = “%Windows%\INF\norBtok.exe”
Worm.Brontok can disable the user’s system registry tools and the command line (cmd.exe) in order to avoid detection and to make manual removal difficult. Worm.Brontok is a malicious worm and should be removed from the users PC immediately.
Type: Worms
How Can You Detect Worm.Brontok?
Worm.Brontok Technical Report
As new Worm.Brontok details are reported by our customers and findings from our Threat Research Center, we will update this section.
The following Worm.Brontok files with its MD5s were created in the system:
| File Name | File Size | MD5 |
|---|
| winlogon.exe | 111616 | a575dd2441173753bb7a0c058d8b1aef |
| winlogon.exe | 42687 | 483fcf432217d71544246aa760d98cdc |
| smss.exe | 56832 | c5a6d5f57999593952dce98acc8ba34f |
| csrss.exe | 811008 | c5827bf72ba1c9a68be2924fe0bf99ed |
| csrss.exe | 1107843 | 4dcb3ad18353392d6f1fd3b56bd00fcd |
| csrss.exe | 48030 | b2af05ff785d63ea99bdef2a90643565 |
| 4BCEE.com | 27508 | 3485c0b837e85d0220efe4ca8ae67b71 |
| services.exe | 763904 | 3155927fae597906fbfab217b45a2d4c |
| csrss.exe | 31232 | 9488b369de58ae7abb9d2a37c8d67745 |
| SERVICES.exe | 24576 | d32e51ada4d466ae9ff7fbf70962913c |
Worm.Brontok has typically the following processes in memory:
- EKSPLORASI.EXE
- BRONSTAB.EXE
Worm.Brontok creates the following registry entries:
- HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Run\Tok-cirrhatus
Important Article Disclaimer

English 
Deutsch
Español
Français
Portuguese
Worm.Brontok 











