logo

Analysis of a UDP worm

ID: 1402a782-3368-5002-a967-68b9f9abf216

STIX ID: report--1402a782-3368-5002-a967-68b9f9abf216

Feed Name: SensePost Blog

Threat Score
65/100

Date Published: 2010-10-25

Date Updated: 2026-04-29

...
...

This report analyzes a malware sample that achieved persistence by copying itself to the user's AppData and adding a Winlogon registry entry, injected into explorer.exe, and communicated with multiple hardcoded C2 servers over UDP (port 14000) using an obfuscated protocol. The sample used GDI-based timing/evasion techniques to bypass heuristic sandboxing, performed a second-stage decryption and decompression of commands (including changing browser homepage), and contains functionality for USB autorun propagation, remote download-and-execute, and Firefox cookie theft.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.