Sophos

Symb/Cabir-I

Category
Type
What to do
Prevalence low high

Summary

 
How it spreads
  • Peer-to-peer
Included in our products from February 2005 (3.90)
Protection available since 28 December 2004 21:00:40 (GMT)
Detected by All Sophos products

More Information

Symb/Cabir-I is a worm written specifically for Nokia Series 60 mobile phones running the Symbian operating system.

The worm spreads as a Symbian SIS package named velasco.sis. The package contains the following components extracted to the .\System\Apps, .\System\SYMBIANSECUREDATA\VELASCO and .\System\Recogs:

./system/apps/velasco/marcos.mdl
./system/apps/velasco/velasco.rsc
./system/apps/velasco/velasco.app
./system/SYMBIANSECUREDATA/VELASCO/velasco.rsc
./system/SYMBIANSECUREDATA/VELASCO/velasco.app
./system/SYMBIANSECUREDATA/VELASCO/velasco.sis
./system/Recogs/marcos.mdl

Marcos.mdl is a DLL that uses EZBoot mechanism to attempt to launch Symb/Cabir-I appliction file velasco.app when the device is powered on.

Once running Symb/Cabir-I attempts to send itself to bluetooth-enabled devices found in the proximity of the infected mobile phone. The user of the receiving device has to accept the file and then manually install it in order to infect the phone. Symbian operating system displays several security warnings during the installation of the infected file.

RSS|Atom
Get reports about the latest virus and spyware threats delivered to your computer