Fandom

Malware Wiki

San

1,345pages on
this wiki
Add New Page
Comments5 Share

Email-Worm.VBS.San or San is a email worm that was made with Visual Basic Script (VBS).

The San worm is sent in an infected message sent with Outlook Express.

Details

When the infected message is viewed, by opening it or via preview pane, it first drops "loveday14-a.hta" to the Windows Startup directory in both Spanish and English versions of Windows.

When the system is restarted, "loveday14-a.hta" will be executed. Also the worm creates an infected "index.html" file to the Windows System directory.

Next it uses registry to replace the default signature of Outlook Express 5 with the "index.html" created above.

On that way every time when an infected user send an email message, the worm will embed its html code to this message.

Next the worm replaces the user's Internet Explorer start page point to a web page, that contains another worm VBS/Valentine.A@mm. These two worms download each other.

If the system date is 8th, 14th, 23rd or 29th on each month, then VBS/Sun.A will destroy the infected system. It will delete all directories and their contents from the drive "C:".

In the place of the original directories, the worm creates a folder with the same name adding a string "happysanvalentin". On that way a directory with a name "My Documents" will become "My Documentshappysavalentin".

This worm has been available on a public web page in the Internet and it has been posted to several Usenet newsgroups. Even after the infected web page has been removed from the Internet, the worm is able to spread via Outlook Express.

Videos

Sources

F-Secure, Email-Worm.VBS.San

Ad blocker interference detected!


Wikia is a free-to-use site that makes money from advertising. We have a modified experience for viewers using ad blockers

Wikia is not accessible if you’ve made further modifications. Remove the custom ad blocker rule(s) and the page will load as expected.