PandaLabs Warns Computer Users of Sality.AO Virus

Virus combines dangerous infection techniques of old viruses with new, financially motivated malware schemes
GLENDALE, Calif., Feb. 18, 2009 " PandaLabs, Panda Security's malware analysis and detection laboratory, discovered a significant increase in the number of computers infected with the Sality.AO virus and is advising computer users to be cautious of this virus. Sality.AO combines the features of traditional viruses (infecting files and damaging as many computers as possible to achieve notoriety for creators) with the objectives of new malware, such as generating financial returns for cyber-criminals. PandaLabs has also discovered new variants of this type of malware.

Sality.AO uses some techniques that have not been seen for years, such as EPO ( and Cavity ( EPO and Cavity are far more complex than automatic malware creation tools and require greater skill and knowledge of malicious code programming. These techniques make it more difficult to detect and disinfect due to the complicated modifications to the original file that are done in order to make the infection. EPO allows part of a legitimate file to be run before infection starts, making it difficult to detect the malware. Cavity involves inserting the virus code in blank spaces within the legitimate file's code, making it both more difficult to locate and to disinfect.

In addition to these techniques that have been seen in early malware, Sality.AO includes a series of features associated with new malware schemes. The first feature is its ability to connect to IRC channels to receive remote commands, potentially turning the infected computer into a zombie. Such zombie computers can be used for sending spam, distributing malware, denial of service attacks, and more.

The second new scheme associated with Sality.AO is that infections are not just restricted to files, as was the case with old viruses, but also look to propagate across the Internet. To this end, it uses an iFrame to infect PHP, ASP and .HTML files on the computer. The result is that when any of these files are run, the browser is redirected, without the user's knowledge, to a malicious page that launches an exploit against a computer in order to download more malware. What's more, if any of the infected files are posted on a Web page, any user downloading the files or visiting the Web pages will become infected. The file downloaded through this technique is what PandaLabs refers to as hybrid malware, as it combines the functions of Trojans and viruses. The Trojan, in addition, has features for downloading other strains of malware to the computer. The URLs used by this downloader were still not operative at the time of the PandaLabs analysis, but they could become active as the number of infected computers increases.

"As we forecasted in our annual report, the distribution of classic malicious code such as viruses will be a major trend in 2009," said Luis Corrons, Technical Director of PandaLabs. "The use of increasingly sophisticated detection technologies like Panda Security's Collective Intelligence, capable of detecting even low-level attacks and the newest malware techniques, will make cyber-crooks turn to old codes that they are adapting to meet new needs. Viruses won't be designed simply to spread or damage computers, as they were 10 years ago, but will be manufactured to hide Trojans or turn computers into zombies."

