Showing posts with label W32.Narilam. Show all posts
Showing posts with label W32.Narilam. Show all posts

Monday, November 26, 2012

Symantec experts found SQL-virus aimed at Iran


Found in the 'wild' virus got internal designation W32.Narilam


The company announced the discovery of a new virus that targets the Iranian computer systems and databases within these systems.

Messages about the virus first appeared on November 15, and the company Symantec said its low hazard. More interesting were the data on the location of virus detection Narilam - most copies were found in Iran, and other isolated cases of infection reported in the UK, in the continental U.S. and Alaska.

It is noteworthy that the new virus Narilam has many similarities with the infamous virus Stuxnet, which has led to large-scale man-made disaster in the factory for uranium enrichment in Iran. Like Stuxnet, which disrupted enrichment centrifuges by implementing a control program, the virus Narilam is a worm that spreads through removable drives and network shares.

When the virus enters Narilam on the victim, he first searches the database Microsoft SQL. The virus searches in these databases for certain keywords, including, in Persian (Farsi), the official language of Iran. Elements found virus replaces a randomly generated value or destroy certain data fields. In particular, the virus searches and replaces words such as 'hesabjari' (current account), 'pasandaz' (account balance) and 'asnad' (debts).