Virus: TR/Spy.ZBot.dkx Date discovered: 25/07/2008 Type: Trojan Subtype: Spy In the wild: Yes Reported Infections: Low to medium Distribution Potential: Low Damage Potential: Medium Static file: Yes File size: 56.320 Bytes MD5 checksum: dd2bddde963c8f6d5a9f0C0De6d4457b IVDF version: 7.00.05.168 - Friday, July 25, 2008
General Method of propagation: • No own spreading routine Aliases: • Symantec: Backdoor.Paproxy • Mcafee: Spy-Agent.bw trojan • Kaspersky: Trojan-Spy.Win32.Zbot.dkx • F-Secure: Trojan-Spy.Win32.Zbot.dkx • Sophos: Mal/Spy-A • VirusBuster: TrojanSpy.Zbot.RC • Eset: Win32/Spy.Agent.NHU • Bitdefender: Trojan.Spy.Wsnpoem.EK Platforms / OS: • Windows 95 • Windows 98 • Windows 98 SE • Windows NT • Windows ME • Windows 2000 • Windows XP • Windows 2003 Side effects: • Downloads a malicious file • Registry modification • Steals information • Third party control Files It copies itself to the following location: • %SYSDIR% \ntos.exe The following files are created: – Temporary files that might be deleted afterwards: • %SYSDIR% \wnspoem\video.dll • %SYSDIR% \wnspoem\audio.dll It tries to download a file: – The location is the following: • http://alparslanovayurt.com/**********ldr.exe It is saved on the local hard drive under: %TEMPDIR% \4.tmp Furthermore this file gets executed after it was fully downloaded. Further investigation pointed out that this file is malware, too. Detected as: TR/Dldr.Agent.xft Registry The following registry key is changed: – [HKLM\software\microsoft\windows nt\currentversion\winlogon] Old value: • "userinit"="%SYSDIR% \userinit.exe," New value: • "userinit"="%SYSDIR% \userinit.exe,%SYSDIR% \ntos.exe," Email It doesn't have its own spreading routine but it was spammed out via email. The characteristics are described in the following: From: The sender address is spoofed. Subject: The following: • Parcel requires declaration Body: The body of the email is the following: • Good day, We have received a parcel for you, sent from France on July 9. Please fill out the customs declaration attached to this message and send it to us by mail or fax. The address and the fax number are at the bottom of the declaration form. Kind regards, Lucinda Addison Your Customs Service Attachment: The filename of the attachment is: • Bill_Tax.zip The attachment is an archive containing a copy of the malware itself. Backdoor The following port is opened: – svchost.exe on a random TCP port Contact server: The following: • http://baltikaredison.ru/**********alaska.bin As a result it may send information and remote control could be provided. Injection – It injects the following file into a process: %SYSDIR% \ntos.exe Process name: • winlogon.exe File details Runtime packer: In order to aggravate detection and reduce size of the file it is packed with a runtime packer.
Description inserted by Thomas Wegele on Friday, July 25, 2008 Description updated by Thomas Wegele on Friday, July 25, 2008
Back
.
.
.
.