Virus: TR/Spy.ZBot.DPE Date discovered: 05/08/2008 Type: Trojan Subtype: Spy In the wild: Yes Reported Infections: Low to medium Distribution Potential: Low Damage Potential: Medium Static file: Yes File size: 59.904 Bytes MD5 checksum: 606ab42e4c906f933bc9c5ab62b798d9 IVDF version: 7.00.05.213 - Tuesday, August 5, 2008
General Method of propagation: • No own spreading routine Aliases: • F-Secure: Trojan-PSW:W32/Zbot.FO • Sophos: Troj/Agent-HJG • Eset: Win32/Spy.Agent.NES trojan • Bitdefender: Trojan.Agent.AJLI Platforms / OS: • Windows 95 • Windows 98 • Windows 98 SE • Windows NT • Windows ME • Windows 2000 • Windows XP • Windows 2003 Side effects: • Downloads a malicious file • Registry modification • Steals information • Third party control Files It copies itself to the following location: • %SYSDIR% \ntos.exe The following files are created: – Temporary files that might be deleted afterwards: • %SYSDIR% \wnspoem\video.dll • %SYSDIR% \wnspoem\audio.dll It tries to download a file: – The location is the following: • http://dr-mahmoud.com/**********.exe It is saved on the local hard drive under: %TEMPDIR% \1.tmp Furthermore this file gets executed after it was fully downloaded. Further investigation pointed out that this file is malware, too. Detected as: TR/Dldr.Small.zou Registry The following registry key is changed: – [HKLM\software\microsoft\windows nt\currentversion\winlogon] Old value: • "userinit"="%SYSDIR% \userinit.exe," New value: • "userinit"="%SYSDIR% \userinit.exe,%SYSDIR% \ntos.exe," Email It doesn't have its own spreading routine but it was spammed out via email. The characteristics are described in the following: From: The sender address is spoofed. Subject: The following: • Rechnung N%number% The body of the email is one of the following: • Sehr geehre Damen und Herren, Ihr Auftrag Nr. SP7848895 wurde erfullt. Ein Betrag von 6536.02 EURO wurde abgebucht und wird in Ihrem Bankauszug als “Paypalabbuchung ” angezeigt. Sie finden die Details zu der Rechnung im Anhang PayPal (Europe) S.158; r.l. & Cie, S.C.A. 50-40 Boulevard Royal L-7672 Luxembourg Hochachtungsvoll, Vertretungsberechtigter: Armand Kruse Handelsregisternummer: R.C.S. B 285 380 • Sehr geehrte Kunden, Ihr Auftrag Nr. SP8742024 wurde erfullt. Ein Betrag von 6127.53 EURO wurde abgebucht und wird in Ihrem Bankauszug als "Paypalabbuchung " angezeigt. Sie finden die Details zu der Rechnung im Anhang PayPal (Europe) S.392; r.l. & Cie, S.C.A. 63-88 Boulevard Royal L-2082 Luxembourg Mit freundlichen Grussen, Vertretungsberechtigter: Joanna Muller Handelsregisternummer: R.C.S. B 922 819 Attachment: The filename of the attachment is: • REC719271.zip The attachment is an archive containing a copy of the malware itself. The email looks like the following: Backdoor The following port is opened: – svchost.exe on a random TCP port Contact server: The following: • http://ahleinaks.ru/**********/millionertest.bin As a result it may send information and remote control could be provided. Injection – It injects the following file into a process: %SYSDIR% \ntos.exe Process name: • winlogon.exe File details Programming language: The malware program was written in MS Visual C++. Runtime packer: In order to aggravate detection and reduce size of the file it is packed with a runtime packer.
Description inserted by Alexander Neth on Tuesday, August 5, 2008 Description updated by Philipp Wolf on Tuesday, August 5, 2008
Back
.
.
.
.