Virus: TR/Dldr.Agent.amzp Date discovered: 31/10/2008 Type: Trojan Subtype: Downloader In the wild: Yes Reported Infections: Low to medium Distribution Potential: Low Damage Potential: Medium Static file: Yes File size: 77.828 Bytes MD5 checksum: 20edfd7563e866c1c149fca2b03ec634 IVDF version: 7.01.00.23 - Friday, October 31, 2008
General Method of propagation: • No own spreading routine Aliases: • Symantec: Trojan.Fakeavalert.B • Mcafee: Downloader-BKM trojan • Kaspersky: Trojan-Downloader.Win32.Agent.amzp • F-Secure: Trojan-Downloader.Win32.Agent.amzp • Eset: Win32/TrojanDownloader.FakeAlert.OY trojan Platforms / OS: • Windows 95 • Windows 98 • Windows 98 SE • Windows NT • Windows ME • Windows 2000 • Windows XP • Windows 2003 Side effects: • Downloads malicious files • Registry modification Files It tries to download some files: – The location is the following: • http://193.142.244.55/**********/item_g.gif It is saved on the local hard drive under: %TEMPDIR% \~tmpa.exe Furthermore this file gets executed after it was fully downloaded. Further investigation pointed out that this file is malware, too. Detected as: TR/BHO.hfq – The location is the following: • http://193.142.244.20/**********/216-1.exe It is saved on the local hard drive under: %TEMPDIR% \~tmpc.exe Furthermore this file gets executed after it was fully downloaded. Further investigation pointed out that this file is malware, too. Detected as: TR/Crypt.ULPM.Gen – The location is the following: • http://bigimagecatalogue.com/**********/chagall.gif It is saved on the local hard drive under: %TEMPDIR% \~tmpd.exe Furthermore this file gets executed after it was fully downloaded. Further investigation pointed out that this file is malware, too. Detected as: TR/Agent.87552.F Registry One of the following values is added in order to run the process after reboot: – [HKCU\Software\Microsoft\Windows\CurrentVersion\Run] • "MSFox"="%executed file% " The following registry keys are added: – [HKLM\SOFTWARE\Mozilla\MSFox] • "Str5"="%random character string% " • "Str9"="%random character string% " • "Str6"="%random character string% " • "Str7"="%random character string% " • "Str8"="%random character string% " • "Str4"="%random character string% " • "Str1"="%random character string% " • "Int2"=dword:%hex number% • "Int3"=dword:%hex number% – [HKLM\Software\Microsoft\RFC1156Agent\CurrentVersion\Parameters] • "TrapPollTimeMilliSecs"=dword:%hex number% File details Programming language: The malware program was written in MS Visual C++. Runtime packer: In order to aggravate detection and reduce size of the file it is packed with the following runtime packer: • UPX
Description inserted by Andreas Feuerstein on Friday, November 14, 2008 Description updated by Andreas Feuerstein on Friday, November 14, 2008
Back
.
.
.
.