Virus: TR/Dldr.FraudLoad.51200 Date discovered: 16/09/2009 Type: Trojan Subtype: Downloader In the wild: Yes Reported Infections: Medium to high Distribution Potential: Medium Damage Potential: Medium Static file: Yes File size: 51.200 Bytes MD5 checksum: 2277c47fd42f0D448dab0C97493e6acc VDF version: 7.01.05.247 IVDF version: 7.01.05.249 - Wednesday, September 16, 2009
General Platforms / OS: • Windows 2000 • Windows XP • Windows 2003 Side effects: • Downloads a malicious file • Drops malicious files • Lowers security settings • Registry modification Elevates itself with SeShutdownPrivilege in order to restart the system. Files It deletes the initially executed copy of itself. The following files are created: – %SYSDIR% \braviax.exe Further investigation pointed out that this file is malware, too. Detected as: TR/Dldr.Renos.56 – %SYSDIR% \dllcache\figaro.sys Further investigation pointed out that this file is malware, too. Detected as: TR/Rootkit.Gen – %SYSDIR% \dllcache\beep.sys Further investigation pointed out that this file is malware, too. Detected as: TR/Rootkit.Gen – %SYSDIR% \drivers\beep.sys Further investigation pointed out that this file is malware, too. Detected as: TR/Rootkit.Gen It tries to download a file: – The locations are the following: • http://gumertagionader.com/nLp1wa/0t5CVd8hD0u/********** • http://celiminerkariota.com/R1J0x5lf8gpn********** • http://uplaserdunavats.com/IgJ1JR0JU5a********** • http://opolertionfer.com/G1Ce0YTH5********** • http://nuherfodaverta.com/Ral1h0T5********** • http://polanermogalios.com/Iq1o0p5********** • http://vuilertumegated.com/gPq1oKN0********** • http://buteratorionasd.com/AYQ1c0sF5n********** • http://nulerotkabelast.com/wBd1Tm0L5k********** Further investigation pointed out that this file is malware, too. Detected as: TR/Dldr.FraudLoad.fnm Registry To each registry key one of the values is added in order to run the processes after reboot: – [HKCU\Software\Microsoft\Windows\CurrentVersion\Run] • "braviax"="%SYSDIR% \braviax.exe" – [HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Run] • "braviax"="%SYSDIR% \braviax.exe" The value of the following registry key is removed: – [HKCU\Software\Microsoft\Windows\CurrentVersion\Run] • risky The following registry keys are changed: Lower security settings from Internet Explorer: – [HKCU\Software\Microsoft\Windows\CurrentVersion\Policies\ Associations] New value: • "LowRiskFileTypes"="zip;.rar;.cab;.txt;.exe;.reg;.msi;.htm;.html;.gif;.bmp;.jpg;.avi;.mov;.mp3;.wav" • "SaveZoneInformation"=dword:00000001 File details Runtime packer: In order to aggravate detection and reduce size of the file it is packed with the following runtime packer: • Mystic Compressor
Description inserted by Petre Galan on Wednesday, September 16, 2009 Description updated by Petre Galan on Wednesday, September 16, 2009
Back
.
.
.
.