Virus: DR/Autoit.RL Date discovered: 14/10/2009 Type: Trojan In the wild: Yes Reported Infections: Low to medium Distribution Potential: Low to medium Damage Potential: Medium Static file: Yes File size: 927.495 Bytes MD5 checksum: e26110b93d3e2b047f11cb9b3158cc35 IVDF version: 7.01.06.109 - Wednesday, October 14, 2009
General Method of propagation: • Autorun feature Aliases: • Mcafee: W32/Renocide.c virus • Sophos: W32/Autoit-HA • Eset: Win32/AutoRun.Autoit.BL • Bitdefender: Trojan.Generic.2590538 Platforms / OS: • Windows 2000 • Windows XP • Windows 2003 Side effects: • Downloads malicious files • Drops malicious files • Lowers security settings • Registry modification Files It copies itself to the following locations: • %SYSDIR% \csrcs.exe • %drive% \mijdwm.exe It deletes the initially executed copy of itself. It deletes the following file: • %TEMPDIR% \suicide.bat The following files are created: – A file that is for temporary use and it might be deleted afterwards: • C:\%random character string% – %SYSDIR% \autorun.inf This is a non malicious text file with the following content: • %code that runs malware% – %drive% \autorun.inf This is a non malicious text file with the following content: • %code that runs malware% – %TEMPDIR% \suicide.bat It tries to download some files: – The locations are the following: • http://pimpumpam.orz.hm:48753/********** • http://lanlenio.or.tp:48753/********** • http://juirjeju.or.tp:48753/********** At the time of writing this file was not online for further investigation. Registry The following registry keys are added: – [HKLM\SOFTWARE\Microsoft\DRM\amty] • "dreg"="408406541BC5BBE4DC197A2A0C46B9ACF2F90D96B151D7C7BCBD177641EE95F562E634D70EB70FB65FC8FBF0EC31276D8626D05B1ED70CC881A48DA07A7E649B" • "exp1"="408406541BC5BBE4DC197A2A0C46B9ADF2F90D96B151D7C7BCBD177641EE95F162E634D70EB70FB65FC8FBF0EC312619" • "fix"="" • "fix1"="1" • "ilop"="1" • "regexp"="%number% " – [HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer\ Run] • "csrcs"="%SYSDIR% \csrcs.exe" The following registry keys are changed: – [HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon] New value: • "Shell"="Explorer.exe csrcs.exe" – [HKCU\Software\Microsoft\Windows\CurrentVersion\Explorer\Advanced] New value: • "Hidden"=dword:0x00000002 • "ShowSuperHidden"=dword:0x00000000 • "SuperHidden"=dword:0x00000000 – [HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings] New value: • "GlobalUserOffline"=dword:0x00000000 Network Infection IP address generation: It creates random IP addresses while it keeps the first three octets from its own address. Afterwards it tries to establish a connection with the created addresses. File details Runtime packer: In order to aggravate detection and reduce size of the file it is packed with a runtime packer.
Description inserted by Petre Galan on Tuesday, December 15, 2009 Description updated by Petre Galan on Tuesday, December 15, 2009
Back
.
.
.
.