Virus: TR/Ransom.Agent.JU Date discovered: 01/02/2010 Type: Trojan In the wild: Yes Reported Infections: Low to medium Distribution Potential: Low Damage Potential: Low to medium Static file: Yes File size: 192.512 Bytes MD5 checksum: 0c13905ce4c33f29496cae8eb4e63a95 IVDF version: 7.10.03.141 - Monday, February 1, 2010
General Aliases: • Mcafee: W32/Akbot • Sophos: Troj/QakBot-D • Panda: Trj/Sinowal.WUJ • Eset: Win32/Spy.Zbot.UN • Bitdefender: Trojan.Zbot.HMK Platforms / OS: • Windows 2000 • Windows XP • Windows 2003 Side effects: • Drops malicious files • Registry modification Files It copies itself to the following location: • %SYSDIR% \sdra64.exe It deletes the following file: • %SYSDIR% \lowsec\user.ds The following files are created: – %SYSDIR% \lowsec\user.ds – %SYSDIR% \lowsec\local.ds – %SYSDIR% \lowsec\user.ds.lll Registry The following registry key is added in order to run the process after reboot: – [HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon] • "userinit"="%SYSDIR% \userinit.exe,%SYSDIR% \sdra64.exe," The following registry keys are added: – [HKEY_USERS\.DEFAULT\software\microsoft\windows\currentversion\ explorer\{4776C4DC-E894-7C06-2148-5D73CEF5F905}] • "{3039636B-5F3D-6C64-6675-696870667265}"=hex:F7,09,F2,0D • "{33373039-3132-3864-6B30-303233343434}"=hex:F7,09,F2,0D • "{6E633338-267E-2A79-6830-386668666866}"=hex:F7,09,F2,0D – [HKEY_USERS\.DEFAULT\software\microsoft\windows\currentversion\ explorer\{3446AF26-B8D7-199B-4CFC-6FD764CA5C9F}] • "{3039636B-5F3D-6C64-6675-696870667265}"=hex:F7,09,F2,0D • "{33373039-3132-3864-6B30-303233343434}"=hex:F7,09,F2,0D • "{6E633338-267E-2A79-6830-386668666866}"=hex:F7,09,F2,0D – [HKEY_USERS\.DEFAULT\software\microsoft\windows\currentversion\ explorer\{43BF8CD1-C5D5-2230-7BB2-98F22C2B7DC6}] • "{3039636B-5F3D-6C64-6675-696870667265}"=hex:F7,09,F2,0D • "{33373039-3132-3864-6B30-303233343434}"=hex:F7,09,F2,0D • "{6E633338-267E-2A79-6830-386668666866}"=hex:F7,09,F2,0D The following registry keys are changed: – [HKEY_USERS\.DEFAULT\Software\Microsoft\Windows NT\CurrentVersion\ Winlogon] New value: • "ParseAutoexec"="1" Deactivate Windows Firewall: – [HKLM\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\ FirewallPolicy\StandardProfile] New value: • "EnableFirewall"=dword:0x00000000 – [HKEY_USERS\S-1-5-19\Software\Microsoft\Windows NT\CurrentVersion\ Winlogon] New value: • "ParseAutoexec"="1" – [HKEY_USERS\S-1-5-20\Software\Microsoft\Windows NT\CurrentVersion\ Winlogon] New value: • "ParseAutoexec"="1" Backdoor The following port is opened: – 239.255.2**********.2********** on UDP port 1900 Injection – It injects itself as a remote thread into a process. Process name: • winlogon.exe – It injects itself as a remote thread into a process. Process name: • svchost.exe – It injects itself as a remote thread into processes. It is injected into all processes. Miscellaneous Internet connection: It queries with the name: • dnsplugweb.com File details Runtime packer: In order to aggravate detection and reduce size of the file it is packed with a runtime packer.
Description inserted by Petre Galan on Friday, April 9, 2010 Description updated by Petre Galan on Thursday, April 15, 2010
Back
.
.
.
.