Virus: TR/Krypt.ehl.228352 Date discovered: 18/05/2010 Type: Trojan In the wild: Yes Reported Infections: Low to medium Distribution Potential: Low to medium Damage Potential: Low to medium Static file: Yes File size: 228.352 Bytes MD5 checksum: 6942724549097e9ddd95a338b998a433 IVDF version: 7.10.07.130 - Tuesday, May 18, 2010
General Aliases: • Sophos: Mal/Agent-AS • Bitdefender: Trojan.Generic.KD.12471 • Panda: W32/Pinit.L.worm • Eset: Win32/Pinit.AF Platforms / OS: • Windows 2000 • Windows XP • Windows 2003 Side effects: • Downloads malicious files • Drops malicious files • Registry modification Files It copies itself to the following location: • %SYSDIR% \cooper.mine It deletes the following file: • %SYSDIR% \pgxahdwvzy The following files are created: – %SYSDIR% \user32.dll Further investigation pointed out that this file is malware, too. Detected as: TR/Patched.Gen2 – %SYSDIR% \agzrngg Further investigation pointed out that this file is malware, too. Detected as: TR/Patched.Gen2 – %SYSDIR% \dllcache\user32.dll Further investigation pointed out that this file is malware, too. Detected as: TR/Patched.Gen2 – %SYSDIR% \pgxahdwvzy Further investigation pointed out that this file is malware, too. Detected as: TR/Patched.Gen2 – %SYSDIR% \h7t.wt – %SYSDIR% \hgtd.ruy – %temporary internet files% \r[1].php – %SYSDIR% \nmklo.dll It tries to download some files: – The location is the following: • http://polujopa.com/tpsa/gate/********** – The location is the following: • http://adobecompany.co.uk/tpsa/********** – The location is the following: • http://adobecompany.co.uk/tpsa/********** It tries to executes the following file: – Filename: • "%SYSDIR% \Wbem\wmic.exe" path win32_terminalservicesetting where (__Class!="") call setallowtsconnections 1 Registry The following registry keys are added: – [HKLM\SOFTWARE\9] • "31897356954C2CD3D41B221E3F24F99BBA"=dword:0x00bbdf19 • "31AC70412E939D72A9234CDEBB1AF5867B"="%character string% " • "31C2E1E4D78E6A11B88DFA803456A1FFA5"=dword:0x00000000 – [HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion] • "MID"="F0998D6076FC4887B1F92F247CE0EE8CF48D83CDBA1B4A5E9FFBA78C9F0142E9" – [HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Windows] • "Appisqt_Dlls"="nmklo" – [HKLM\SOFTWARE\1] • "31897356954C2CD3D41B221E3F24F99BBA"=dword:0x00bbdf19 • "31AC70412E939D72A9234CDEBB1AF5867B"="%character string% " • "31C2E1E4D78E6A11B88DFA803456A1FFA5"=dword:0x00000000 – [HKLM\SYSTEM\CurrentControlSet\Control\Terminal Server\ Licensing Core] • "EnableConcurrentSessions"=dword:0x00000001 The following registry key is changed: – [HKLM\SYSTEM\CurrentControlSet\Control\Terminal Server] New value: • "fDenyTSConnections"=dword:0x00000000 Backdoor The following ports are opened: – 174.36.1**********.1********** on TCP port 4521 – 174.36.1**********.1********** on TCP port 55039 – 174.36.1**********.1********** on TCP port 51534 File details Runtime packer: In order to aggravate detection and reduce size of the file it is packed with a runtime packer.
Description inserted by Petre Galan on Wednesday, July 14, 2010 Description updated by Petre Galan on Tuesday, July 20, 2010
Back
.
.
.
.