Virus: TR/Spy.ZBot.akbb Date discovered: 10/06/2010 Type: Trojan In the wild: Yes Reported Infections: Low to medium Distribution Potential: Low to medium Damage Potential: Medium Static file: Yes File size: 130.560 Bytes MD5 checksum: 3c67f319f7f2d6f9028018bfc2b94960 IVDF version: 7.10.08.31 - Thursday, June 10, 2010
General Method of propagation: • Autorun feature Aliases: • Bitdefender: Trojan.Spy.ZBot.EPM • Panda: Trj/Krapack.gen • Eset: Win32/Spy.Zbot.JF Platforms / OS: • Windows 2000 • Windows XP • Windows 2003 Side effects: • Downloads a malicious file • Drops malicious files • Registry modification Files It copies itself to the following locations: • %SYSDIR% \sdra64.exe • %drive% \%executed file% The following files are created: – %drive% \Autorun.inf This is a non malicious text file with the following content: • %code that runs malware% – %SYSDIR% \lowsec\user.ds – %SYSDIR% \lowsec\local.ds – %SYSDIR% \lowsec\user.ds.lll It tries to download a file: – The location is the following: • http://babah20122012.com/zv/********** Registry It creates the following entry in order to bypass the Windows XP firewall: The following registry keys are added: – [HKEY_USERS\S-1-5-20\SOFTWARE\Microsoft\ Protected Storage System Provider\S-1-5-20] • "Migrate"=dword:0x00000002 – [HKEY_USERS\S-1-5-20\Software\Microsoft\ Protected Storage System Provider\S-1-5-20\Data 2\Windows] • "Value"=hex:01,00,00,00,1C,00,00,00,03,00,00,00,AE,11,D9,A4,19,4C,7C,89,F4,DC,40,63,72,FA,99,0C,7E,6F,CF,6B,CE,E9,10,E8,10,00,00,00,89,3D,50,AD,A5,CF,68,A8,24,AE,9C,50,4F,CE,FB,3C,14,00,00,00,C6,6E,5C,0C,61,D1,67,62,E7,97,8F,47,ED,6F,87,F9,41,C0,9B,C5 – [HKEY_USERS\S-1-5-19\Software\Microsoft\Windows NT\CurrentVersion\ Network] • "UID"="%computer name% _001D3849" – [HKEY_USERS\.DEFAULT\Software\Microsoft\ Protected Storage System Provider\S-1-5-18\Data 2\Windows] • "Value"=hex:01,00,00,00,1C,00,00,00,03,00,00,00,1E,5A,D0,F8,FF,47,75,C2,21,04,44,A2,79,1D,7B,3B,0B,DD,DE,18,CC,4C,74,40,10,00,00,00,88,F2,ED,F5,9C,51,81,3E,99,80,43,85,7D,A5,4F,7D,14,00,00,00,21,13,EF,3B,1A,89,46,5F,E1,56,E2,9E,D5,E6,B2,4F,12,86,2E,CF – [HKEY_USERS\S-1-5-19\SOFTWARE\Microsoft\ Protected Storage System Provider\S-1-5-19] • "Migrate"=dword:0x00000002 – [HKEY_USERS\.DEFAULT\software\microsoft\windows\currentversion\ explorer\{43BF8CD1-C5D5-2230-7BB2-98F22C2B7DC6}] • "{3039636B-5F3D-6C64-6675-696870667265}"=hex:F7,09,F2,0D • "{33373039-3132-3864-6B30-303233343434}"=hex:47,09,F2,0D – [HKEY_USERS\S-1-5-19\Software\Microsoft\ Protected Storage System Provider\S-1-5-19\Data 2\Windows] • "Value"=hex:01,00,00,00,1C,00,00,00,03,00,00,00,A2,C3,1C,67,56,DE,39,C9,75,06,2A,2F,45,0D,C3,D7,89,BE,78,8B,02,22,48,02,10,00,00,00,CD,A2,D0,3B,A8,18,52,9F,86,1D,33,31,B4,4E,20,F1,14,00,00,00,CE,58,EE,A8,EA,9F,7A,D0,0E,29,75,B9,82,16,9B,9B,BF,54,67,5C – [HKEY_USERS\.DEFAULT\SOFTWARE\Microsoft\ Protected Storage System Provider\S-1-5-18] • "Migrate"=dword:0x00000002 – [HKEY_USERS\S-1-5-20\Software\Microsoft\Windows NT\CurrentVersion\ Network] • "UID"="%computer name% _001D3173" – [HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Network] • "UID"="%computer name% _001D28C8" The following registry keys are changed: – [HKEY_USERS\S-1-5-20\Software\Microsoft\Internet Explorer\Main] New value: • "Start Page"="" – [HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon] New value: • "userinit"="%SYSDIR% \userinit.exe,%SYSDIR% \sdra64.exe," – [HKEY_USERS\S-1-5-20\Software\Microsoft\Windows NT\CurrentVersion\ Winlogon] New value: • "ParseAutoexec"="1" – [HKEY_USERS\S-1-5-19\Software\Microsoft\Windows NT\CurrentVersion\ Winlogon] New value: • "ParseAutoexec"="1" – [HKEY_USERS\.DEFAULT\Software\Microsoft\Windows NT\CurrentVersion\ Winlogon] New value: • "ParseAutoexec"="1" – [HKEY_USERS\S-1-5-19\Software\Microsoft\Internet Explorer\Main] New value: • "Start Page"="" Network Infection Exploit: It makes use of the following Exploit: – MS04-007 (ASN.1 Vulnerability) Backdoor The following port is opened: – 239.255.25**********.250 on UDP port 1900 M-SEARCH * HTTP/1.1 Stealing It tries to steal the following information: – A logging routine is started after a website is visited: • https://onlineeast.bankofamerica.com/cgi-bin/ias/*/GotoWelcome Injection – It injects itself as a remote thread into a process. Process name: • winlogon.exe – It injects itself as a remote thread into a process. Process name: • svchost.exe – It injects itself as a remote thread into a process. It is injected into all processes. File details Runtime packer: In order to aggravate detection and reduce size of the file it is packed with a runtime packer.
Description inserted by Petre Galan on Tuesday, October 12, 2010 Description updated by Petre Galan on Tuesday, October 12, 2010
Back
.
.
.
.