Virus: TR/Spy.Zb.ae.118784 Date discovered: 14/05/2010 Type: Trojan In the wild: Yes Reported Infections: Low to medium Distribution Potential: Low to medium Damage Potential: Low to medium Static file: Yes File size: 118.784 Bytes MD5 checksum: 4dc14290fb2cb22e11e3a1d24aa09dc1 VDF version: 7.10.03.22 IVDF version: 7.10.07.108 - Friday, May 14, 2010
General Method of propagation: • Peer to Peer Aliases: • Bitdefender: Trojan.Generic.4448808 • Panda: Trj/Sinowal.XHI • Eset: Win32/Spy.Zbot.YW Platforms / OS: • Windows 2000 • Windows XP • Windows 2003 Side effects: • Drops malicious files • Registry modification • Makes use of software vulnerability • CVE-2007-1204 • MS07-019 Files It copies itself to the following location: • %SYSDIR% \sdra64.exe The following files are created: – %SYSDIR% \lowsec\user.ds – %SYSDIR% \lowsec\local.ds – %SYSDIR% \lowsec\user.ds.lll Registry It creates the following entry in order to bypass the Windows XP firewall: – [HKLM\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\ FirewallPolicy\StandardProfile] • "EnableFirewall"=dword:0x00000000 The following registry keys are added: – [HKEY_USERS\S-1-5-20\SOFTWARE\Microsoft\ Protected Storage System Provider\S-1-5-20] • "Migrate"=dword:0x00000002 – [HKEY_USERS\S-1-5-20\Software\Microsoft\ Protected Storage System Provider\S-1-5-20\Data 2\Windows] • "Value"=hex:01,00,00,00,1C,00,00,00,03,00,00,00,6D,DB,FE,19,ED,B6,6C,F2,56,86,31,BD,12,FB,6F,BB,00,86,57,A4,41,28,EB,06,10,00,00,00,89,3D,50,AD,A5,CF,68,A8,24,AE,9C,50,4F,CE,FB,3C,14,00,00,00,C6,6E,5C,0C,61,D1,67,62,E7,97,8F,47,ED,6F,87,F9,41,C0,9B,C5 – [HKEY_USERS\S-1-5-19\Software\Microsoft\Windows NT\CurrentVersion\ Network] • "UID"="%computer name% _7875768FCFF3ECE1" – [HKEY_USERS\.DEFAULT\software\microsoft\windows\currentversion\ explorer\{4776C4DC-E894-7C06-2148-5D73CEF5F905}] • "{3039636B-5F3D-6C64-6675-696870667265}"=hex:F7,09,F2,0D • "{33373039-3132-3864-6B30-303233343434}"=hex:F7,09,F2,0D • "{6E633338-267E-2A79-6830-386668666866}"=hex:F7,09,F2,0D – [HKEY_USERS\.DEFAULT\Software\Microsoft\ Protected Storage System Provider\S-1-5-18\Data 2\Windows] • "Value"=hex:01,00,00,00,1C,00,00,00,03,00,00,00,2C,3F,19,91,9B,FA,E1,E9,3C,EC,47,57,9D,58,B0,8C,CE,E0,C2,55,B3,A0,92,BF,10,00,00,00,88,F2,ED,F5,9C,51,81,3E,99,80,43,85,7D,A5,4F,7D,14,00,00,00,86,B4,0A,71,D5,43,63,CA,5C,FF,9F,0E,13,1B,E5,E6,EF,AA,5D,4A – [HKEY_USERS\.DEFAULT\software\microsoft\windows\currentversion\ explorer\{43BF8CD1-C5D5-2230-7BB2-98F22C2B7DC6}] • "{3039636B-5F3D-6C64-6675-696870667265}"=hex:F7,09,F2,0D • "{33373039-3132-3864-6B30-303233343434}"=hex:F7,09,F2,0D • "{6E633338-267E-2A79-6830-386668666866}"=hex:F7,09,F2,0D – [HKEY_USERS\.DEFAULT\SOFTWARE\Microsoft\ Protected Storage System Provider\S-1-5-18] • "Migrate"=dword:0x00000002 – [HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Network] • "UID"="%computer name% _7875768FCFF3ECE1" – [HKEY_USERS\S-1-5-20\Software\Microsoft\Windows NT\CurrentVersion\ Network] • "UID"="%computer name% _7875768FCFF3ECE1" The following registry keys are changed: – [HKEY_USERS\.DEFAULT\Software\Microsoft\Windows NT\CurrentVersion\ Winlogon] New value: • "ParseAutoexec"="1" – [HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon] New value: • "userinit"="%SYSDIR% \userinit.exe,%SYSDIR% \sdra64.exe," – [HKEY_USERS\S-1-5-20\Software\Microsoft\Windows NT\CurrentVersion\ Winlogon] New value: • "ParseAutoexec"="1" P2P In order to infect other systems in the Peer to Peer network community the following action is performed: It retrieves shared folders by querying the following registry keys: • software\flashfxp\3 • software\ghisler\total commander • software\ipswitch\ws_ftp • software\far\plugins\ftp\hosts • software\far2\plugins\ftp\hosts • software\martin prikryl\winscp 2\sessions • software\ftpware\coreftp\sites • software\smartftp\client 2.0\settings\general\favorites Stealing It tries to steal the following information: – A logging routine is started after a website is visited: • https://onlineeast.bankofamerica.com/cgi-bin/ias/*/GotoWelcome Injection – It injects itself as a remote thread into a process. Process name: • winlogon.exe – It injects itself as a remote thread into a process. Process name: • svchost.exe – It injects itself as a remote thread into a process. It is injected into all processes. Miscellaneous Accesses internet resources: • http://www.oomseekerss.ru/img/********** Mutex: It creates the following Mutexes: • _AVIRA_2110 • _AVIRA_2109 • _AVIRA_2108 • _AVIRA_2101 • _AVIRA_21099 File details Programming language: The malware program was written in MS Visual C++. Runtime packer: In order to aggravate detection and reduce size of the file it is packed with a runtime packer.
Description inserted by Petre Galan on Friday, February 4, 2011 Description updated by Petre Galan on Friday, February 4, 2011
Back
.
.
.
.