Virus: DR/Autoit.YH.240 Date discovered: 22/08/2010 Type: Trojan In the wild: Yes Reported Infections: Low to medium Distribution Potential: Low to medium Damage Potential: Low to medium Static file: Yes File size: 622.072 Bytes MD5 checksum: f8bfb7e4337651e5c002602cca0fe6ad VDF version: 7.10.04.184 IVDF version: 7.10.10.240 - Sunday, August 22, 2010
General Methods of propagation: • Autorun feature • Peer to Peer Aliases: • Mcafee: W32/Autorun.worm.zf.gen • Bitdefender: Trojan.Autoit.AKA • Panda: Trj/Autoit.gen • Eset: Win32/Tifaut.A Platforms / OS: • Windows 2000 • Windows XP • Windows 2003 Side effects: • Downloads a malicious file • Drops malicious files • Lowers security settings • Registry modification Files It copies itself to the following locations: • %SYSDIR% \csrcs.exe • %drive% \csrcs.exe • %SYSDIR% \23332094.exe It deletes the initially executed copy of itself. It deletes the following files: • %SYSDIR% \aaaamon.dll • %SYSDIR% \access.cpl • %TEMPDIR% \aofihcr • %SYSDIR% \$winnt$.inf • %SYSDIR% \acledit.dll • %TEMPDIR% \prpzvmn • %TEMPDIR% \~ip.tmp • %SYSDIR% \acctres.dll • %SYSDIR% \12520850.cpx • %SYSDIR% \12520437.cpx • %SYSDIR% \accwiz.exe • %SYSDIR% \aclui.dll • %SYSDIR% \aaclient.dll • %SYSDIR% \6to4svc.dll The following file is created: – %drive% \Autorun.inf This is a non malicious text file with the following content: • %code that runs malware% – %TEMPDIR% \~ip.tmp – %SYSDIR% \autorun.in – %TEMPDIR% \aofihcr – %SYSDIR% \autorun.i – %TEMPDIR% \prpzvmn It tries to download a file: – The location is the following: • http://www.5eb149c0.com/********** It is saved on the local hard drive under: %temporary internet files% \xny[1].htm It tries to execute the following files: – Filename: • %SYSDIR% \csrcs.exe – Filename: • net view %IP address% Registry The following registry keys are added in order to run the processes after reboot: – [HKLM\Software\Microsoft\Windows\CurrentVersion\RunServices] • "csrcs"="%SYSDIR% \csrcs.exe" – [HKLM\Software\Microsoft\Windows\CurrentVersion\policies\Explorer\ Run] • "csrcs"="%SYSDIR% \csrcs.exe" – [HKLM\Software\Microsoft\DRM\amty] • fir The following registry key is added: – [HKLM\Software\Microsoft\DRM\amty] • "bwp2"="noneed" • "cb3"="noneed" • "dreg"="408406541BC5BBE4DC197A2A0C46B9ACF2F90D96B151D7C7BCBD177641EE95F562E634D70EB70FB65FC8FBF0EC31261C8626D05B1ED70CC881A48DA07A7E1A9A" • "exp1"="408406541BC5BBE4DC197A2A0C46B9A8F2F90D96B151D7C7BCBD177641EE95F5" • "ilop"="1" • "kiu"="408406541BC5BBE4DC197A2A0C46B9AFF2F90D96B151D7C7BCBD177741EE958C62E634D70EB773B95FC8FBF0EC31261B8626D05B1ED70CC981A58DD77A7E64EBE121A6249AF4EF57624A6F9892029D504AF01C82DA09AF8C1E11E7C7C1DBB0E4C73A32413AEDD017317B4DD6134930AFBED5B4DE9732DD170CBA2B3D5055F2C5FAEBD5B5E320E57FAC7FF1B2E72784568EE6B66EBA34598D9DCBC155626987AC3FDCA60253FBE2E44B511E5AB957FD1A279E1A156BE3D057430F95C77B73E25AA592466217DE3CB8135AF486B8FFD8138B7490B696B777E429C0A0619658E4A44BEFB49C04967F02EF5BD2C14F82440C9BCDDD932103EA89479138700DFF6A4A" • "p1"="1" • "regexp"="-0.952412980415156" The following registry keys are changed: – [HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon] New value: • "Shell"="Explorer.exe csrcs.exe" – [HKCU\Software\Microsoft\Windows\CurrentVersion\Explorer\Advanced] New value: • "Hidden"=dword:0x00000002 • "ShowSuperHidden"=dword:0x00000000 • "SuperHidden"=dword:0x00000000 – [HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Advanced\ Folder\Hidden\SHOWALL] New value: • "CheckedValue"=dword:0x00000001 P2P In order to infect other systems in the Peer to Peer network community the following action is performed: It retrieves shared folders by querying the following registry keys: • LOCAL_MACHINE\SOFTWARE\LimeWire • Software\Kazaa\LocalContent • HKLM\SOFTWARE\DC++ • HKCU\Software\Shareaza\Shareaza\Downloads • Software\eMule Backdoor Contact server: The following: • http://www.fake_trafic_test.vasthost.co.cc/test1/admin/**********?v=%number% &id=%character string% Injection – It injects a process watching routine into a process. Process name: • net.exe Miscellaneous Checks for an internet connection by contacting the following web sites: • http://www.whatismyip.com/automation/n09230945.asp • http://checkip.dyndns.org/?rnd1=%character string% &rnd2=%character string% Accesses internet resources: • http://www.5eb149c0.com:85/********** • http://geoloc.dai**********.com/?self • http://95.211.21.184:89/********** • http://thepiratebay.org/top/********** Mutex: It creates the following Mutex: • df8g1sdf68g18er1g8re16 File details Runtime packer: In order to aggravate detection and reduce size of the file it is packed with a runtime packer.
Description inserted by Petre Galan on Tuesday, March 1, 2011 Description updated by Petre Galan on Tuesday, March 1, 2011
Back
.
.
.
.