Virus: TR/Spy.SpyEyes.egp Date discovered: 05/01/2011 Type: Trojan In the wild: Yes Reported Infections: Low to medium Distribution Potential: Low Damage Potential: Low to medium Static file: Yes File size: 167.936 Bytes MD5 checksum: d58a02ab8a9a9b2b6bc2a98937471b16 VDF version: 7.10.07.154 IVDF version: 7.11.01.29 - Wednesday, January 5, 2011
General Aliases: • Mcafee: PWS-Spyeye • Kaspersky: Trojan-Spy.Win32.SpyEyes.egp • Sophos: Mal/Zbot-AV • Bitdefender: Trojan.Generic.5346632 • Panda: Trj/SpyEyes.E • GData: Trojan.Generic.5346632 Platforms / OS: • Windows 2000 • Windows XP • Windows 2003 Side effects: • Drops malicious files • Registry modification • Steals information Files It copies itself to the following location: • C:\malacuxatx.exe\malacuxatx.exe It deletes the initially executed copy of itself. The following file is created: – C:\malacuxatx.exe\config.bin It tries to execute the following file: – Filename: • C:\malacuxatx.exe\malacuxatx.exe Registry The following registry key is added in order to run the process after reboot: – [HKCU\Software\Microsoft\Windows\CurrentVersion\Run] • "malacuxatx.exe"="C:\malacuxatx.exe\malacuxatx.exe" The values of the following registry key are removed: – [HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings] • AutoConfigURL • ProxyOverride • ProxyServer The following registry keys are added: – [HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings] • "WarnOnIntranet"=dword:0x00000000 – [HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings\ Zones\0] • "1409"=dword:0x00000003 – [HKCU\Software\Microsoft\Internet Explorer\PhishingFilter] • "ShownServiceDownBalloon"=dword:0x00000000 – [HKCU\Software\Microsoft\Internet Explorer\Recovery] • "ClearBrowsingHistoryOnExit"=dword:0x00000000 The following registry keys are changed: – [HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings\ Zones\1] New value: • "1406"=dword:0x00000000 • "1409"=dword:0x00000003 • "1609"=dword:0x00000000 – [HKCU\Software\Microsoft\Internet Explorer\PhishingFilter] New value: • "EnabledV8"=dword:0x00000000 – [HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings\ Zones\0] New value: • "1406"=dword:0x00000000 • "1609"=dword:0x00000000 – [HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings\ Zones\2] New value: • "1406"=dword:0x00000000 • "1409"=dword:0x00000003 • "1609"=dword:0x00000000 – [HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings\ Lockdown_Zones\4] New value: • "1406"=dword:0x00000000 – [HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings\ Lockdown_Zones\1] New value: • "1406"=dword:0x00000000 – [HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings\ Lockdown_Zones\2] New value: • "1406"=dword:0x00000000 – [HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings\ Lockdown_Zones\3] New value: • "1406"=dword:0x00000000 – [HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings] New value: • "EnableHttp1_1"=dword:0x00000001 • "MigrateProxy"=dword:0x00000001 • "ProxyEnable"=dword:0x00000000 • "ProxyHttp1.1"=dword:0x00000001 • "WarnOnPost"=hex:00,00,00,00 • "WarnOnPostRedirect"=dword:0x00000000 – [HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings\ Zones\3] New value: • "1406"=dword:0x00000000 • "1409"=dword:0x00000003 • "1609"=dword:0x00000000 – [HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings\ Zones\4] New value: • "1406"=dword:0x00000000 • "1409"=dword:0x00000003 • "1609"=dword:0x00000000 Backdoor Contact server: All of the following: • 91.207.18**********.35:444 (TCP) • http://domain291.org/vppb1/**********?guid=%character string% &ver=%number% &stat=%character string% &ie=%character string% &os=%character string% &ut=%character string% &plg=%character string% &cpu=%number% &ccrc=%character string% &md5=%character string% Sends information about: • Computer name • CPU type • Current user • Current malware status • Username • Information about the Windows operating system Stealing It tries to steal the following information: – Passwords from the following programs: • Mozilla Firefox • Internet Explorer Injection – It injects itself as a remote thread into a process. Process name: • explorer.exe – It injects itself as a remote thread into a process. It is injected into all processes. Miscellaneous Checks for an internet connection by contacting the following web site: • http://www.microsoft.com Mutex: It creates the following Mutexes: • __ViXyzp__ • __SPYNET_REPALREADYSENDED__ File details Runtime packer: In order to aggravate detection and reduce size of the file it is packed with a runtime packer.
Description inserted by Petre Galan on Thursday, April 14, 2011 Description updated by Petre Galan on Thursday, April 14, 2011
Back
.
.
.
.