Virus: TR/Rimecud.A.1859 Date discovered: 06/12/2010 Type: Trojan In the wild: Yes Reported Infections: Low to medium Distribution Potential: Low Damage Potential: Low to medium Static file: Yes File size: 90.112 Bytes MD5 checksum: 5d1ac261c4312106ce27fede4af939de VDF version: 7.10.06.204 IVDF version: 7.10.14.192 - Monday, December 6, 2010
General Aliases: • Kaspersky: Trojan.Win32.Pincav.anjh • Sophos: Mal/Palevo-A • Bitdefender: Trojan.Generic.KDV.81884 • Panda: W32/P2Pworm.PK • GData: Trojan.Generic.KDV.81884 Platforms / OS: • Windows 2000 • Windows XP • Windows 2003 Side effects: • Downloads malicious files • Drops malicious files • Registry modification Files It copies itself to the following location: • %HOME%\Application Data\ltzqai.exe The following files are created: – %recycle bin% \%CLSID% \Desktop.ini – %recycle bin% \%CLSID% \ju7bd.exe – %recycle bin% \%CLSID% \psyjo3.exe – %recycle bin% \%CLSID% \games.exe – %recycle bin% \%CLSID% \system.exe – %recycle bin% \%CLSID% \jwjqa.exe – %recycle bin% \%CLSID% \lsvb.exe – %recycle bin% \%CLSID% \jwkd.exe – %recycle bin% \%CLSID% \dfe.exe – %recycle bin% \%CLSID% \lsq.exe – %recycle bin% \%CLSID% \jikd.exe It tries to download some files: – The location is the following: • http://two.natnatraoi.com/********** It is saved on the local hard drive under: %TEMPDIR% \128840.exe – The location is the following: • http://two.natnatraoi.com/********** It is saved on the local hard drive under: %TEMPDIR% \83169.exe – The location is the following: • http://two.natnatraoi.com/********** It is saved on the local hard drive under: %TEMPDIR% \755.exe – The location is the following: • http://two.natnatraoi.com/********** It is saved on the local hard drive under: %TEMPDIR% \207124.exe – The location is the following: • http://two.natnatraoi.com/********** It is saved on the local hard drive under: %TEMPDIR% \9661586.exe – The location is the following: • http://two.natnatraoi.com/********** It is saved on the local hard drive under: %TEMPDIR% \6890.exe – The location is the following: • http://two.natnatraoi.com/********** It is saved on the local hard drive under: %TEMPDIR% \9726578.exe – The location is the following: • http://two.natnatraoi.com/********** It is saved on the local hard drive under: %TEMPDIR% \36021.exe – The location is the following: • http://two.natnatraoi.com/********** It is saved on the local hard drive under: %TEMPDIR% \546679.exe – The location is the following: • http://two.natnatraoi.com/********** It is saved on the local hard drive under: %TEMPDIR% \021.exe It tries to execute the following files: – Filename: • %TEMPDIR% \36021.exe – Filename: • %TEMPDIR% \6890.exe – Filename: • %TEMPDIR% \128840.exe – Filename: • %TEMPDIR% \755.exe – Filename: • %TEMPDIR% \021.exe – Filename: • %TEMPDIR% \546679.exe – Filename: • %TEMPDIR% \207124.exe – Filename: • %TEMPDIR% \9726578.exe – Filename: • %TEMPDIR% \9661586.exe – Filename: • %TEMPDIR% \83169.exe Registry The following registry keys are added in order to run the processes after reboot: – [HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon] • "Taskman"="%HOME%\Application Data\ltzqai.exe" – [HKCU\Software\Microsoft\Windows\CurrentVersion\Run] • "Fgfk"="%recycle bin% \%CLSID% \lsq.exe" • "Fnfx"="%recycle bin% \%CLSID% \dfe.exe" • "Fvbk"="%recycle bin% \%CLSID% \lsvb.exe" • "Teswf"="%recycle bin% \%CLSID% \system.exe" • "games"="%recycle bin% \%CLSID% \games.exe" • "jaqq"="%recycle bin% \%CLSID% \jwkd.exe" • "jkqq"="%recycle bin% \%CLSID% \jikd.exe" • "ju7bd"="%recycle bin% \%CLSID% \ju7bd.exe" • "psysjo3"="%recycle bin% \%CLSID% \psyjo3.exe" • "sdjwe"="%recycle bin% \%CLSID% \jwjqa.exe" – [HKCU\Software\Microsoft\Windows NT\CurrentVersion\Winlogon] • "Shell"="%recycle bin% \%CLSID% \dfe.exe,%recycle bin% \%CLSID% \jwjqa.exe,%recycle bin% \S-1-5-21-0243556031-888888379-781863308-1457\system.exe,%recycle bin% \S-1-5-21-0243556031-888888379-781863308-1455\psyjo3.exe,%recycle bin% \S-1-5-21-0243556031-888888379-781863308-8333\lsvb.exe,%recycle bin% \S-1-5-21-0243556031-888888379-781863308-9043\jwkd.exe,%recycle bin% \S-1-5-21-0243556031-888888379-781863308-1451\games.exe,%recycle bin% \S-1-5-21-0243556031-888888379-781863308-2734\ju7bd.exe,%HOME%\Application Data\ltzqai.exe,%recycle bin% \S-1-5-21-0243556031-888888379-781863308-9143\jikd.exe,explorer.exe,%recycle bin% \S-1-5-21-0243556031-888888379-781863308-8763\lsq.exe" Backdoor Contact server: All of the following: • play.myg**********.com:9955 (UDP) • tf130.tef**********.com:8800 (TCP) • tf98.tef**********.com:8800 (TCP) • mix.tef**********.com:8800 (TCP) • tf122.tef**********.com:8800 (TCP) • tf50.tef**********.com:8800 (TCP) • mails.joo**********.com:8800 (TCP) • peas.com**********.org:8800 (TCP) • tf18.tef**********.com:8800 (TCP) • 209.90.13**********.220:8800 (TCP) • 66.7.22**********.28:8800 (TCP) Injection – It injects itself as a remote thread into a process. Process name: • explorer.exe Miscellaneous Accesses internet resources: • http://b.suhi4hr.net/********** Mutex: It creates the following Mutexes: • fwghw • psyjo • games • f7bd • mdge • sewwwefwef • omdgv • dwcfewf • nbev+32 • fewhx • fedfw File details Programming language: The malware program was written in MS Visual C++. Runtime packer: In order to aggravate detection and reduce size of the file it is packed with a runtime packer.
Description inserted by Petre Galan on Wednesday, April 20, 2011 Description updated by Petre Galan on Wednesday, April 20, 2011
Back
.
.
.
.