Virus: TR/EyeStye.N.107 Date discovered: 07/06/2011 Type: Trojan In the wild: No Reported Infections: Low Distribution Potential: Low Damage Potential: Low Static file: Yes File size: 172.067 Bytes MD5 checksum: 9D2FC019B4B7582C7AFD0D5D55E23449 VDF version: 7.11.09.66 - Tuesday, June 7, 2011IVDF version: 7.11.09.66 - Tuesday, June 7, 2011
General Method of propagation: • No own spreading routine Aliases: • Kaspersky: Trojan.Win32.Jorik.SpyEyes.sy • Bitdefender: Trojan.Generic.KDV.285014 • Eset: Win32/Kryptik.QER • DrWeb: Trojan.PWS.SpySweep.45 Platforms / OS: • Windows 95 • Windows 98 • Windows 98 SE • Windows NT • Windows ME • Windows 2000 • Windows XP • Windows 2003 • Windows Vista • Windows Server 2008 • Windows 7 Side effects: • Drops a file • Registry modification Files It copies itself to the following location: • C:\Recycle.Bin\Recycle.Bin.exe It deletes the initially executed copy of itself. The following file is created: – Non malicious file: • C:\Recycle.Bin\config.bin Registry One of the following values is added in order to run the process after reboot: – HKCU\Software\Microsoft\Windows\CurrentVersion\Run • "%random% "="C:\Recycle.Bin\Recycle.Bin.exe" The following registry keys are added: – HKCU\Software\Microsoft\Internet Explorer\PhishingFilter • "EnabledV8"=dword:00000000 • "ShownServiceDownBalloon"=dword:00000000 – HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings • "WarnOnIntranet"=dword:00000000 – HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings\ Zones\0 • "1409"=dword:00000003 – HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings\ Zones\1 • "1409"=dword:00000003 – HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings\ Zones\2 • "1409"=dword:00000003 – HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings\ Zones\3 • "1409"=dword:00000003 – HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings\ Zones\4 • "1409"=dword:00000003 The following registry keys are changed: Lower security settings from Internet Explorer: – HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings Old value: • "WarnOnPost"=hex:01,00,00,00 • "ProxyHttp1.1"=dword:00000000 • "WarnOnPostRedirect"=dword:00000001 New value: • "WarnOnPost"=hex:00,00,00,00 • "ProxyHttp1.1"=dword:00000001 • "WarnOnPostRedirect"=dword:00000000 Lower security settings from Internet Explorer: – HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings\ Lockdown_Zones\1 Old value: • "1406"=dword:00000001 New value: • "1406"=dword:00000000 Lower security settings from Internet Explorer: – HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings\ Lockdown_Zones\3 Old value: • "1406"=dword:00000003 New value: • "1406"=dword:00000000 Lower security settings from Internet Explorer: – HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings\ Lockdown_Zones\4 Old value: • "1406"=dword:00000003 New value: • "1406"=dword:00000000 Lower security settings from Internet Explorer: – HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings\ Zones\0 Old value: • "1609"=dword:00000001 New value: • "1609"=dword:00000000 Lower security settings from Internet Explorer: – HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings\ Zones\1 Old value: • "1406"=dword:00000001 • "1609"=dword:00000001 New value: • "1406"=dword:00000000 • "1609"=dword:00000000 Lower security settings from Internet Explorer: – HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings\ Zones\2 Old value: • "1609"=dword:00000001 New value: • "1609"=dword:00000000 Lower security settings from Internet Explorer: – HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings\ Zones\3 Old value: • "1406"=dword:00000003 • "1609"=dword:00000001 New value: • "1406"=dword:00000000 • "1609"=dword:00000000 Lower security settings from Internet Explorer: – HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings\ Zones\4 Old value: • "1406"=dword:00000003 • "1609"=dword:00000001 New value: • "1406"=dword:00000000 • "1609"=dword:00000000 Miscellaneous Internet connection: In order to check for its internet connection the following DNS server is contacted: • www.fa**********ok.com It queries with the name: • www.fa**********ok.com/log**********hp?guid**********2EB1&ver=10325&ie=**********&md5=**********&plg=**********=online File details Programming language: The malware program was written in MS Visual C++. Runtime packer: In order to aggravate detection and reduce size of the file it is packed with the following runtime packer: • UPX V2.00-V2.90
Description inserted by Szewee Tan on Wednesday, July 13, 2011 Description updated by Szewee Tan on Wednesday, July 13, 2011
Back
.
.
.
.