Virus: BDS/Cycbot.B.735 Date discovered: 26/11/2010 Type: Backdoor Server In the wild: Yes Reported Infections: Low Distribution Potential: Low Damage Potential: Medium File size: 190.976 Bytes MD5 checksum: 035D0EAC0267B776C68157A9F5E06F33 VDF version: 7.10.06.152 IVDF version: 7.10.14.113 - Friday, November 26, 2010
General Method of propagation: • No own spreading routine Aliases: • Kaspersky: Backdoor.Win32.Gbot.hgd • TrendMicro: BKDR_CYCBOT.SMIB • Microsoft: Backdoor:Win32/Cycbot.B Platforms / OS: • Windows 2000 • Windows XP • Windows 2003 • Windows Vista • Windows 7 Side effects: • Third party control • Drops files • Lowers security settings • Registry modification • Steals information Files It copies itself to the following location: • %TEMPDIR% \csrss.exe It modifies the following file: • %APPDATA%\Mozilla\Firefox\Profiles\f81lb9un.default\prefs.js As a result various security mechanisms are disabled. The following file is created: – %APPDATA%\A896.542 Contains parameters used by the malware. Registry One of the following values is added in order to run the process after reboot: – [HCKU\Software\Microsoft\Windows NT\CurrentVersion\Windows] • "load"="%TEMPDIR% \csrss.exe" The following registry key is added: – [HKEY_CURRENT_CONFIG\Software\Microsoft\windows\CurrentVersion\ Internet Settings] • "ProxyEnable"=dword:00000001 The following registry key is changed: Lower security settings from Internet Explorer: – [HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings] New value: • "MigrateProxy"=dword:00000001 • "ProxyEnable"=dword:00000001 • "ProxyServer"="http=127.0.0.1:%number% " Process termination Processes with one of the following strings are terminated: • Avast • Avira • Dr.Web • Kaspersky • McAfee • ESET NOD32 • Norton • BitDefender Backdoor The following ports are opened: – %executed file% on a random TCP port in order to provide a proxy server. – %executed file% on a random TCP port in order to provide backdoor capabilities. Stealing – A logging routine is started after the following website is visited, which contains one of the following substrings in the URL: • .2mdn.; .abmr.; .adtechus.; .aol.; .atdmt.; .atwola.; .autodatadirect.; .bing.net; .dartsearch.; .doubleclick.; .ggpht.; .google; .ivwbox.; .mapquestapi.; .microsoft.; .opera.; .tacoda.; .thawte.; .tlowdb.; .truveo.; .virtualearth.; .wsod.; .yimg.com; .ypcdn.; amazon.; aol/search; aolcdn.; aolsvc.; bing.com; bing.com/search; blogger; brightcove.com; doubleclick.; ebay.; err069; facebook.; flickr; google-analytics.; google.; googlesyndication.; googleusercontent.; gstatic.; imdb.; mapq.st; scorecardresearch.com; search.aol.; search.yahoo.com/search; searcht2.aol.; start=; start=0; suche.aol.; twitter.; wikimedia.; wikipedia.; yahoo.; yahoo.com; youtube.; ytimg. • Internet traffic Miscellaneous Accesses internet resources: • http://bigbadhead.**********/blog/images/%number% .jpg; http://crazyleafdesign.**********/blog/images/share/facebook.png; http://crazyleafdesign.**********/blog/images/share/stumble.png; http://ddossecureonline.**********/blog/images/%number% .jpg; http://folusho.**********/wp-content/uploads/2010/09/web-20-what-is-300x251.jpg; http://freeservermonitorings.**********/blog/images/%number% .jpg; http://freewhoisdb.**********/blog/images/%number% .jpg; http://fxsystemsone.**********/blog/images/%number% .jpg; http://gravatar.**********/avatar.php?gravatar_id=f2a3889aff6fc9711a3cbcfe64067be1; http://gravatar.**********/avatar.php?gravatar_id=f2a3889aff6fc9711a3cbcfe64067be2; http://greenherbalteaonline.**********/images/greenherbalteagirlholdingcup250.gif; http://healthylifenow.**********/templates/7348/images/header_logo.jpg; http://healthylifenow.**********/templates/7349/images/header_logo.jpg; http://hlamidioz.**********/blog/images/%number% .jpg; http://hollandandbarrett.**********/images/footer/account.gif; http://hollandandbarrett.**********/images/footer/account.jpg; http://itshopsonline.**********/blog/images/%number% .jpg; http://japanesegreenteaonline.**********/assets/images/greentea-cha-1.gif; http://japanesegreenteaonline.**********/assets/images/greentea-cha-2.gif; http://killprocessoffline.**********/blog/images/%number% .jpg; http://laporoskopia.**********/blog/images/%number% .jpg; http://myonlinefreelibrarry.**********/blog/images/%number% .jpg; http://nationsautoelectric.**********/images/50-217-1_F_1_.jpg; http://nationsautoelectric.**********/images/50-217-1_F_2_.jpg; http://onlinebizdirectory.**********/images/PowerHideBanner.gif; http://onlinebizdirectory.**********/images/PowerShowBanner.gif; http://psfk.**********/img/icons/facebook.png; http://psfk.**********/img/icons/twitter.png; http://realsoftwaredevelopment.**********/WindowsLiveWriter/web-2_0_thumb_1.gif; http://repairshampoo.**********/blog/images/%number% .jpg; http://sambukaclubonline.**********/blog/images/%number% .jpg; http://securityshllsonline.**********/blog/images/%number% .jpg; http://sslprogrammingshool.**********/blog/images/%number% .jpg; http://lostpropaganda.**********/blog/pics/3321.jpg; http://lostpropaganda.**********/blog/pics/3322.jpg; http://monochrom.**********/polytheism/pictures/TanzenderShiva.jpg File details Programming language: The malware program was written in MS Visual C++.
Description inserted by Andrei Ilie on Monday, August 1, 2011 Description updated by Andrei Ilie on Thursday, August 4, 2011
Back
.
.
.
.