Virus: TR/Dldr.Scar.D Date discovered: 29/06/2011 Type: Trojan In the wild: Yes Reported Infections: Low Distribution Potential: Medium to high Damage Potential: Medium File size: 188.416 Bytes MD5 checksum: 1BF5CFFD41DEE4386A82D4A98DBDDE56 VDF version: 7.11.10.144 - Wednesday, June 29, 2011IVDF version: 7.11.10.144 - Wednesday, June 29, 2011
General Methods of propagation: • By visiting infected websites • Messenger Aliases: • Symantec: W32.IRCBot.NG • TrendMicro: WORM_DORKBOT.WP • Microsoft: Worm:Win32/Dorkbot.A Platforms / OS: • Windows 2000 • Windows XP • Windows 2003 • Windows Vista • Windows 7 Side effects: • Third party control • Downloads files • Drops files • Registry modification • Steals information Files It deletes the initially executed copy of itself. The following file is created: – %APPDATA%\%random character string% .exe Further investigation pointed out that this file is malware, too. Registry One of the following values is added in order to run the process after reboot: – [HKCU\Software\Microsoft\Windows\CurrentVersion\Run] • "%random character string% "="%APPDATA%\%random character string% .exe" The following registry key is changed: Lower security settings from Internet Explorer: – [HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings] New value: • "MigrateProxy"=dword:00000001 • "ProxyEnable"=dword:00000000 • "ProxyServer"=- • "ProxyOverride"=- • "AutoConfigURL"=- Messenger It is spreading via Messenger. The characteristics are described below: – Windows Live Messenger IRC Server: **********shannen.cc Port: 4949 Server password: ngrBot Nickname: %random character string% Server: **********0days.in Server password: ngrBot Nickname: %random character string% Server: **********a7aneek.net Port: 5900 Server password: ngrBot Nickname: %random character string% Server: **********honeycat.org Server password: ngrBot Nickname: %random character string% Server: **********masrawy.in Server password: ngrBot Nickname: %random character string% Server: **********scorevidic.net Server password: ngrBot Nickname: %random character string% – This malware has the ability to collect and send information such as: • Username • Information about the Windows operating system – Furthermore it has the ability to perform actions such as: • connect to IRC server • disconnect from IRC server • Join IRC channel • Leave IRC channel • Perform DDoS attack Backdoor Contact server: All of the following: • **********a7aneek.net:3211 • **********a7aneek.net:3212 • **********a7aneek.net:80 • **********ka22.fileave.com:80 As a result it may send information and remote control could be provided. Sends information about: • visited URLs • Information about the Windows operating system Remote control capabilities: • Perform DDoS attack • Visit a website Stealing – It uses a network sniffer that checks for the following strings: • *&password=*; *&txtPassword=*; *.moneybookers.*/*login.pl; *1and1.com/xml/config*; *4shared.com/login*; *:2082/login*; *:2083/login*; *:2086/login*; *:2222/CMD_LOGIN*; *alertpay.com/login*; *aol.*/*login.psp*; *bcointernacional*login*; *bigstring.*/*index.php*; *clave=*; *depositfiles.*/*/login*; *dotster.com/*login*; *dyndns*/account*; *enom.com/login*; *facebook.*/login.php*; *fastmail.*/mail/*; *fileserv.com/login*; *filesonic.com/*login*; *FLN-Password=*; *freakshare.com/login*; *gmx.*/*FormLogin*; *godaddy.com/login*; *google.*/*ServiceLoginAuth*; *hackforums.*/member.php; *hotfile.com/login*; *letitbit.net*; *login.live.*/*post.srf*; *login.Pass=*; *login.yahoo.*/*login*; *LoginPassword=*; *loginUserPassword=*; *login_pass=*; *login_password=*; *mediafire.com/*login*; *megaupload.*/*login*; *members*.iknowthatgirl*/members*; *members.brazzers.com*; *moniker.com/*Login*; *namecheap.com/*login*; *netflix.com/*ogin*; *netload.in/index*; *no-ip*/login*; *officebanking.cl/*login.asp*; *oron.com/login*; *pas=*; *pass=*; *passwd=*; *Passwd=*; *Password=*; *password=*; *password]=*; *paypal.*/webscr?cmd=_login-submit*; *runescape*/*weblogin*; *screenname.aol.*/login.psp*; *secure.logmein.*/*logincheck*; *sendspace.com/login*; *service=youtube*; *signin.ebay*SignIn; *sms4file.com/*/signin-do*; *speedyshare.com/login*; *steampowered*/login*; *TextfieldPassword=*; *thepiratebay.org/login*; *torrentleech.org/*login*; *twitter.com/sessions; *txtpass=*; *uploaded.to/*login*; *uploading.com/*login*; *vip-file.com/*/signin-do*; *webnames.ru/*user_login*; *what.cd/login*; *whcms*dologin*; *youporn.*/login*; 1and1; 4shared; Alertpay; AOL; Bcointernacional; BigString; Brazzers; clave; Depositfiles; Dotster; DynDNS; eBay; email; Email; EmailName; Enom; Facebook; Fastmail; Fileserve; Filesonic; FLN-Password; FLN-UserName; Freakshare; Gmail; GMX; Godaddy; Hackforums; Hotfile; IKnowThatGirl; Letitbit; Live; log; login; login.Pass; login.User; loginid; loginId; loginname; LoginPassword; LoginUserName; loginUserName; loginUserPassword; login[password]; login[username]; login_email; login_pass; login_password; LogMeIn; Mediafire; Megaupload; Moneybookers; Moniker; Namecheap; Netflix; Netload; NoIP; numeroTarjeta; OfficeBanking; Oron; pas; pass; passwd; Passwd; password; Password; PayPal; quick_password; quick_username; Runescape; rut; screenname; Sendspace; session[password]; session[username_or_email]; Sms4file; Speedyshare; Steam; TextfieldEmail; TextfieldPassword; Thepiratebay; token; Torrentleech; Twitter; txtEmail; txtpass; txtPassword; txtuser; Uploaded; Uploading; user; userid; username; Vip-file; Webnames; Whatcd; Yahoo; YouPorn; YouTube Injection – It injects itself as a remote thread into processes. All of the following processes: • explorer.exe; alg.exe; csrss.exe; services.exe; smss.exe; spoolsv.exe; svchost.exe; svchost.exe; svchost.exe; svchost.exe; svchost.exe; winlogon.exe; wuauclt.exe Purpose: Access to the following websites is effectively blocked: • *avast*; *avg*; *avira*; *bitdefender*; *bullguard*; *clamav*; *comodo*; *emsisoft*; *eset*; *f-secure*; *fortinet*; *garyshood*; *gdatasoftware*; *heck*tc; *iseclab*; *jotti*; *kaspersky*; *lavasoft*; *malwarebytes*; *mcafee*; *norman*; *norton*; *novirusthanks*; *onecare*live*; *onlinemalwarescanner*; *pandasecurity*; *precisesecurity*; *sophos*; *sunbeltsoftware*; *symantec; *threatexpert*; *trendmicro*; *virscan*; *virus*; *virusbuster*nprotect*; *viruschief*; *virustotal*; *webroot* Miscellaneous Accesses internet resources: • rapidshare.com:443 • server.buy-host.com:443 • http://api.wipmania.com/
Description inserted by Andrei Ilie on Wednesday, August 10, 2011 Description updated by Andrei Ilie on Wednesday, August 10, 2011
Back
.
.
.
.