Nume:TR/PSW.Steal.46592
Descoperit pe data de:03/11/2006
Tip:Troian
ITW:Nu
Numar infectii raportate:Scazut
Potential de raspandire:Scazut
Potential de distrugere:Mediu
Fisier static:Da
Marime:94.208 Bytes
MD5:50dd1445ede1d7aa737a7943a6440811
Versiune VDF:6.36.00.207
Versiune IVDF:6.36.00.231 - viernes 3 de noviembre de 2006

 General Metoda de raspandire:
   • Nu are rutina proprie de raspandire


Alias:
   •  Kaspersky: Trojan-Spy.Win32.Banker.cew
   •  F-Secure: Trojan-Spy.Win32.Banker.cew
   •  Sophos: Troj/Nethell-G


Sistem de operare:
   • Windows 98
   • Windows 98 SE
   • Windows NT
   • Windows ME
   • Windows 2000
   • Windows XP
   • Windows 2003


Efecte secundare:
   • Creeaza un fisier
   • Creeaza un fisier malware
   • Inregistreaza intrarile de la tastatura
   • Modificari in registri
   • Sustrage informatii

 Fisiere Sterge copia initiala a virusului.



Sunt create fisierele:

– %SYSDIR%\nethelper.xml
– %SYSDIR%\commandhelper.xml
– %SYSDIR%\conf.dat
– %SYSDIR%\nethelper.dll Analiza ulterioara a relevat ca si acest fisier este malware. Detectat ca: TR/PSW.Steal.46592

– %SYSDIR%\accs.txt Acest fisier stocheaza datele introduse de utilizator la tastatura.
– %SYSDIR%\fulllog.txt Acest fisier stocheaza datele introduse de utilizator la tastatura.
– %SYSDIR%\log.txt Acest fisier stocheaza datele introduse de utilizator la tastatura.

 Registrii sistemului Inregistreaza un browser helper object (BHO) prin adaugarea urmatoarei chei in registri:

– [HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\
   Browser Helper Objects\{1593C741-C011-46FE-99FC-3805C28328BA}]


Urmatoarele chei sunt adaugate in registrii sistemului:

– [HKCR\NetHelper.Hook]
   • @="Hook Class"

– [HKCR\NetHelper.Hook\CLSID]
   • @="{1593C741-C011-46FE-99FC-3805C28328BA}"

– [HKCR\NetHelper.Hook\CurVer]
   • @="NetHelper.Hook.1"

– [HKCR\NetHelper.Hook.1]
   • @="Hook Class"

– [HKCR\NetHelper.Hook.1\CLSID]
   • @="{1593C741-C011-46FE-99FC-3805C28328BA}"

– [HKCR\CLSID\{1593C741-C011-46FE-99FC-3805C28328BA}]
   • @="Hook Class"

– [HKCR\CLSID\{1593C741-C011-46FE-99FC-3805C28328BA}\InprocServer32]
   • @="%SYSDIR%\nethelper.dll"
   • "ThreadingModel"="Apartment"

– [HKCR\CLSID\{1593C741-C011-46FE-99FC-3805C28328BA}\ProgID]
   • @="NetHelper.Hook.1"

– [HKCR\CLSID\{1593C741-C011-46FE-99FC-3805C28328BA}\Programmable]
– [HKCR\CLSID\{1593C741-C011-46FE-99FC-3805C28328BA}\TypeLib]
   • @="{0324D9F1-2199-4424-98C7-A0E8CC45743B}"

– [HKCR\CLSID\{1593C741-C011-46FE-99FC-3805C28328BA}\
   VersionIndependentProgID]
   • @="NetHelper.Hook"

– [HKCR\TypeLib\{0324D9F1-2199-4424-98C7-A0E8CC45743B}]
– [HKCR\TypeLib\{0324D9F1-2199-4424-98C7-A0E8CC45743B}\1.0]
   • @="NetHelper 1.0 Type Library"

– [HKCR\TypeLib\{0324D9F1-2199-4424-98C7-A0E8CC45743B}\1.0\0]
– [HKCR\TypeLib\{0324D9F1-2199-4424-98C7-A0E8CC45743B}\1.0\0\win32]
   • @="%SYSDIR%\nethelper.dll"

– [HKCR\TypeLib\{0324D9F1-2199-4424-98C7-A0E8CC45743B}\1.0\FLAGS]
   • @="0"

– [HKCR\TypeLib\{0324D9F1-2199-4424-98C7-A0E8CC45743B}\1.0\HELPDIR]
   • @="%SYSDIR%\"

– [HKCR\Interface\{54DCBD5A-3FDC-490F-B9AE-5B9DBAA39BEC}]
   • @="IHook"

– [HKCR\Interface\{54DCBD5A-3FDC-490F-B9AE-5B9DBAA39BEC}\
   ProxyStubClsid]
   • @="{00020424-0000-0000-C000-000000000046}"

– [HKCR\Interface\{54DCBD5A-3FDC-490F-B9AE-5B9DBAA39BEC}\
   ProxyStubClsid32]
   • @="{00020424-0000-0000-C000-000000000046}"

– [HKCR\Interface\{54DCBD5A-3FDC-490F-B9AE-5B9DBAA39BEC}\TypeLib]
   • @="{0324D9F1-2199-4424-98C7-A0E8CC45743B}"
   • "Version"="1.0"

 Backdoor Servere contactate:
Urmatoarele:
   • http://noviid.com/**********
   • http://noviid.com/**********
   • http://noviid.com/**********
   • http://noviid.com/**********
   • http://noviid.com/**********
   • http://noviid.com/**********

Astfel se pot transmite informatii. Aceasta se face printr-o interogare HTTP GET intr-un script PHP.


Trimte informatii despre:
    • Informatiile colectate, descrise in sectiunea

 Furt de informatii Incearca sa obtina urmatoarele informatii:
– Informatii despre contul de email, obtinute din cheia de registru: HKCU\SoftwareMicrosoft\Internet Account Manager\Accounts

– O rutina de logare este pornita dupa ce unul din urmatoarele site-uri este vizitat:
   • https://www3.netbank.commbank.com.au/netbank/bankmain
   • ib.national.com.au/nabib/loginProcess.ctl
   • www.national.au

– Face captura la:
    • Informatii de logare

 Detaliile fisierului Limbaj de programare:
Limbaj de programare folosit: C (compilat cu Microsoft Visual C++).

Descripción insertada por Adriana Popa el lunes 6 de noviembre de 2006
Descripción actualizada por Adriana Popa el martes 7 de noviembre de 2006

Volver . . . .