Nume: TR/PSW.Steal.46592 Descoperit pe data de: 03/11/2006 Tip: Troian ITW: Nu Numar infectii raportate: Scazut Potential de raspandire: Scazut Potential de distrugere: Mediu Fisier static: Da Marime: 94.208 Bytes MD5: 50dd1445ede1d7aa737a7943a6440811 Versiune VDF: 6.36.00.207 Versiune IVDF: 6.36.00.231 - viernes 3 de noviembre de 2006
General Metoda de raspandire: • Nu are rutina proprie de raspandire Alias: • Kaspersky: Trojan-Spy.Win32.Banker.cew • F-Secure: Trojan-Spy.Win32.Banker.cew • Sophos: Troj/Nethell-G Sistem de operare: • Windows 98 • Windows 98 SE • Windows NT • Windows ME • Windows 2000 • Windows XP • Windows 2003 Efecte secundare: • Creeaza un fisier • Creeaza un fisier malware • Inregistreaza intrarile de la tastatura • Modificari in registri • Sustrage informatii Fisiere Sterge copia initiala a virusului. Sunt create fisierele: – %SYSDIR%\nethelper.xml – %SYSDIR%\commandhelper.xml – %SYSDIR%\conf.dat – %SYSDIR%\nethelper.dll Analiza ulterioara a relevat ca si acest fisier este malware. Detectat ca: TR/PSW.Steal.46592 – %SYSDIR%\accs.txt Acest fisier stocheaza datele introduse de utilizator la tastatura. – %SYSDIR%\fulllog.txt Acest fisier stocheaza datele introduse de utilizator la tastatura. – %SYSDIR%\log.txt Acest fisier stocheaza datele introduse de utilizator la tastatura. Registrii sistemului Inregistreaza un browser helper object (BHO) prin adaugarea urmatoarei chei in registri: – [HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\ Browser Helper Objects\{1593C741-C011-46FE-99FC-3805C28328BA}] Urmatoarele chei sunt adaugate in registrii sistemului: – [HKCR\NetHelper.Hook] • @="Hook Class" – [HKCR\NetHelper.Hook\CLSID] • @="{1593C741-C011-46FE-99FC-3805C28328BA}" – [HKCR\NetHelper.Hook\CurVer] • @="NetHelper.Hook.1" – [HKCR\NetHelper.Hook.1] • @="Hook Class" – [HKCR\NetHelper.Hook.1\CLSID] • @="{1593C741-C011-46FE-99FC-3805C28328BA}" – [HKCR\CLSID\{1593C741-C011-46FE-99FC-3805C28328BA}] • @="Hook Class" – [HKCR\CLSID\{1593C741-C011-46FE-99FC-3805C28328BA}\InprocServer32] • @="%SYSDIR%\nethelper.dll" • "ThreadingModel"="Apartment" – [HKCR\CLSID\{1593C741-C011-46FE-99FC-3805C28328BA}\ProgID] • @="NetHelper.Hook.1" – [HKCR\CLSID\{1593C741-C011-46FE-99FC-3805C28328BA}\Programmable] – [HKCR\CLSID\{1593C741-C011-46FE-99FC-3805C28328BA}\TypeLib] • @="{0324D9F1-2199-4424-98C7-A0E8CC45743B}" – [HKCR\CLSID\{1593C741-C011-46FE-99FC-3805C28328BA}\ VersionIndependentProgID] • @="NetHelper.Hook" – [HKCR\TypeLib\{0324D9F1-2199-4424-98C7-A0E8CC45743B}] – [HKCR\TypeLib\{0324D9F1-2199-4424-98C7-A0E8CC45743B}\1.0] • @="NetHelper 1.0 Type Library" – [HKCR\TypeLib\{0324D9F1-2199-4424-98C7-A0E8CC45743B}\1.0\0] – [HKCR\TypeLib\{0324D9F1-2199-4424-98C7-A0E8CC45743B}\1.0\0\win32] • @="%SYSDIR%\nethelper.dll" – [HKCR\TypeLib\{0324D9F1-2199-4424-98C7-A0E8CC45743B}\1.0\FLAGS] • @="0" – [HKCR\TypeLib\{0324D9F1-2199-4424-98C7-A0E8CC45743B}\1.0\HELPDIR] • @="%SYSDIR%\" – [HKCR\Interface\{54DCBD5A-3FDC-490F-B9AE-5B9DBAA39BEC}] • @="IHook" – [HKCR\Interface\{54DCBD5A-3FDC-490F-B9AE-5B9DBAA39BEC}\ ProxyStubClsid] • @="{00020424-0000-0000-C000-000000000046}" – [HKCR\Interface\{54DCBD5A-3FDC-490F-B9AE-5B9DBAA39BEC}\ ProxyStubClsid32] • @="{00020424-0000-0000-C000-000000000046}" – [HKCR\Interface\{54DCBD5A-3FDC-490F-B9AE-5B9DBAA39BEC}\TypeLib] • @="{0324D9F1-2199-4424-98C7-A0E8CC45743B}" • "Version"="1.0" Backdoor Servere contactate: Urmatoarele: • http://noviid.com/********** • http://noviid.com/********** • http://noviid.com/********** • http://noviid.com/********** • http://noviid.com/********** • http://noviid.com/********** Astfel se pot transmite informatii. Aceasta se face printr-o interogare HTTP GET intr-un script PHP. Trimte informatii despre: • Informatiile colectate, descrise in sectiunea Furt de informatii Incearca sa obtina urmatoarele informatii: – Informatii despre contul de email, obtinute din cheia de registru: HKCU\SoftwareMicrosoft\Internet Account Manager\Accounts – O rutina de logare este pornita dupa ce unul din urmatoarele site-uri este vizitat: • https://www3.netbank.commbank.com.au/netbank/bankmain • ib.national.com.au/nabib/loginProcess.ctl • www.national.au – Face captura la: • Informatii de logare Detaliile fisierului Limbaj de programare: Limbaj de programare folosit: C (compilat cu Microsoft Visual C++).
Descripción insertada por Adriana Popa el lunes 6 de noviembre de 2006 Descripción actualizada por Adriana Popa el martes 7 de noviembre de 2006
Volver
.
.
.
.