Virus: TR/Kazy.331776 Date discovered: 20/05/2011 Type: Trojan In the wild: Yes Reported Infections: Low Distribution Potential: Low Damage Potential: Low to medium Static file: Yes File size: 331.776 Bytes MD5 checksum: 25601D8D71A9C410F6C29AF2BF8DD027 VDF version: 7.11.08.85 - Friday, May 20, 2011IVDF version: 7.11.08.85 - Friday, May 20, 2011
General Method of propagation: • No own spreading routine Aliases: • TrendMicro: TROJ_FAKEAL.SMQP • Sophos: Mal/FakeAV-JR • Microsoft: Rogue:Win32/FakeRean Platforms / OS: • Windows 2000 • Windows XP • Windows 2003 • Windows Vista • Windows 7 Side effects: • Blocks access to security websites • Drops files • Lowers security settings • Registry modification Right after execution the following information is displayed: Files It copies itself to the following location: • %HOME%\Local Settings\Application Data\%random character string% .exe It deletes the initially executed copy of itself. The following files are created: – %TEMPDIR% \%random character string% – %ALLUSERSPROFILE%\Application Data\%random character string% – %HOME%\Local Settings\Application Data\%random character string% – %TEMPDIR% \%random character string% – %HOME%\Templates\%random character string% Registry The following registry keys are added: – [HKLM\SYSTEM\ControlSet001\Services\SharedAccess\Parameters\ FirewallPolicy\StandardProfile] • "DoNotAllowExceptions"=dword:00000000 • "EnableFirewall"=dword:00000000 • "DisableNotifications"=dword:00000001 – [HKLM\SYSTEM\ControlSet001\Services\SharedAccess\Parameters\ FirewallPolicy\DomainProfile] • "EnableFirewall"=dword:00000000 • "DoNotAllowExceptions"=dword:00000000 • "DisableNotifications"=dword:00000001 – [HKCU\Software\Microsoft\Windows\CurrentVersion\Run] • "ctfmon.exe"="%SYSDIR% \ctfmon.exe" – [HKCR\.exe\shell\open\command] • "(Default)"="\"%HOME%\Local Settings\Application Data\\%random character string% .exe\" -a \"%1\" %*" • "IsolatedCommand"="\"%1\" %*" – [HKCR\exefile\shell\open\command] • "(Default)"="\"%HOME%\Local Settings\Application Data\\%random character string% .exe\" -a \"%1\" %*" • "IsolatedCommand"="\"%1\" %*" – [HKCR\exefile\shell\runas\command] • "(Default)"="\"%1\" %*" • "IsolatedCommand"="\"%1\" %*" – [HKLM\SOFTWARE\Clients\StartMenuInternet\IEXPLORE.EXE\shell\open\ command] • "(Default)"="\"%HOME%\Local Settings\Application Data\\%random character string% .exe\" -a \"%PROGRAM FILES% \Intern" The following registry key is changed: – [HKLM\SOFTWARE\Microsoft\Security Center] New value: • "AntiVirusDisableNotify"=dword:00000001 • "FirewallDisableNotify"=dword:00000001 • "FirewallOverride"=dword:00000001 • "UpdatesDisableNotify"=dword:00000001 • "AntiVirusOverride"=dword:00000001 Injection – It injects itself as a remote thread into a process. Process name: • iexplore.exe Miscellaneous Accesses internet resources: • **********ihudamaqyr.com/%several random digits% ; **********adovykavo.com/%several random digits% ; **********ehukalyna.com/%several random digits% ; **********yrizyp.com/%several random digits% ; **********ovajisem.com/%several random digits% ; **********erecus.com/%several random digits% ; **********yzykuboqo.com/%several random digits% ; **********otarohoc.com/%several random digits% ; **********ynefusawi.com/%several random digits% ; **********ehujosyp.com/%several random digits% ; **********anipuw.com/%several random digits% ; **********agexyz.com/%several random digits% ; **********ebenirahu.com/%several random digits% ; **********ukopomiva.com/%several random digits% ; **********ireracy.com/%several random digits% ; **********anatapum.com/%several random digits% ; **********support-2011.com/%several random digits% ; **********mium-support2011.com/%several random digits% ; **********upport-2011.com/%several random digits% ; **********ivirussupport2011.com/%several random digits% ; **********ivirus-support2011.com/%several random digits% ; **********support2011.com/%several random digits% ; **********upport2011.com/%several random digits% ; **********hukyq.com/%several random digits% ; **********cewyfyxut.com/%several random digits% ; **********walulas.com/%several random digits% ; **********mokowe.com/%several random digits% ; **********okowe.com/%several random digits% ; **********okowe.com/%several random digits% ; **********okowe.com/%several random digits% ; **********ilezavyxiro.com/%several random digits% ; **********ovatywo.com/%several random digits% ; **********akidukojoz.com/%several random digits% ; **********agyjaj.com/%several random digits% ; **********ojafadezy.com/%several random digits% ; **********evaviqopoci.com/%several random digits% ; **********otyger.com/%several random digits% ; **********afiduzipame.com/%several random digits% ; **********ojewedowigo.com/%several random digits% ; **********yxepomer.com/%several random digits% ; **********ahanybyvu.com/%several random digits% ; **********akydugudi.com/%several random digits% ; **********ugypenihyf.com/%several random digits% ; **********ybobik.com/%several random digits% ; **********okatahinery.com/%several random digits% ; **********icaraso.com/%several random digits% ; **********osahule.com/%several random digits% ; **********uzajylot.com/%several random digits% ; **********onevetode.com/%several random digits% ; **********atesomyz.com/%several random digits% ; **********ofymela.com/%several random digits% ; **********uponip.com/%several random digits% ; **********ovasuced.com/%several random digits% ; **********oduhisegu.com/%several random digits% ; **********editacif.com/%several random digits% ; **********emehypuq.com/%several random digits% ; **********yxaqunowy.com/%several random digits% ; **********ovexidysopy.com/%several random digits% ; **********ecebyt.com/%several random digits% ; **********esexyzobuz.com/%several random digits% ; **********ijinymut.com/%several random digits% ; **********evanyxora.com/%several random digits% ; **********ixydyf.com/%several random digits% ; **********usaseda.com/%several random digits% ; **********udizoni.com/%several random digits% ; **********ejutyhyfu.com/%several random digits% ; **********ygizeq.com/%several random digits% ; **********ehiqino.com/%several random digits% ; **********ynufyk.com/%several random digits% ; **********ibipaj.com/%several random digits% ; **********ityvik.com/%several random digits% ; **********olalat.com/%several random digits% ; **********yziriryvi.com/%several random digits% ; **********idehecyty.com/%several random digits% ; **********uwemixonav.com/%several random digits% ; **********inolecowary.com/%several random digits% ; **********upowibi.com/%several random digits% ; **********isesyf.com/%several random digits% ; **********exynogemi.com/%several random digits% ; **********evepapucof.com/%several random digits% ; **********igomyqeg.com/%several random digits% ; **********emolezala.com/%several random digits% ; **********unemymyko.com/%several random digits% ; **********onabubi.com/%several random digits% ; **********oripuqoxyl.com/%several random digits% ; **********elaticik.com/%several random digits% ; **********exyhun.com/%several random digits% ; **********ofociv.com/%several random digits% ; **********ebihyku.com/%several random digits% ; **********yjajutava.com/%several random digits% Mutex: It creates the following Mutex: • ir4cnxm3oi333
Descripción insertada por Andrei Ilie el viernes, 26 de agosto de 2011 Descripción actualizada por Andrei Ilie el viernes, 26 de agosto de 2011
Volver
.
.
.
.