Vírus BDS/IRCBot.AQ Data em que surgiu: 30/11/2011 Tipo: Servidor Backdoor Incluído na lista "In The Wild" Não Nível de danos: Baixo Nível de distribuição: Baixo Nível de risco: Médio Tamanho: 422912 Bytes MD5 checksum: f4888616ec030455b529304453e190a6 Versão VDF: 7.11.18.139 - quarta-feira, 30 de novembro de 2011Versão IVDF: 7.11.18.139 - quarta-feira, 30 de novembro de 2011
Vulgarmente Meio de transmissão: • Não tem rotinas de propagação Alias: • Kaspersky: Trojan-Spy.MSIL.Agent.fof • Bitdefender: Trojan.Generic.5717619 • Microsoft: VirTool:MSIL/Injector.P • Grisoft: PSW.Generic8.CBQC • Eset: probably a variant of MSIL/Injector.CF trojan • GData: Trojan.Generic.5717619 • Norman: Trojan W32/Suspicious_Gen2.LKWMX Sistemas Operativos: • Windows 2000 • Windows XP • Windows 2003 • Windows Vista • Windows Server 2008 • Windows 7 Efeitos secundários: • Pode ser usado para modificar configurações do sistema que permitem ou aumentam o comportamento do malware em potencial. • Descarrega ficheiros • Altera o registo do Windows • Informação de roubos Ficheiros Autocopia-se para as seguintes localizações • %TEMPDIR% \%12 digit random character string%.exe • %APPDATA%\%12 digit random character string%.exe • %WINDIR% \install\winup32.exe Apaga a cópia executada inicialmente. Elimina os seguintes ficheiros: • %TEMPDIR% \%nome do computador% .txt • %TEMPDIR% \%nome do computador% 7 • %TEMPDIR% \%nome do computador% 8 São criados os seguintes ficheiros: – Ficheiro não malicioso: • %APPDATA%\%nome do computador% log.dat – %TEMPDIR% \delete.bat Além disso executa-se depois de gerado. Este ficheiro de processamento em lote é usado para apagar um ficheiro. Registry (Registo do Windows) Para cada chave de registo é adicionado um dos seguintes valores para executar os processos depois reinicializar: – [HKCU\Software\Microsoft\Windows\CurrentVersion\Run] • "Audio HD Driver"="%TEMPDIR% \\%12 digit random character string%.exe" – [HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Run] • "Audio HD Driver"="%TEMPDIR% \\%12 digit random character string%.exe" – [HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Run] • "HKLM"="c:\windows\\install\\winup32.exe" – [HKCU\Software\Microsoft\Windows\CurrentVersion\Run] • "HKCU"="c:\windows\\install\\winup32.exe" São adicionados os seguintes valores ao registo do Windows de forma a que os serviços sejam carregados depois do computador ser reiniciado: – [HKCU\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts\ .aif\OpenWithProgids] • (null) – [HKCU\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts\ .aifc\OpenWithProgids] • (null) – [HKCU\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts\ .aiff\OpenWithProgids] • (null) – [HKCU\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts\ .asf\OpenWithProgids] • (null) – [HKCU\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts\ .asx\OpenWithProgids] • (null) – [HKCU\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts\ .au\OpenWithProgids] • (null) – [HKCU\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts\ .avi\OpenWithProgids] • (null) – [HKCU\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts\ .bmp\OpenWithProgids] • (null) – [HKCU\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts\ .css\OpenWithProgids] • (null) – [HKCU\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts\ .dib\OpenWithProgids] • (null) – [HKCU\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts\ .doc\OpenWithProgids] • (null) – [HKCU\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts\ .dvr-ms\OpenWithProgids] • (null) – [HKCU\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts\ .emf\OpenWithProgids] • (null) – [HKCU\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts\ .gif\OpenWithProgids] • (null) – [HKCU\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts\ .htm\OpenWithProgids] • (null) – [HKCU\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts\ .html\OpenWithProgids] • (null) – [HKCU\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts\ .htm\OpenWithProgids] • (null) – [HKCU\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts\ .html\OpenWithProgids] • (null) – [HKCU\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts\ .ico\OpenWithProgids] • (null) – [HKCU\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts\ .IVF\OpenWithProgids] • (null) – [HKCU\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts\ .jfif\OpenWithProgids] • (null) – [HKCU\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts\ .jpe\OpenWithProgids] • (null) – [HKCU\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts\ .jpeg\OpenWithProgids] • (null) – [HKCU\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts\ .jpg\OpenWithProgids] • (null) – [HKCU\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts\ .m1v\OpenWithProgids] • (null) – [HKCU\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts\ .m3u\OpenWithProgids] • (null) – [HKCU\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts\ .mid\OpenWithProgids] • (null) – [HKCU\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts\ .midi\OpenWithProgids] • (null) – [HKCU\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts\ .mp2\OpenWithProgids] • (null) – [HKCU\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts\ .mp2v\OpenWithProgids] • (null) – [HKCU\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts\ .mp3\OpenWithProgids] • (null) – [HKCU\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts\ .mpa\OpenWithProgids] • (null) – [HKCU\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts\ .mpe\OpenWithProgids] • (null) – [HKCU\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts\ .mpeg\OpenWithProgids] • (null) – [HKCU\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts\ .mpg\OpenWithProgids] • (null) – [HKCU\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts\ .mpv2\OpenWithProgids] • (null) – [HKCU\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts\ .png\OpenWithProgids] • (null) – [HKCU\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts\ .rmi\OpenWithProgids] • (null) – [HKCU\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts\ .rtf\OpenWithProgids] • (null) – [HKCU\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts\ .snd\OpenWithProgids] • (null) – [HKCU\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts\ .tif\OpenWithProgids] • (null) – [HKCU\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts\ .tiff\OpenWithProgids] • (null) – [HKCU\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts\ .txt\OpenWithProgids] • (null) – [HKCU\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts\ .wav\OpenWithProgids] • (null) – [HKCU\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts\ .wax\OpenWithProgids] • (null) – [HKCU\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts\ .wm\OpenWithProgids] • (null) – [HKCU\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts\ .wma\OpenWithProgids] • (null) – [HKCU\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts\ .wmf\OpenWithProgids] • (null) – [HKCU\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts\ .wmv\OpenWithProgids] • (null) – [HKCU\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts\ .wmx\OpenWithProgids] • (null) – [HKCU\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts\ .wpl\OpenWithProgids] • (null) – [HKCU\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts\ .wri\OpenWithProgids] • (null) – [HKCU\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts\ .wvx\OpenWithProgids] • (null) – [HKCU\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts\ .xml\OpenWithProgids] • (null) – [HKCU\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts\ .xsl\OpenWithProgids] • (null) – [HKCU\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts\ .zip\OpenWithProgids] • (null) São adicionadas as seguintes chaves ao registo: – [HKLM\SOFTWARE\Microsoft\Active Setup\Installed Components\ {04P34X25-047M-8IOY-5N0F-0UD5J4UX071D}] • "StubPath"="c:\windows\\install\\winup32.exe Restart" – [HKCU\Software\pwNd b1tch] • "FirstExecution"="29/02/2012 -- 10:15" • "NewIdentification"="pwNd b1tch" • (null) – [HKLM\SOFTWARE\Microsoft\Active Setup\Installed Components\ {04P34X25-047M-8IOY-5N0F-0UD5J4UX071D}] • "StubPath"="c:\windows\\install\\winup32.exe" – [HKCU\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts\ .eml\OpenWithProgids] • (null) – [HKCU\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts\ .mht\OpenWithProgids] • (null) – [HKCU\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts\ .mhtml\OpenWithProgids] • (null) – [HKCU\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts\ .nws\OpenWithProgids] • (null) – [HKCU\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts\ .URL\OpenWithProgids] • (null) – [HKCU\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts\ .wdp\OpenWithProgids] • (null) – [HKCU\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts\ .wmp\OpenWithProgids] • (null) O seguinte valor do registo é alterado: – [HKCU\Software\Microsoft\Windows\CurrentVersion\Explorer\Advanced] Valor anterior: • "Hidden"=dword:00000001 Valor recente: • "Hidden"=dword:00000002 Backdoor Contacta o servidor: Seguinte: • **********.zapto.org Envia informação sobre: • Palavras-chave armazenadas • Informação recolhida na secção de roubos. Informações diversas Manipulador de eventos: Cria o seguinte Manipulador de eventos: • ReadProcessMemory • WriteProcessMemory • SetWindowsHook • CreateRemoteThread • CopyFile • CreateProcess • CreateFile • GetWindowsDirectory • GetSystemDirectory • LsaRetrievePrivateData • RasDefaultCredentials • LookupAccountName • CredEnumerate • CryptUnprotectData • PStoreCreateInstance Texto: Além disso contém os seguintes blocos de texto: • pstorec.dll • WindowsLive:name • rasphone.pbk
Descrição enviada por Wensin Lee em
segunda-feira, 2 de abril de 2012 Descrição atualizada por Wensin Lee em
segunda-feira, 2 de abril de 2012
Voltar
.
.
.
.