live casino online

TSPY_ZBOT.EFNA

March 24, 2014
 Analysis by: Adrian Cofreros
 Modified by: Jimelle Monteser

 ALIASES:

a variant of Win32/Kryptik.BXCQ trojan (NOD32)

 PLATFORM:

Windows 2000, Windows Server 2003, Windows XP (32-bit, 64-bit), Windows Vista (32-bit, 64-bit), Windows 7 (32-bit, 64-bit)

 OVERALL RISK RATING:
 DAMAGE POTENTIAL:
 DISTRIBUTION POTENTIAL:
 REPORTED INFECTION:
 INFORMATION EXPOSURE:

  • Threat Type: Spyware

  • Destructiveness: No

  • Encrypted: Yes

  • In the wild: Yes

  OVERVIEW

Infection Channel:

Dropped by other malware, Downloaded from the Internet


This spyware arrives on a system as a file dropped by other malware or as a file downloaded unknowingly by users when visiting malicious sites.

It hides files, processes, and/or registry entries.

It steals certain information from the system and/or the user.

  TECHNICAL DETAILS

File Size:

499,712 bytes

File Type:

EXE

Memory Resident:

Yes

Initial Samples Received Date:

14 Mar 2014

Payload:

Steals information, Downloads files

Arrival Details

This spyware arrives on a system as a file dropped by other malware or as a file downloaded unknowingly by users when visiting malicious sites.

Installation

This spyware drops the following non-malicious files:

  • %Application Data%\Microsoft\Address Book\{user name}.wab
  • %Application Data%\{random filename 2}.{random}

(Note: %Application Data% is the current user's Application Data folder, which is usually C:\Documents and Settings\{user name}\Application Data on Windows 2000, XP, and Server 2003, or C:\Users\{user name}\AppData\Roaming on Windows Vista and 7.)

It drops the following copies of itself into the affected system:

  • %User Temp%\{random folder name}\{random filename 1}.exe

(Note: %User Temp% is the current user's Temp folder, which is usually C:\Documents and Settings\{user name}\Local Settings\Temp on Windows 2000, XP, and Server 2003, or C:\Users\{user name}\AppData\Local\Temp on Windows Vista and 7.)

It creates the following folders:

  • %Application Data%\Microsoft\Address Book
  • %User Temp%\{random folder name}

(Note: %Application Data% is the current user's Application Data folder, which is usually C:\Documents and Settings\{user name}\Application Data on Windows 2000, XP, and Server 2003, or C:\Users\{user name}\AppData\Roaming on Windows Vista and 7.. %User Temp% is the current user's Temp folder, which is usually C:\Documents and Settings\{user name}\Local Settings\Temp on Windows 2000, XP, and Server 2003, or C:\Users\{user name}\AppData\Local\Temp on Windows Vista and 7.)

It adds the following mutexes to ensure that only one of its copies runs at any one time:

  • Local\{GUID}
  • Global\{GUID}

It injects codes into the following process(es):

  • explorer.exe

Autostart Technique

This spyware adds the following registry entries to enable its automatic execution at every system startup:

HKEY_CURRENT_USER\Software\Microsoft\
Windows\CurrentVersion\Run
{random} = ""%User Temp%\{random folder name}\{random filename 1}.exe""

It registers its dropped component as a system service to ensure its automatic execution at every system startup. It does this by creating the following registry entries:

HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\
Services\{random}
Type = "1"

HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\
Services\{random}
Start = "1"

HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\
Services\{random}
ErrorControl = "0"

HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\
Services\{random}
ImagePath = "\??\%System%\drivers\{random}.sys"

HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\
Services\{random}\Security
Security = "{random values}"

It registers its dropped component as a system service to ensure its automatic execution at every system startup. It does this by creating the following registry keys:

HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\
Services\{random}

HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\
Services\{random}\Security

Other System Modifications

This spyware adds the following registry keys:

HKEY_CURRENT_USER\Software\Microsoft\
{random}

HKEY_CURRENT_USER\Software\Microsoft\
WAB

HKEY_CURRENT_USER\Software\Microsoft\
WAB\WAB4

HKEY_CURRENT_USER\Software\Microsoft\
WAB\WAB4\Wab File Name

It adds the following registry entries:

HKEY_CURRENT_USER\Software\Microsoft\
{random}
{random} = "{random}"

HKEY_CURRENT_USER\Software\Microsoft\
WAB\WAB4
OlkContactRefresh = "0"

HKEY_CURRENT_USER\Software\Microsoft\
WAB\WAB4
OlkFolderRefresh = "0"

HKEY_CURRENT_USER\Software\Microsoft\
WAB\WAB4\Wab File Name
(Default) = "%Application Data%\Microsoft\Address Book\{user name}.wab"

It creates the following registry entry(ies) to bypass Windows Firewall:

HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\
Services\SharedAccess\Parameters\
FirewallPolicy\StandardProfile\AuthorizedApplications\
List
%Windows%\explorer.exe = "%Windows%\explorer.exe:*:Enabled:Windows Explorer"

HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\
Services\SharedAccess\Parameters\
FirewallPolicy\StandardProfile\GloballyOpenPorts\
List
{random port 1}:UDP = "{random port 1}:UDP:*:Enabled:UDP {random port 1}"

HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\
Services\SharedAccess\Parameters\
FirewallPolicy\StandardProfile\GloballyOpenPorts\
List
{random port 2}:TCP = "{random port 2}:TCP:*:Enabled:TCP {random port 2}"

Rootkit Capabilities

This spyware hides files, processes, and/or registry entries.

Download Routine

This spyware connects to the following URL(s) to download its configuration file:

  • http://{random generated URL}

Information Theft

This spyware steals the following information:

  • Data on cookie files (URLs)
  • Email-related information such as account names, email addresses, passwords, server data, and server port
  • Email information stored in the user’s Windows Address Book (WAB) file
  • Online banking credentials
  • Personal digital cerificates

Other Details

This spyware connects to the following URL(s) to check for an Internet connection:

  • http://google.com
  • http://bing.com

It drops the following file(s)/component(s):

  • %System%\driver\{random}.sys - detected as RTKT_NECURS.BGSF

(Note: %System% is the Windows system folder, which is usually C:\Windows\System32.)

NOTES:

This spyware attempts to download its configuration file by connecting to randomly generated URL.

The configuration file may contain URLs where it downloads an updated copy of itself and where it sends its gathered information.

It may also contain URLs of its target online banking and finance-related sites from where it steals the information.

It also collects information when it finds the following strings in certain applications:

  • bancline
  • bankman
  • cruisenet
  • dirclt32.exe
  • episys
  • fastdoc
  • fdmaster.exe
  • fidelity
  • gplusmain
  • jack henry
  • launch[adshell.exe
  • micrsolv
  • pcsws.exe
  • prologue.exe
  • silverlake
  • tellerplus
  • v48d0250s1
  • vantiv
  • wtng.exe

  SOLUTION

Minimum Scan Engine:

9.700

FIRST VSAPI PATTERN FILE:

10.670.08

FIRST VSAPI PATTERN DATE:

18 Mar 2014

VSAPI OPR PATTERN File:

10.671.00

VSAPI OPR PATTERN Date:

18 Mar 2014

Step 1

Before doing any scans, Windows XP, Windows Vista, and Windows 7 users must to allow full scanning of their computers.

Step 2

Remove malware/grayware files dropped/downloaded by TSPY_ZBOT.EFNA