This file infector may be dropped by other malware. It may be unknowingly downloaded by a user while visiting malicious websites.
File size: Varies
File type: PE
Memory resident: Yes
Initial samples received date: 12 Jul 2010
Arrival Details
This file infector may be dropped by other malware.
It may be unknowingly downloaded by a user while visiting malicious websites.
Installation
This file infector injects codes into the following process(es):
Other System Modifications
This file infector creates the following registry entry(ies) to bypass Windows Firewall:
HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\
Services\SharedAccess\Parameters\
FirewallPolicy\DomainProfile\AuthorizedApplications\
List
\??\%System%\winlogon.exe = \??\%System%\winlogon.exe:*:enabled:@shell32.dll,-1
File Infection
This file infector infects the following file types:
It avoids infecting files that contain the following strings in their names:
It avoids infecting the following files:
- .DLL files
- PE Files with "_win" section name
- Files with infection marker
HOSTS File Modification
This file infector adds the following strings to the Windows HOSTS file:
- 127.0.0.1 {BLOCKED}L.chura.pl
Other Details
Based on analysis of the codes, it has the following capabilities:
- Connects to any of the following IRC servers using port 80:
- {BLOCKED}c.zief.pl
- {BLOCKED}m.ircgalaxy.pl
- Connects to the said servers using 8-randomly generated character for its NICK and 1-randomly generated character for its USER. Once connected, it joins a certain channel to receive and execute commands on the affected system. As of this writing, the servers reply with a command to download the following file:
- http://{BLOCKED}a.com/kb9.txt - detected by Trend Micro as TROJ_DLOAD.JKZQ
This file is saved as temp files in %User Temp% folder. This file infector then executes the downloaded file. As a result, malicious routines of the downloaded file are exhibited on the affected system. - Performs DNS request to the following site which is inaccessible as of writing:
- Hooks the following APIs so that when these APIs are called, the malware code is executed which then infects files:
- NtCreateFile
- NtOpenFile
- NtCreateProcess
- NtCreateProcessEx
- NtQueryInformationProcess
- Infects script files by first checking if the target script file's extension name is any of the following:.
- Once it finds target script files, it creates a flag for the file for iFrame infection. It opens flagged files, then checks for a certain string in the file. If it finds that string, it skips the file. If not, then it proceeds with the infection of the file.
- Looks for the string < /BODY > in the target script file. Once found, it infects script files by inserting the malicious IFRAME code below: Infected script files are detected as HTML_IFRME.QAWA. Trend Micro detects the infected files (EXE/SCR) as either PE_VIRUX.J, PE_VIRUX.N-3, and PE_VIRUX.AA.
- Returns execution to the HOST file's original code after execution of its routines.
Connect with us on
| | | |