Bredolab trojan keeps on using DHL tracking emails to infect systems


MX Lab keeps on intercepting Bredolab variants where the DHL tracking story is present in the email.

The From address is Manager Reinaldo Pelletier <[email protected]>. The name of the person is choosen randomly and can be any combination of first and last name. The subject of the email is “DHL Express Services. Please get your parcel NR.37888″. The email contains the attachment DHL_Delivery_Label_089d97c.zip with DHL_Delivery_Label_089d97c.exe. Be aware, that the numbers in the filenames and subject can change randomly.

The body of the email:

Dear customer!

The courier company was not able to deliver your parcel by your address.
Cause: Error in shipping address.

You may pickup the parcel at our post office personaly!

Please attention!
The shipping label is attached to this e-mail.
Print this label to get this package at our post office.

Thank you for attention.
DHL Services.

At the time of writting, only 14 of the 41 AV engines detected the virus. Virus Total permlink and MD5: 7e4fd271218525ea87787edd4443ffae.

Letter from Ondernemings-Portaal België


My company Pixel Design and MX Lab received today a letter from Ondernemings-Portaal België, in Dutch, regarding our presence on their business portal http://www.ondernemings-portaal-belgie.be or http://www.portail-des-entreprises-de-belgique.be/.

The way this company works is more or less similar to the World Business Guide or Belgisch Internet Register (DAD). Page one is the introduction letter and page two is the registration form with the company details that will be used in the pubication.

The letter does state the following:

Indien de door ons ingevuld gegevens niet correct of onvolledig zouden zijn, hebt u de mogelijkheid om uw gegevens te corrigeren: de basisgegevensinvoer (naam, postcode, plaats) onder http://www.ondernemings-portaal-belgië submenu-item: registratie. Hiervoor worden geen kosten berekend!

For the non Dutch speaking readers, the above mentions that you can correct your basic details like name, zip and city on the web site without any costs.

Wilt u meer communicatiegegevens dan de basisgegevensinvoer publiceren, dan gebruikt u het bijgevoegde formulier en stuurt het aan ons terug. Aangezien wij geen kamer-aangesloten- of overheidsafhankelijke onderneming zijn, zijn er aan deze publicatie kosten verbonden.

If you want to publish more data than the basic details like name, zip and city then you need to take extra costs into account.

Indien u per vergissing als exploitant van een privé internet pagina werd aangeschreven of niet wenst gepubliceerd te worden, gelieve dit dan in het daartoe bestemde vak linksonder aan te duiden en het formulier aan ons terug te sturen.

If you don’t want your details published on their web site because your company does not exist anymore, you don’t want a publication or you are a private person, you need to mark this on the first paper and send this back to Ondernemings-Portaal België with the registration form.

Now here is catch. The place where you can mark that you don’t want to publish your basic details is on the first page. The registration form with your details is on page two. On page two you are asked to sign and put the date on it. Now, if they receive it and they throw page one in the trashcan - something you can’t check - you have signed their contract for publication. The ‘not publish’ option is not on their registration form so it can be abused.

The costs are not mentioned on the first page but is stated on the second page and this is € 987 per year and the contract is for 3 years! So be aware that this is a costly advertisment.

Beside that, when you are in dispute with the company be aware that their establishment is located in Germany under the name TVV Tele Verzeichnis Verlag GmbH, Hamburg, and that German law applies to the contract.

Unizo, the Union of Independent Entrepreneurs in Belgium, has dedicated a whole section on their web site regarding these advertising recruiters (site in Dutch) with lots of examples.

FakeRean masked in email from Microsoft


MX Lab intercepted some messages with the subject line “Conflicker.B Infection Alert” coming from “Microsoft Windows Agent” but with a spoofed from address.

The virus is known as Trojan-Downloader:W32/Fakerean.AG (F-Secure, Microsoft), W32/FakeAlert.SYY!tr.dldr (Fortinet) or Mal/EncPk-KP (Sophos).

This is the body of the message:

Dear Microsoft Customer,

Starting 18/10/2009 the ‘Conficker’ worm began infecting Microsoft customers unusually rapidly. Microsoft has been advised by your Internet provider that your network is infected.

To counteract further spread we advise removing the infection using an antispyware program. We are supplying all effected Windows Users with a free system scan in order to clean any files infected by the virus.

Please install attached file to start the scan. The process takes under a minute and will prevent your files from being compromised. We appreciate your prompt cooperation.

Regards,
Microsoft Windows Agent #2 (Hollis)
Microsoft Windows Computer Safety Division

The message starts with a reminder of the Conficker worm and this alone will scare some people. But read a little bit further - “Microsoft has been advised by your Internet provider that your network is infected.” - and you should see that this is clearly an attempt to fool computer users. Why on earth will your internet provider contact Microsoft to inform you regarding a virus infection on your computer? I don’t know, perhaps the ‘author’ has a good reason to suggest this.

This virus will, once installed, will create the following files %AppData%\lizkavd.exe, %AppData%\seres.exe , %AppData%\svcst.exe where %AppData% is a variable that refers to the file system directory that serves as a common repository for application-specific data. A typical path is C:\Documents and Settings\[UserName]\Application Data.

Other created files are %Temp%\tmpwr2, %Temp%\tmpwr3, %Temp%\tmpwr4, %Temp%\tmpwr5, %Temp%\tmpwr6 and %Temp%\tmpwr7.

The processes %AppData%\seres.exe and %AppData%\svcst.exe will be created and some Windows registry modifications are executed.

svcst.exe (%AppData%\svcst.exe) will use the UDP port 1050 on the system and connections to remote hosts on 64.237.55.39 and 66.79.188.115 on port 80 are established.

The data identified by the following URLs was then requested from the remote web server:

* hxxp://orav4abdustorabe.com/files/avp21_d_/_1_._d_
* hxxp://orav4abdustorabe.com/files/_AVE_._d_
* hxxp://orav4abdustorabe.com/files/_Add_._d_
* hxxp://orav4abdustorabe.com/files/_GUI_._d_
* hxxp://orav4abdustorabe.com/files/_SC_._d_
* hxxp://orav4abdustorabe.com/files/_Upd_._d_
* hxxp://ertanue5skayert.com/iM1ci0K5p8bj0KtZ4IKD7p/c3vM

Virus Total permlink and MD5:e6bc86359946024ea7547ae8e9915e61

New Bredolab variant detected


Messages with the subject line “Your order has been paid! Parcel NR.8314″ and attachment DHL_print_label_42bae.zip name, or similar, should be treated with caution. The ZIP file contains the virus W32/Bredolab!Generic (Authentium, F-Prot), W32/Obfuscated.D2!genr (Norman), Mal/Bredo-A (Sophos).

The body of the email:

Goodafternoon!

Thank you for shopping at our internet shop!
We have successfully received your payment.

Your order has been shipped to your billing address.

You have ordered ” Samsung X22 “

You can find your tracking number in attached to the e-mail document.
Please print the DHL label to get your package.

We hope you enjoy your order!

Virus Total permalink and MD5: caa17f78e301aae4f5424ba99ab1d827.

FakeRean trojan is using the same subject of the latest ZBot variant


MX Lab just intercepted an email with the subject “A new settings file for the jp@******.com has just been released”, similar to the latest ZBot variant, but with a major difference in distribution. This time the email conatins the ZIP archive install.zip with the executable install.exe.

Body of the email:

Dear user of the ****.com mailing service!

We are informing you that because of the security upgrade of the mailing service your mailbox jp@****.com settings were changed. In order to apply the new set of settings open zip attached file.

Best regards, ****.com Technical Support.

Further investigation shows us that this virus is listening to the name W32/FakeRean.A.gen!Eldorado (F-Prot), TrojanDownloader:Win32/FakeRean (Microsoft), W32/PackSpam.A!worm (Fortinet) or W32/FakeAV.AE!genr (Norman).

Virus Total permlink and MD5: 7d96ce7f588613f0343049918de70665. Only 15 of the 41 AV engines detected the trojan correctly. For more information regarding this tojan you could check out the Microsoft Malware Protection Center.

[Update - 16/10/2009 11:36 PM, local Belgian time]

The subject line changed to “Microsoft Outlook Notification for the ******.******@*****.be” and this is now the body of the email:

You have (6) New Message from Outlook Microsoft

- Please re-configure your Microsoft Outlook Again.
- Download attached setup file and install.

The trojan itself is still in the same ZIP archive and is around 50 kB large.

Virus Total permlink and MD5: 958e5d61d6617806f649946e02ff04c8. At Virus Total only 24 of the 41 AV engines detect the trojan so be carefull.

ZBot variant masked as settings file for MS Outlook


MX Lab has been tipped regarding a new 0-day email related virus by Alan Dougherty from the company Synergistix. Thanks for sharing this with us. MX Lab intercepted only one sample of the email so we had the possibility to investigate this.

The email comes from suport@****.com where **** stands for the domain that is being used in the recipient email address. This will make that the receiver thinks it is from the support department of his own company. Now, if you don’t have a support department it should be clear that this is spoofed and that the email must be handled as being suspicious. If you have a support department don’t accept the fact that they will give you instructions on how to install and run executables.

Possible subjects are :

A new settings file for the andre@****.com mailbox
The settings for the andre@****.com mailbox

The body of the email:

Dear user of the beweb.com mailing service!

We are informing you that because of the security upgrade of the mailing service your mailbox (andre@b****.com) settings were changed. In order to apply the new set of settings click on the following link:

hxxp://b****.com/owa/service_directory/settings.php?email=andre@b****.com=b****.com=andre

Best regards, beweb.com Technical Support.

The malware is not attached at the email but the inluded link will take you to a web site where you need to download the .exe file and apply the new settings. The malware listens to the names Trojan-Spy.Win32.Zbot.gen (F-Secure), Mal/Zbot-R (Sophos) or PWS:Win32/Zbot.gen!R (Microsoft). The file itself is about 92 kB big and has the name settings-file.exe.

Regarding ZBot: it is a trojan that disables firewall, steals sensitive financial data (credit card numbers, online banking login details), makes screen snapshots, downloads additional components, and provides a hacker with the remote access to the compromised system.

The trojan will create a file %System%\sdra64.exe and the hidden files %System%\lowsec\local.ds and %System%\lowsec\user.ds in combination with a hidden directory %System%\lowsec. There were new memory pages created in the address space of the system process(es): services.exe, lsass.exe, alg.exe, iexplore.exe and svchost.exe.

Several registry settings are modified and the trojan could make connection to a remote host on the IP 195.93.208.106 on port 80. Data requested is: hxxp://195.93.208.106/livs/rec.php, hxxp://195.93.208.106/lcc/ip1.gif and hxxp://195.93.208.106/ip.php.

In the sample from Alan Dougherty was the domain oikkkkuy.co.uk in use and ur sample contained bertdffm.co.uk. These domains are registered by the same licensee today and already offline. These are so called fast-flux domains.

With a typical domain, the IP address associated with the domain does not change often, if at all. Fast-flux domains use a large number of servers and a fast-changing domain A record to turn shutdown attempts into a game.

Domain name:
         bertdffm.co.uk
     Registrant:
         Evelyn Wilson
     Registrant type:
         Non-UK Individual
     Registrant's address:
         805 E. Stocker
         paris
         68554
         Belgium
     Registrar:
         Webfusion Ltd t/a 123-Reg.co.uk [Tag = 123-REG]
         URL: http://www.123-reg.co.uk
     Relevant dates:
         Registered on: 14-Oct-2009
         Renewal date:  14-Oct-2011
         Last updated:  14-Oct-2009
     Registration status:
         Registration request being processed.
     Name servers:
         No name servers listed.
     WHOIS lookup made at 16:46:50 14-Oct-2009

At the time of writing, Virus Total gives us the fact that only 6 of the 41 AV engines detect the new ZBot variant. Virus Total permlink and MD5: 06085157775a67575c8a40ba934af2d2.

[Update - 20/10/2009 - 4:25 PM Local Belgian time] Following domains are being used to host the malware:

bertdffm.co.uk
ffffexdl.co.uk
photo.net
polikkp.eu
nerrasssb.eu
nerassssp.co.uk
nerasssspt.co.uk
nerrasssx.eu
nerrasssy.eu
oikkkkuy.co.uk
opopio.co.uk
til1tlli.com
ttl1lll.com
ttl1lii.com
vvverfq.co.uk
vvverkp.co.uk

This will not be a full list of all malicious URLs.

For the domain nerrasssx.eu we have the following list of A records:

nerrasssx.eu.		1800	IN	A	91.141.19.106
nerrasssx.eu.		1800	IN	A	83.55.90.230
nerrasssx.eu.		1800	IN	A	77.105.4.79
nerrasssx.eu.		1800	IN	A	190.82.168.179
nerrasssx.eu.		1800	IN	A	85.65.48.188
nerrasssx.eu.		1800	IN	A	92.85.230.178
nerrasssx.eu.		1800	IN	A	190.16.45.45
nerrasssx.eu.		1800	IN	A	201.62.140.63
nerrasssx.eu.		1800	IN	A	190.245.16.36
nerrasssx.eu.		1800	IN	A	95.133.54.191
nerrasssx.eu.		1800	IN	A	89.173.151.200
nerrasssx.eu.		1800	IN	A	218.209.20.19
nerrasssx.eu.		1800	IN	A	78.30.202.143
nerrasssx.eu.		1800	IN	A	190.245.42.164
nerrasssx.eu.		1800	IN	A	95.209.138.179

For the domain nerrasssb.eu we have the following list of A records:

nerrasssb.eu.		1800	IN	A	95.133.54.191
nerrasssb.eu.		1800	IN	A	190.245.42.164
nerrasssb.eu.		1800	IN	A	201.62.140.63
nerrasssb.eu.		1800	IN	A	89.173.151.200
nerrasssb.eu.		1800	IN	A	190.16.45.45
nerrasssb.eu.		1800	IN	A	95.209.138.179
nerrasssb.eu.		1800	IN	A	83.55.90.230
nerrasssb.eu.		1800	IN	A	77.105.4.79
nerrasssb.eu.		1800	IN	A	92.85.230.178
nerrasssb.eu.		1800	IN	A	190.82.168.179
nerrasssb.eu.		1800	IN	A	91.141.19.106
nerrasssb.eu.		1800	IN	A	78.30.202.143
nerrasssb.eu.		1800	IN	A	85.65.48.188
nerrasssb.eu.		1800	IN	A	218.209.20.19
nerrasssb.eu.		1800	IN	A	190.245.16.36

Microsoft Security Bulletin with attached executable is malware with a nasty twitch


MX Lab intercepted a few emails from “Microsoft Security <*[email protected]>”, where * in the from address stands for random characters in a combination of letters and numbers, with the subject line “Important Security Update for Windows XP (KB932823)” with the attached file Windows Update.exe.

This is the body of the email:

Microsoft Security Bulletin Notification | Critical update and notification service software for genuine Microsoft (r) Windows operating system users.

As part of the monthly security bulletin release cycle, Microsoft provides the Microsoft Security Bulletin Notification Service Software.
This software is intended to help our customers effectively deploy security updates, and includes information about the number of new security updates being released,
the software affected, severity levels of vulnerabilities, and information about any detection tools relevant to the updates.

Please be asvised that this is a critical update affecting Microsoft (c) Windows (r) operating system family.

Note that the advance notification software will provide information about high-priority updates and install the updates that are released the same day as the security updates.
The advance notification software does not provide information about non-security updates released on other days.

Please download the attached bundle and install the Microsoft Advanced Notification and Malware Removal software

Instead of being malware removal software this is in fact malware that listens to the name W32/Trojan3.BHU (F-Prot), Trojan-Spy.Win32.Zbot.gen (Kaspersky) or Troj/Zbot-IC (Sophos).

The threat has the characteristics of ZBot - a banking trojan that disables firewall, steals sensitive financial data, makes screen snapshots, downloads additional components, and provides a hacker with the remote access to the compromised system. It is a rootkit trojan which steals online banking information and downloads other malware as well.

The service %System%\sdra64.exe, some hidden files %System%\lowsec\local.ds, %System%\lowsec\user.ds and %System%\lowsec\user.ds.lll are being created on an infected system.

As always some registry modifications will happen and for the following list of online banking site, the threat may compromise your access by injecting additional HTML code:

* https://www.gruposantander.es
* https://banking.*.de
* https://internetbanking.gad.de
* https://www.citibank.de
* https://www.us.hsbc.com
* https://www.e-gold.com
* https://online.wellsfargo.com
* https://www.wellsfargo.com
* https://www.paypal.com
* https://www#.usbank.com
* https://easyweb*.tdcanadatrust.com
* https://www#.citizensbankonline.com
* https://onlinebanking.nationalcity.com
* https://www.suntrust.com
* https://www.53.com
* https://web.da-us.citibank.com
* https://onlineeast#.bankofamerica.com
* https://online.wamu.com
* https://onlinebanking#.wachovia.com
* https://resources.chase.com
* https://bancaonline.openbank.es
* https://extranet.banesto.es
* https://banesnet.banesto.es
* https://empresas.gruposantander.es
* https://www.bbvanetoffice.com
* https://www.bancajaproximaempresas.com
* https://probanking.procreditbank.bg
* https://ibank.internationalbanking.barclays.com
* https://ibank.barclays.co.uk
* https://online-offshore.lloydstsb.com
* https://online-business.lloydstsb.co.uk
* http://www.hsbc.co.uk
* https://www.nwolb.com
* https://home.ybonline.co.uk
* https://home.cbonline.co.uk
* https://welcome27.co-operativebank.co.uk
* https://welcome23.smile.co.uk
* https://www.halifax-online.co.uk
* https://www2.bancopopular.es
* https://www.bancoherrero.com
* https://pastornetparticulares.bancopastor.es
* https://intelvia.cajamurcia.es
* https://www.caja-granada.es
* https://www.fibancmediolanum.es
* https://carnet.cajarioja.es
* https://www.cajalaboral.com
* https://www.cajasoldirecto.es
* https://www.clavenet.net
* https://www.cajavital.es
* https://banca.cajaen.es
* https://www.cajadeavila.es
* https://www.caixatarragona.es
* http://caixasabadell.net
* https://www.caixaontinyent.es
* https://www.caixalaietana.es
* https://www.cajacirculo.es
* https://areasegura.banif.es
* https://www.bgnetplus.com
* https://www.caixagirona.es
* https://www.unicaja.es
* https://www.sabadellatlantico.com
* https://oi.cajamadrid.es
* https://www.cajabadajoz.es
* https://montevia.elmonte.es
* https://www.cajacanarias.es
* https://oie.cajamadridempresas.es
* https://www.gruppocarige.it
* https://bancopostaonline.poste.it
* https://privati.internetbanking.bancaintesa.it
* https://hb.quiubi.it
* https://www.iwbank.it
* https://web.secservizi.it
* https://www.isideonline.it
* https://online*.lloydstsb.co.uk
* https://www.mybank.alliance-leicester.co.uk
* https://www.ebank.hsbc.co.uk
* https://www.isbank.com.tr
* https://light.webmoney.ru
* https://olb2.nationet.com
* https://www*.banking.first-direct.com
* https://cardsonline-consumer.com
* https://www.rbsdigital.com
* https://banking*.anz.com
* https://home2ae.cd.citibank.ae
* https://internetbanking.aib.ie
* https://lot-port.bcs.ru
* https://rupay.com
* http://*.osmp.ru
* https://www.uno-e.com
* https://www.ccm.es

When visiting your online bank service, the threat my inject additional fields in the login form with the goal to steal confidential information. Compromised forms may look like the following screens:

Virus Total permlink and MD5: ac9fe62b82080e405a9ffadb64bdcdf7.

Follow

Get every new post delivered to your Inbox.

Join 348 other followers