DHL Tracking Number 3YMH6JJY contains trojan


MX Lab intercepted a large amount of emails with the subject “DHL Tracking Number 3YMH6JJY” containing the trojan TrojanDownloader:Win32/Cutwail.gen!C (Microsoft), Trojan.Kobka.E (GData), AVG (SHeur2.BQSN() or Troj/Agent-LQA (Sophos).

The contents of the email:

Dear customer!

The courier company was not able to deliver your parcel by your address.

You may pickup the parcel at our post office personaly.

The shipping label is attached to this e-mail.
Please print this label to get this package at our post office.

Thank you for attention.
DHL Express Services.

The attachment is named 3YMH6JJY.zip and contains the file 3YMH6JJY.exe, 56 kB big. The threat has the characteristics of ZBot, a trojan that disables firewall, steals sensitive financial data makes screen snapshots, downloads additional components, and provides a hacker with the remote access to the compromised system. The trojan can communicate with a remote SMTP server for sending out emails.

The following files are being created:

c:\2.tmp
c:\6.tmp
%AppData%\wiaservg.log
%Temp%\2515696084.exe
%Temp%\b2jp5k.exe
%Temp%\debug.exe
%Temp%\services.exe
%Temp%\svchost.exe
%Temp%\taskmgr.exe
%Temp%\win32.exe
%Temp%\winamp.exe
%Temp%\g260h.exe
%Temp%\habnf88jkefh87ifiks.tmp
%Temp%\jisfije9fjoiee.tmp
%Temp%\ogxyx.exe
%Temp%\pskfo83wijf89uwuhal8.tmp
%UserProfile%\reader_s.exe
%System%\reader_s.exe
%System%\dllcache\ndis.sys
%System%\ntos.exe
%System%\p2hhr.bat
%System%\wbem\grpconv.exe
%System%\wbem\Performance\WmiApRpl_new.ini
%System%\wsnpoem\audio.dll
%System%\wsnpoem\video.dll
%System%\z7v89qurrt.dll

The following file was deleted: %System%\grpconv.exe.
The following file was modified: %System%\drivers\ndis.sys.
The following directory was created: %System%\wsnpoem.

Following processes are created:

%System%\reader_s.exe
%UserProfile%\reader_s.exe
%Temp%\g260h.exe
%Temp%\winamp.exe
%Temp%\services.exe
%Temp%\svchost.exe
%Temp%\ogxyx.exe

A new memory page created in the address space of the system process(es): %System%\svchost.exe.
The following module was loaded into the address space of other process(es): %System%\z7v89qurrt.dll with process name: IEXPLORE.EXE.

Connections to remore hosts:

12.191.105.50 port 25
12.49.129.230 port 25
207.58.165.84 port 25
209.128.32.160 port 25
209.181.247.105 port 25
209.85.135.27 port 25
216.130.106.200 port 25
24.106.49.86 port 25
62.72.96.41 port 25
64.183.119.211 port 25
72.9.145.85 port 80
94.75.207.170 port 80
94.75.228.136 port 80
78.159.121.41 port 38811

The following URLs are requested from the remote web server:

* hxxp://www.panel911.com/traffic/in.cgi?google2
* hxxp://virtualmits.com/ndw/vp1.php?id=1CA619795E68E12&ver=v10&er=S_wd_rd_we_re_
* hxxp://virtualmits.com/ndw/ndw.php?id=1CA619795E68E12&ver=v10&er=S_wd_rd_we_re_
* hxxp://virtualmits.com/ndw/ndw.php?id=1CA619795E68E12&ver=v12
* hxxp://virtualmits.com/ndw/ndw.php?id=1-1CA6197986CAB58&ver=v12
* hxxp://1job1.cn/us4/error
* hxxp://1job1.cn/us4/us4.php?1=computername_0001e9af&i=
* hxxp://1job1.cn/l/controller.php?action=bot&entity_list=&uid=3&first=1&guid=13441600&v=15&rnd=6293712
* hxxp://1job1.cn/us4/us4.php?2=computername_0001e9af&n=1&v=16778496&i=&s=0&sp=0&lcp=0&pr=0
* hxxp://1job1.cn/l/controller.php?action=report&guid=0&rnd=6293712&uid=3&entity=1257509694:unique_start
* hxxp://1job1.cn/l2/2.php
* hxxp://1job1.cn/l2/1.php
* hxxp://1job1.cn/us4/us4.exe
* hxxp://1job1.cn/x.exe
* hxxp://1job1.cn/l2/stat.php

SMTP traffic will be generated from following email addresses:

Virus Total permlink and MD5: 08ba612f05b0433a4a5ca2df4da38deb.

22 Responses to DHL Tracking Number 3YMH6JJY contains trojan

  1. al says:

    i just clicked on this attachment and of course as I clicked I realized what I’d done - but it was too late. how do I remove the malware from my computer? any help or pointers much appreciated. thank you.

  2. Terri says:

    Hi: I have the same issue. Norton email scanning was disabled by the virus, the TCP/IP was corrupted or removed, the network adapters were corrupted/removed. Did the fix suggested above work for you?

  3. yoyoyo says:

    no, it found something and wanted me to buy the full version in order to fix it…so they want just cash for nothing i guess….

  4. Terri says:

    Thanks for your reply. Nothing I’ve tried has worked either.

  5. Gerry says:

    Any news? I was fool enough to click on it (just because I am truly waiting for something from the DHL….) and now, its on my Pc. I’m trying to find something that could solve the problem, but nothing yet… I could use my laptop, not my pc….

  6. Stephen says:

    Had a user open and run the DHL attachment and infect her PC with this bug. Nod32 AV was running and up to date, but did not stop the infection of ndis.sys.

    Later Nod32 did alert to the presence of this bug though was unable to clean it out.
    I was able to find and buy Prevx 3.0 and install it after reading some good reviews on the web through google. This software could not automatically kill this bug, but within 12 hours I had a remote connection with their very competent technicians and together we were able to eradicate this difficult malware.

    They told me at the end of our remote session that better automated functions to remove this bug will be in Prevx very soon. I would rate them 5 stars for their help.

    • Terri says:

      Thanks for your post. Were your network adapters corrupted/removed by the virus? If so, did their tech support help you re-establish your internet connection?

  7. Keith says:

    I have the same variant on a machine im working on. sheur2.BQSN. It corrupted all the networking stack drivers killing all communication immediately after install, so it wasnt such a good trojan. A good trojan doesn’t kill its host!

    Im working on a fix now too.

    • Gerry says:

      Yeah, its nearly the same in my Pc. There is net on my Pc, so torrents could work, or updaters too, but the browsers are not working, and every net connection is damm slow. I’m not able to use the Win. restore points, since it sais that sorry, it cannot help to save the Pc, and no point appears.
      Nothing I tried help me - not even conflicker ecc. killers. New variant, maybe, damm.

  8. stane says:

    possible solution… I had restore system (tooles/system restore-win XP) than run mrt.exe from MS (windows-kb890830-v3.1.exe) and seems (for now) system is stable and network traffic is clear > wirhout sending packets to 78.159.121.41 port 38811

  9. stane says:

    oops, sorry for bad English

  10. stane says:

    and replace ndis.sys with ndis.sys from clean system

  11. Gerry says:

    I tried it, but nothing happends, the problem is the same. The only thing I’m not able to understand is how it affects my net connection. Sometimes, everytthing seems to be ok for a few minutes, and then the net simply collapses, and I haver a very limited connection. On my laptop, everything works fine.
    I just thinked that maybe these trojans and conefickers are responsible, however all crashes and problems started after a few minutes later whern I opened and clicked on the zip file. Still, as I see others don’t have such problems, and it don’t seems to be logical, that this stuff affects my net connection. But somehow, it does. Or the pc had some errors at the same time, when I downloaded the zip, I dunno.
    Bah, and I’m still waiting for my package from the DHL :D

  12. Stefs says:

    Hi there i have an awesome antivirus that warns me i never opened the attached ment but my antivirus is going beserk. Now i need to know is this trojan virus can it send personal information to the person that created this virus? Please let me know ASAP!

    • mxlab says:

      You will not be able to track the author of the virus and send him/her personal information. Let your anti virus remove the file from your system. It is recommended to remove malware.

      • Gerry says:

        Arright, and which anti virus or malaware remover could remove this threat? i’m using ESET Nod 32, and it don’t seems that the antivirus is able to found it.

  13. mxlab says:

    @Gerry:

    There is no general solution for all computers. Some users have succes by using an up to date anti virus and others will have to reinstall Windows. I’m also not an expert in removal but in prevention and protection so I won’t be able to help much.

    What you can try:

    * disable internet access on computer, if possible, to avoid automated downloads of other malware by trojan and/or
    * try installing an anti virus that does detect the trojan and can remove it
    * someone had used Prevx 3.0 and got some support for removing the malware (previous comment on this post)
    * try to use Spybot-S&D
    * search and try some malware removal tools, for ex http://www.f-secure.com/en_EMEA/security/security-lab/tools-and-services/removal-tools/ (only use tools from trusted companies)
    * search Google,….

    Some drastic measures if anything fails:

    * restore Windows from a restore point
    * restore Windows from a backup (mirrored copy, ghost or image backup) that is guaranteed virus free
    * format and reinstall Windows (backup your documents folder - make sure it is virus free)

    To be honest, I prefer the drastic measures. The time you spend on virus removal can be used on reinstalling your system - assuming you have a descent backup. Afterwards you can be sure your system is 100% vrus free again.

  14. Peter says:

    Hello all,

    I opened the mail but not the attachment, still during a system scan
    got a warning from scanner that a trojan Win32 containg file 3YMH6JJY
    has bee detected with request to move to the quarantine container.
    Did so and deleted item. After that another scan was done and clean,
    followed by two more scans using scanners from different suppliers.
    Also these did not find a trace of this trojan, so can I hope it/s gone or
    what do you think?

  15. sonia19 says:

    Remove AAV Trojan Patch or Ai Trojan Patch

    http://www.tips29.com/2009/01/remove-aav-trojan-patch-or-ai-trojan.html

Follow

Get every new post delivered to your Inbox.

Join 348 other followers

%d bloggers like this: