Sasfis trojan present in emails with subject Statement of fees 2009/2010
April 29, 2010
MX Lab intercepted messages with the subject “Statement of fees 2009/2010″ that contains the Sasfis trojan attached in a ZIP archive. The email is send from various spoofed email addresses and changes randomly.
Body of the email:
Please find attached a statement of fees as requested, this will be posted today.
The accommodation is dealt with by another section and I have passed your request on to them today.Kind regards.
Ramon Roberson
The attached ZIP archive has the name Statement_of_fees_2009_2010.zip and the extracted file has the name Statement_of_fees_2009_2010__[manyunderscores]_doc.exe. A large amount of underscores makes it more difficult to see that this file is in fact an executable.
The following files will be created:
%Temp%\1.tmp
%System%\thxr.wgo
%Temp%\2.tmp
The registry key “HKEY_LOCAL_MACHINE\SOFTWARE\Classes\idid” is created.
The registry key “[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon]” will be modified.
The trojan can establish a remote connection with the IP 174.120.228.122 and 193.105.174.108 on port 80 and retrieve data from:
* hxxp://www.brightspottech.com/loader_40.exe
* hxxp://hulejsoops.ru/images/bb.php?v=200&id=256235564&b=build001&tm=2
At the time of writing, only 10 of the 40 Av engines did detect the trojan. Virus Total permlink and MD5: b5e6830bb7836f776d5629291cc961a1
