Sasfis trojan present in emails with subject Statement of fees 2009/2010


MX Lab intercepted messages with the subject “Statement of fees 2009/2010″ that contains the Sasfis trojan attached in a ZIP archive. The email is send from various spoofed email addresses and changes randomly.

Body of the email:

Please find attached a statement of fees as requested, this will be posted today.
The accommodation is dealt with by another section and I have passed your request on to them today.

Kind regards.
Ramon Roberson

The attached ZIP archive has the name Statement_of_fees_2009_2010.zip and the extracted file has the name Statement_of_fees_2009_2010__[manyunderscores]_doc.exe. A large amount of underscores makes it more difficult to see that this file is in fact an executable.

The following files will be created:

%Temp%\1.tmp
%System%\thxr.wgo
%Temp%\2.tmp

The registry key “HKEY_LOCAL_MACHINE\SOFTWARE\Classes\idid” is created.
The registry key “[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon]” will be modified.

The trojan can establish a remote connection with the IP 174.120.228.122 and 193.105.174.108 on port 80 and retrieve data from:

* hxxp://www.brightspottech.com/loader_40.exe
* hxxp://hulejsoops.ru/images/bb.php?v=200&id=256235564&b=build001&tm=2

At the time of writing, only 10 of the 40 Av engines did detect the trojan. Virus Total permlink and MD5: b5e6830bb7836f776d5629291cc961a1

Comments are closed.

Follow

Get every new post delivered to your Inbox.

Join 348 other followers

%d bloggers like this: