Oficla/Sasfis trojan now detected in emails regarding contract
May 3, 2010 1 Comment
MX Lab intercepted a new trojan variant from Oficla/Sasfis in email regarding labour contracts. The from email address is randomly choosen and contains spoofed email addresses.
Possible subjects are:
Contract of settlements
Contract of retirement
Loan contract
Permit for retirement
Rent contract
Your new labour contract
The body of the email:
Good day,
We have prepared a contract and added the paragraphs that you wanted to see in it.
Our lawyers made alterations on the last page. If you agree with all the provisions we are ready to make the payment on Friday for the first consignment.
We are enclosing the file with the prepared contract.
If necessary, we can send it by fax.
Looking forward to your decision.
“Benito Swan
The email contains the attachment Contract_29_04_2010.zip and once extracted the 36 kB large file Contract_29_04_2010____doc__[many_undercores]___.exe emerges.
The trojan is known as Win32/Oficla.GN (NOD32), Trojan.Win32.Oficla (Ikarus), Trojan.Oficla.38 (Dr Web) but also as VirTool:Win32/VBInject.FO (Microsoft) or Trojan.Sasfis (Symantec).
The following files will be created:
%Temp%\1.tmp
%System%\thxr.wgo
%Temp%\2.tmp
The registry key “HKEY_LOCAL_MACHINE\SOFTWARE\Classes\idid” is created.
The registry key “[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon]” will be modified.
The trojan can establish a remote connection with the IP 174.120.228.122 and 193.105.174.108 on port 80 and retrieve data from:
* hxxp://www.brightspottech.com/loader_40.exe
* hxxp://hulejsoops.ru/images/bb.php?v=200&id=544932909&b=build001&tm=2
At the time of writing, 16 of the 41 AV engines at Virus Total did detect the threat. Virus Total permlink and MD5: 73f9b5732155d68b908f4acdaadff2ec

Pingback: Oficla/Sasfis trojan now detected in emails regarding contract | Computer Security Articles