Emails with the subject “UPS INVOICE NR9094991” and “Delivery Problem NR2204780” contains trojan


A combination of the “Thank you for buying iTunes Gift Certificate!” and the latest UPS related emails with subjects like “UPS INVOICE NR9094991” or “Delivery Problem NR2204780” has made that MX Lab noted the highest virus detection rate since months.

The possible subjects are (numbers are random):

UPS INVOICE NR9094991
Delivery Problem NR2204780

The body of the email:

Hello!
Unfortunately we were not able to deliver your postal you have sent on the 11th of March in time because the addressee’s is inexact.
Please print out the invoice copy attached and collect the package at our department.
UPS Global Services.

Hello!
We failed to deliver the postal you have sent on the 24th of March in time because the addressee’s is wrong.
Please print out the invoice copy attached and collect the package at our department.
UPS Express Services.

The email contains the zip archive upsinvoice3325037.zip, once extracted the 36 kB large file UPSINVOICE.exe is available.

The trojan is known as W32/FakeAlert.NW (F-Prot), Trojan.Win32.VBKrypt.yj (Kaspersky), Win32/Oficla.EU (NOD32), Troj/Bredo-CX (Sophos) or Trojan.Sasfis (Symantec).

The following files are created:

%Temp%\1.tmp
%System%\nnfj.tqo
%Temp%\2.tmp
%Windir%\scindl.dll

The following modules will be loaded into the address space of other process(es):

%Windir%\scindl.dll —>
Process name: explorer.exe
Process filename: %Windir%\explorer.exe
Address space: 0x1E90000 - 0x1EA1000

%Windir%\scindl.dll —>
Process name: IEXPLORE.EXE
Process filename: %ProgramFiles%\internet explorer\iexplore.exe
Address space: 0x1940000 - 0x1951000

%Windir%\scindl.dll —>
Process name: [generic host process]
Process filename: [generic host process filename]
Address space: 0x10000000 - 0x10011000

The trojan can establish a remote connection with the following hosts on port 80:

85.87.17.230
89.149.202.142
95.211.27.238

Data will be requested fromt he following web sites:

* hxxp://funnylive2010.ru/ms/bb.php?v=200&id=653227819&b=newsp&tm=2
* hxxp://funnylive2010.ru/ms/bb.php?v=200&id=653227819&tid=5&b=newsp&r=1&tm=2
* hxxp://www.yunusemre.net/trpanel/fckeditor/editor/
_source/classes/sistempod.exe

Virus Total permlink and MD5: 493c929efe366812cd6fc921c2b549fc.

New trojan variant in “Thank you for buying iTunes Gift Certificate!” email


MX Lab started to intercept a new campaign with the subject “Thank you for buying iTunes Gift Certificate!” with the trojan Gen:Variant.Bredo.4 (Bitdefender, F-Secure), Win32/Oficla.GQ (NDO32), Trojan.Sasfis (Symantec) or Mal/EncPk-NS (Sophos).

It is clear that with this campaign, the virus authors are using a subtle way to lure potential victims. Getting a $50 iTunes Gift Certificate is more tempting than anything else.

This distribution is sent from the spoofed email address iTunes Products <[email protected]>.

The body of the email:

Hello!

You have received an iTunes Gift Certificate in the amount of $50.00
You can find your certificate code in attachment below.

Then you need to open iTunes. Once you verify your account, $50.00 will be credited to your account, so you can start buying music, games, video right away.

iTunes Store.

The email contains the file ZIP archive Gift_Certificate_531.zip containing the 36 kB large executable Gift_Certificate_531.exe.

The following files are created:

%Temp%\1.tmp
%System%\nnfj.tqo
%Temp%\4.tmp
%Temp%\_check32.bat
%Windir%\Moxmact1.dll
%Windir%\s32.txt
%System%\aspimgr.exe
%Windir%\ws386.ini

A new process will be created on the system:

%System%\aspimgr.exe

The following modules will be loaded into the address space of other process(es):

%Windir%\Moxmact1.dll —>
Process name: explorer.exe
Process filename: %Windir%\explorer.exe
Address space: 0x1E80000 - 0x1E91000

%Windir%\Moxmact1.dll —>
Process name: [generic host process]
Process filename: [generic host process filename]
Address space: 0x10000000 - 0x10011000

New registry key creations:

  • HKEY_LOCAL_MACHINE\SOFTWARE\Classes\idid
  • HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Phuxobab
  • HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Sft
  • HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Enum\Root\LEGACY_ASPIMGR
  • HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Enum\Root\LEGACY_ASPIMGR000
  • HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Enum\Root\LEGACY_ASPIMGR000\Control
  • HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Services\aspimgr
  • HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Services\aspimgr\Security
  • HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Services\aspimgr\Enum
  • HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Enum\Root\LEGACY_ASPIMGR
  • HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Enum\Root\LEGACY_ASPIMGR000
  • HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Enum\Root\LEGACY_ASPIMGR000\Control
  • HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\aspimgr
  • HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\aspimgr\Security
  • HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\aspimgr\Enum

The following registry keys are modified:

  • [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon]
    • Shell =
  • [HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\ServiceCurrent]
    • (Default) =
  • [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\ServiceCurrent]
    • (Default) =

The trojan can establish a remote connection with the following hosts on port 80:

128.175.82.88
195.78.108.203
89.149.202.142
95.211.27.238

Data will be requested fromt he following web sites:

* hxxp://funnylive2010.ru/ms/bb.php?v=200&id=555611691&b=26may&tm=2
* hxxp://funnylive2010.ru/ms/bb.php?v=200&id=555611691&tid=11&b=26may&r=1&tm=2
* hxxp://porsche911start.ru:80/board.php
* hxxp://www.yunusemre.net/trpanel/fckeditor/editor/
_source/classes/v106.exe
* hxxp://www.yunusemre.net/trpanel/fckeditor/editor/
_source/classes/sistempod.exe

At the time of writing, 16 of the 41 AV engines did detect the trojan. Virus Total permlink and MD5: 75809a70e8773d51c5b20dd0f7b8163e.

Follow

Get every new post delivered to your Inbox.

Join 1,551 other followers