Email “Statement of fees 2009/2010” contains trojan


MX Lab intercepts a new trojan variant in emails with the subject “Statement of fees 2009/2010”. The trojan is known as Trojan.Sasfis (Symantec), Suspicious:W32/Malware!Gemini (F-Secure) or Mal/Zbot-U (Sophos).

The body of the email:

Please find attached a statement of fees as requested, this will be posted today.
The accommodation is dealt with by another section and I have passed your request on to them today.

Kind regards.
Fred Brooks

The trojan is packed in the ZIP archive Statement_of_Fees_2009-2010.zip. Once extracted, an 52 kB large file Statement_of_Fees_2009-2010.DOC.exe is available.

The following files are created:

%Temp%\1.tmp
%System%\thxr.wgo
%Temp%\2.tmp

The following registry will be created:

* HKEY_LOCAL_MACHINE\SOFTWARE\Classes\idid

The following registry will be modified:

* [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon]
+ Shell =

Connection with remote hosts 193.105.174.108 and 59.53.91.195 are established over port 80 and the following URLs are requested:

* hxxp://hulejsoops.ru/images/bb.php?v=200&id=828459563&b=b_27_spa&tm=1
* hxxp://russianmomds.ru/bot.exe

Out of the 41 AV engines at Virus Total, only 11 detect the trojan. Virus Total permlink and MD5: 180a8d1991c5dbbc01f883e5254fba0f.

When investigating the downloaded file bot.exe, 172 kB, which is obviously malware, we did found the following information.

The threat is known as Trojan-Downloader:W32/Piker.A (F-Secure), Mal/Zbot-U (Sophos), TROJ_ZBOT.BAK (Trend Micro) or TR/PSW.Zbot.173056.R.1 (AntiVir).

The following file is created:

%System%\sdra64.exe

The following hidden files are created:

%System%\lowsec\local.ds
%System%\lowsec\user.ds
%System%\lowsec\user.ds.lll

New memory pages created in the address space of the system process(es):

%System%\svchost.exe
%System%\services.exe
%System%\lsass.exe
%System%\alg.exe

The following URLs are requested:

* hxxp://www.oomseekerss.ru/img/konf.bin
* hxxp://www.oomseekerss.ru/cppp.php

29 out of the 41 AV engines did detect the treath. Virus Total permlink and MD5: f5e18b513d5b41b4905b5e216094cf9e.

Comments are closed.

Follow

Get every new post delivered to your Inbox.

Join 1,551 other followers

%d bloggers like this: