Email “Statement of fees 2009/2010” contains trojan
June 11, 2010
MX Lab intercepts a new trojan variant in emails with the subject “Statement of fees 2009/2010”. The trojan is known as Trojan.Sasfis (Symantec), Suspicious:W32/Malware!Gemini (F-Secure) or Mal/Zbot-U (Sophos).
The body of the email:
Please find attached a statement of fees as requested, this will be posted today.
The accommodation is dealt with by another section and I have passed your request on to them today.Kind regards.
Fred Brooks
The trojan is packed in the ZIP archive Statement_of_Fees_2009-2010.zip. Once extracted, an 52 kB large file Statement_of_Fees_2009-2010.DOC.exe is available.
The following files are created:
%Temp%\1.tmp
%System%\thxr.wgo
%Temp%\2.tmp
The following registry will be created:
* HKEY_LOCAL_MACHINE\SOFTWARE\Classes\idid
The following registry will be modified:
* [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon]
+ Shell =
Connection with remote hosts 193.105.174.108 and 59.53.91.195 are established over port 80 and the following URLs are requested:
* hxxp://hulejsoops.ru/images/bb.php?v=200&id=828459563&b=b_27_spa&tm=1
* hxxp://russianmomds.ru/bot.exe
Out of the 41 AV engines at Virus Total, only 11 detect the trojan. Virus Total permlink and MD5: 180a8d1991c5dbbc01f883e5254fba0f.
When investigating the downloaded file bot.exe, 172 kB, which is obviously malware, we did found the following information.
The threat is known as Trojan-Downloader:W32/Piker.A (F-Secure), Mal/Zbot-U (Sophos), TROJ_ZBOT.BAK (Trend Micro) or TR/PSW.Zbot.173056.R.1 (AntiVir).
The following file is created:
%System%\sdra64.exe
The following hidden files are created:
%System%\lowsec\local.ds
%System%\lowsec\user.ds
%System%\lowsec\user.ds.lll
New memory pages created in the address space of the system process(es):
%System%\svchost.exe
%System%\services.exe
%System%\lsass.exe
%System%\alg.exe
The following URLs are requested:
* hxxp://www.oomseekerss.ru/img/konf.bin
* hxxp://www.oomseekerss.ru/cppp.php
29 out of the 41 AV engines did detect the treath. Virus Total permlink and MD5: f5e18b513d5b41b4905b5e216094cf9e.
