Clicky

Pages

Showing posts with label Banking Trojans. Show all posts
Showing posts with label Banking Trojans. Show all posts

Thursday, August 26, 2010

Aug 25 CVE-2010-1240 From Intelligence Fusion Centre with ZeuS trojan



Update: Please read detailed analysis of this and associated attacks   
Crime or Espionage? by Nart Villeneuve

 Download  as a password protected archive (contact me if you need the password)



Intelligence Fusion Centre
In support of NATO
RAF Molesworth, United Kingdom
Unit 8845 Box 300, Huntingdon
CAMBS PE28 0QB

FROM: Intelligence Fusion Centre
SUBJECT: Military operation of the EU

Additional information can be found in the following report:

http:// gnarus.mobi/media/EuropeanUnion_MilitaryOperations_EN. zip
http:// quimeras.com.mx/media/EuropeanUnion_MilitaryOperations_EN.ip

> EUROPEAN UNION
> EUROPEAN SECURITY AND DEFENCE POLICY
> Military operation of the EU
> EU NAVFOR Somalia
>
> This military operation, called EU NAVFOR Somalia - operation
> "Atalanta", is launched in support of Resolutions 1814 (2008), 1816
> (2008), 1838 (2008) and 1846 (2008) of the United Nations Security Council (UNSC) in order to contribute to:
> -  the protection of vessels of the WFP (World Food Programme) delivering food aid to displaced
>    persons in Somalia;
> -  the protection of vulnerable vessels cruising off the Somali coast, and the deterrence, prevention
>    and repression of acts of piracy and armed robbery off the Somali coast.
> This operation, which is the first EU maritime operation, is conducted
> in the framework of the European Security and Defence Policy (ESDP).
>
>
> More information and background documents available on
> http:// gnarus.mobi/media/EuropeanUnion_MilitaryOperations_EN. zip
> and
> http:// quimeras.com.mx/media/EuropeanUnion_MilitaryOperations_EN. zip
>
> ________________________________________
> PRESS - EU Council Secretariat Tel: +32 (0)2 281 7640 / 6319

Headers
X-VirusChecked: Checked
X-Env-Sender: gnarusm@mail.thecopperstar.com
X-Msg-Ref: xxxxxxxxxxx
X-StarScan-Version: 6.2.4; banners=-,-,-
X-Originating-IP: [174.132.255.10]
X-SpamReason: No, hits=1.0 required=7.0 tests=BODY_RANDOMQ
Received: (qmail 15068 invoked from network); 26 Aug 2010 13:24:33 -0000
Received: from a.ff.84ae.static.theplanet.com (HELO mail.thecopperstar.com)
 (174.132.255.10)  by xxxxxxxxxx
 DHE-RSA-AES256-SHA encrypted SMTP; 26 Aug 2010 13:24:33 -0000
Received: from gnarusm by mail.thecopperstar.com with local (Exim 4.69)
 (envelope-from <gnarusm@mail.thecopperstar.com>) id 1OocRS-0006Y5-PR for
 XXXXXXXXXX; Thu, 26 Aug 2010 08:24:30 -0500
To: XXXXXXXXX
Subject: From Intelligence Fusion Centre to XXXXXXX
From: <ifc@ifc.nato.int>
Message-ID: <E1OocRS-0006Y5-PR@mail.thecopperstar.com>
Date: Thu, 26 Aug 2010 08:24:30 -0500
X-AntiAbuse: This header was added to track abuse, please include it with any abuse report
X-AntiAbuse: Primary Hostname - mail.thecopperstar.com
 174.132.255.10
 Hostname:    a.ff.84ae.static.theplanet.com
ISP:    THEPLANET.COM INTERNET SERVICES
Organization:    THEPLANET.COM INTERNET SERVICES
Type:    Broadband
Assignment:    Static IP
Country:    United States
State/Region:    Texas
File name: EuropeanUnion_MilitaryOperations_EN.pdf
 http://www.virustotal.com/file-scan/report.html?id=5761e303d7bc027df47b5b01a3e4e8e186eb36d3a4f40956768231ef3bbcac46-1282832496
 Submission date: 2010-08-26 14:21:36 (UTC)
Current status: finished
Result: 11 /41 (26.8%)
Avast 4.8.1351.0 2010.08.26 PDF:Risk-A
Avast5 5.0.594.0 2010.08.26 PDF:Risk-A
BitDefender 7.2 2010.08.26 Exploit.PDF-Dropper.Gen
eSafe 7.0.17.0 2010.08.26 PDF.DropperExploit.Gen
eTrust-Vet 36.1.7818 2010.08.26 PDF/Pidief.RU
F-Secure 9.0.15370.0 2010.08.26 Exploit.PDF-Dropper.Gen
GData 21 2010.08.26 Exploit.PDF-Dropper.Gen
Kaspersky 7.0.0.125 2010.08.26 Trojan-Dropper.VBS.Pdfka.b
nProtect 2010-08-26.01 2010.08.26 Exploit.PDF-Dropper.Gen
PCTools 7.0.3.5 2010.08.26 Trojan.Dropper
SUPERAntiSpyware 4.40.0.1006 2010.08.26 -
Symantec 20101.1.1.7 2010.08.26 Trojan.Dropper
Additional informationShow all 
MD5   : 8b3a3c4386e4d59c6665762f53e6ec8e



   /Type /Action
   /S /Launch
   /Win /F (cmd.exe) 
   /P (
   /c echo Dim BinaryStream > vbs1.vbs && echo Set BinaryStream = CreateObject("ADODB.Stream")
 -------------------------------------------------
Windows XPSP2 Adobe Reader 9.1


Quick flash of CMD.exe black window and we are looking at a pretty new icon on the desktop exe.exe


 Files created
c:\windows\system32\ntos.exe  28C4648F05F46A3EC37D664CEE0D84A8
same directory as the original file - exe.exe  5fb94eef8bd57fe8e20ccc56e33570c5

And these are the classic signs of old Zeus and this is what it is.


File name:
exe.exe
http://www.virustotal.com/file-scan/report.html?id=33ac66e78d410d03f5644fb1569ea7d28e823561e00b86593d9022f554127c7e-1282847843
3 /41 (7.3%)
AntiVir     8.2.4.46     2010.08.26     TR/Crypt.XPACK.Gen2
PCTools     7.0.3.5     2010.08.26     Trojan.Zbot
Symantec     20101.1.1.7     2010.08.26     Trojan.Zbot
Additional information
Show all
MD5   : 5fb94eef8bd57fe8e20ccc56e33570c5

File name: ntos.exe
http://www.virustotal.com/file-scan/report.html?id=c61fdc96fb7861396d7aa99a26cb6dff3f92aeeccf93d212a8fa3e166adec6aa-1282850806
Submission date: 2010-08-26 19:26:46 (UTC)
Result: 4 /39 (10.3%)
AntiVir 8.2.4.46 2010.08.26 TR/Crypt.XPACK.Gen2
Panda 10.0.2.7 2010.08.26 Suspicious file
PCTools 7.0.3.5 2010.08.26 Trojan.Zbot
Symantec 20101.1.1.7 2010.08.26 Trojan.Zbot
Additional informationShow all
MD5   : 28c4648f05f46a3ec37d664cee0d84a8




Sunday, August 1, 2010

Zeus Trojan Research Links

Links to good ZeuS Trojan research papers (in no particular order). See update changes in Green

Malware Intelligence blog
  1. Nov. 7 2009  Special!!! ZeuS Botnet for Dummies - Jorge Mieres (Malware Intelligence blog)
  2. Jan 25, 2010  Leveraging ZeuS to send spam through social networks - Jorge Mieres (Malware Intelligence blog)
  3. Feb. 20, 2010  Facebook & VISA phishing campaign proposed by ZeuS - Jorge Mieres (Malware Intelligence blog)
  4. March 15, 2010 New phishing campaign against Facebook led by Zeus - Jorge Mieres (Malware Intelligence blog)
  5. Apr. 19, 2010 / 31.03.2010 ZeuS on IRS Scam remains actively exploited - Jorge Mieres (Malware Intelligence blog)
Abuse.ch

  1. Zeus Tracker
  2. April 3, 2010 ZeuS: Cybercriminals moving over to FastFlux Hosting
  3. March 10, 2010 -- Massive Drop in Number of Active Zeus C&C Servers
  4. March 18, 2010 -- And another Bulletproof Hoster goes Offline…

mdl4 by Mark

  1. May 3, 2010 Decrypting a ZeuS (ZBot) config
  2. Feb. 28, 2010 Reverse engineering a Facebook ZeuS infection
 Trusteer
  1. Sept 14, 2009 Measuring the in-the-wild effectiveness of Antivirus against Zeus 
  2. April 21, 2010 Trusteer Detects Rapid Spread of New Polymorphic Version of Zeus Online Banking Trojan (v.1.4)
SecureWorks
  1. March 11, 2010 ZeuS Banking Trojan Report  (v. 1.3.4.x and v. 1.4)
PaulDotCom - Security Weekly  
  1. June 23, 2010 Dennis Brown - Zeus/FreeZeus setup, technical details, etc   -- very interesting podcast with the most recent info
 Symantec
  1. May 3rd, 2010  A Brief Look at Zeus/Zbot 2 by Karthik Selvaraj
  2. Feb . 2010 Clash of the Titans: ZeuS v SpyEye   - 72 page analysis  - added Aug 1, 2010

Sophos
  1. Why won’t my sample run?  James Wyke
S21Sec
  1.  July 5, 2010 New features of ZeuS   Mikel Gastesi
  2. Apr 28, 2010 Killing the enemy  Mikel Gastes
  3. Apr 07, 2009 when a bot master goes mad - kill the os  Jozsef Gegeny
Eternal to-do.com  Jose Miguel Esparza
  1. Feb 2,2010 ZeuS spreading via Facebook Jose Miguel Esparza
  2. Nov 6, 2009 New ZeuS binary
  3. Oct 11, 2009 Detecting ZeuS
National Cyber Forensics and Training Alliance Canada / Computer Security Laboratory, Concordia University - added Aug 1, 2010
  1. On the Analysis of the Zeus Botnet Crimeware Toolkit by H. Binsalleeh,T. Ormerod, A. Boukhtouta, P. Sinha, A. Youssef, M. Debbabi, and L. Wang - Overview, functionality and RE of v.1.2.4.2
Secure Science Corporation and Michael Ligh - added Aug 1, 2010
  1. Nov. 13  2006[Prg] Malware Case Study 
TrustDefender Labs - added Aug 1, 2010
  1. May 6, 2010 Zeus 2.0 – Zeus trojan at its best – extending its reach to Windows Vista, 7 and Mozilla Firefox

From TrustDefender:
"How to detect that a system is compromised

Since the new variant of Zeus doesn’t use complex rootkit techniques, detection is relatively easy. Simply start the registry editor (regedit.exe) and check for an entry in the Run section of HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Run.

The things to look out for are:
  • Name looks like a GUID (such as {26014332-876A-668A-546A-2A9930E39482})
  • Value is a filename in %USERDIR%\Application Data\\    (such as “C:\Documents and Settings\support\Application Data\Kyniin\yqypy.exe”)

How to remove Zeus v2

Removal of the Zeus v2 Trojan is also much easier since no complex rootkit techniques are used.
Simply locate the file that is being run from the above registry entry and delete the registry entry and the file. After a restart, your computer is clean. :-)
These are just a few links, please send me links to more good ZeuS research, I will include them. Thank you


Sunday, March 7, 2010

March 2010 Opachki Trojan update and sample

I already posted a few links for Opachki trojan in November 2009.  Here is an update.


 
Download dropper.exe and dropped rundll32.dll as a password protected archive. Please contact me if you need the password

Details:
2ded7ee112cea2db509ba95dc09fded6  dropper.exe
032e8fced2fbed146c30a47d4989804b  rundll32.dll

March 2010 Virustotal scan results of the available sample. Please note this sample dates to October 2009. Newer versions and samples will have lower detection rate and may get slightly different names.

 File dropper.exe received on 2010.03.07 16:46:50 (UTC)
www.virustotal.com/analisis/787d0eae3fb29883b8dba9c3bcc00793baa4a54fbad0921d1aee7f5e6ad86907-1267980410
Result: 37/42 (88.1%)
a-squared    4.5.0.50    2010.03.07    Packed.Win32.Krap!IK
AhnLab-V3    5.0.0.2    2010.03.07    Win-Trojan/Krap.31232.K
AntiVir    8.2.1.180    2010.03.05    TR/Crypt.ZPACK.Gen
Antiy-AVL    2.0.3.7    2010.03.05    Packed/Win32.Krap.gen
Authentium    5.2.0.5    2010.03.06    W32/Trojan2.KMYU
Avast    4.8.1351.0    2010.03.07    Win32:MalOb-R
Avast5    5.0.332.0    2010.03.07    Win32:MalOb-R
AVG    9.0.0.787    2010.03.07    Win32/Cryptor
BitDefender    7.2    2010.03.07    Trojan.Generic.2594388
CAT-QuickHeal    10.00    2010.03.06    Trojan.Krap.ah
Comodo    4091    2010.02.28    TrojWare.Win32.Trojan.Agent.Gen
DrWeb    5.0.1.12222    2010.03.07    Trojan.Packed.683
eSafe    7.0.17.0    2010.03.04    Win32.Horse
F-Prot    4.5.1.85    2010.03.06    W32/Trojan2.KMYU
F-Secure    9.0.15370.0    2010.03.07    Packed:W32/Tikmis.gen!A
Fortinet    4.0.14.0    2010.03.07    W32/Krap.AH
GData    19    2010.03.07    Trojan.Generic.2594388
Ikarus    T3.1.1.80.0    2010.03.07    Packed.Win32.Krap
Jiangmin    13.0.900    2010.03.07    Packed.Krap.zvc
K7AntiVirus    7.10.990    2010.03.04    Trojan.Win32.Malware.4
Kaspersky    7.0.0.125    2010.03.07    Packed.Win32.Krap.ah
McAfee    5912    2010.03.06    Opachki.a
McAfee+Artemis    5912    2010.03.06    Opachki.a
McAfee-GW-Edition    6.8.5    2010.03.07    Trojan.Crypt.ZPACK.Gen
Microsoft    1.5502    2010.03.07    Trojan:Win32/Opachki.A
NOD32    4922    2010.03.07    Win32/TrojanDropper.Agent.OLQ
Norman    6.04.08    2010.03.07    W32/Crypt.dam
nProtect    2009.1.8.0    2010.03.07    Trojan/W32.Krap.31232.L
Panda    10.0.2.2    2010.03.07    Trj/Zlob.KH
PCTools    7.0.3.5    2010.03.04    Trojan.Generic
Prevx    3.0    2010.03.07    High Risk Cloaked Malware
Sophos    4.51.0    2010.03.07    Mal/FakeAV-BX
Sunbelt    5780    2010.03.07    Trojan.Win32.Generic!VS
Symantec    20091.2.0.41    2010.03.07    Trojan Horse
TrendMicro    9.120.0.1004    2010.03.07    TROJ_OPACHKI.I
VBA32    3.12.12.2    2010.03.05    BScope.Win32.AntiAV2010
VirusBuster    5.0.27.0    2010.03.06    Trojan.Opachki.EK
Additional information
File size: 31232 bytes
MD5...: 2ded7ee112cea2db509ba95dc09fded6

Monday, November 2, 2009

Win32/Opachki.A - Trojan that removes Zeus (but it is not benign)

Links updated: Jan 18, 2023

Download. Email me if you need the password
1) 
6762a2e15913e66b06a0953387bd87b0f9ce22b5939fe1efd46c7120df214d7c
2) 
MD5 00f2fd5e2c125965c188754f04da576c
SHA-1 63d53f6e1b3f9fb23c88b19f7c6326da45753a5d
SHA-256 a602a3dd91b5aa0e0e68d20efe787e01c9548cb1b11b5032541c2e7d4edb5710



Win32/Opachki.A --Virustotal-all antivirus names for it. The real tragedy is in those  http://www.threatexpert.com/report.aspx?md5=87a2583de6f6fbb5104e0433e89b1bcf


nsrbgxod.bak created by Opachki http://www.threatexpert.com/report.aspx?md5=87a2583de6f6fbb5104e0433e89b1bcf and nsrbgxod.bak created by Zeus/ZBot http://www.threatexpert.com/report.aspx?md5=00f2fd5e2c125965c188754f04da576c (link lost)



Different hash


SecureWorks Opachki Trojan Analysis http://www.secureworks.com/research/threats/opachki

Threatexpert

Submission details:

Filename(s)

1 %Temp%\nsrbgxod.bak

0 bytes


MD5: D41D8CD98F00B204E9800998ECF8427E
SHA-1: DA39A3EE5E6B4B0D3255BFEF95601890AFD80709
2 %UserProfile%\protect.dll
%Programs%Startup\ChkDisk.dll
%System%\autochk.dll


[file and pathname of the sample #1]


24,064 bytes

MD5: 0x87A2583DE6F6FBB5104E0433E89B1BCF

SHA-1: 6048D36DB2207A1CEA877742C9403A816D711C6D

Mal/UnkPack-Fam
[Sophos]

TrojanDropper:Win32/Opachki.A

[Microsoft]

Trojan-Dropper.Win32.Opachki

[Ikarus]

3 %Programs%\Startup\ChkDisk.lnk



655 bytes



MD5: 0x6F61156F14AEED438770D31391E67EC9

SHA-1: 0x277B806CEC1AEDE9F9B934B7DD655D0BBB542597

Read more -  Update March 2010 

New banking trojan W32.Silon -msjet51.dll

Links updated: Jan 18, 2023