Threat Spotlight

For the week of 01 Sep 2011
Threat 1

Morto worm exploits weak passwords

Threat Name:

Mal/Morto-A

Users at Risk:

Windows users

Further Reading:

Morto: RDP worm of death?

Removal Instructions:

Please follow the instructions for removing worms

About:

Mal/Morto-A is a family of network worms.

This old-fashioned Internet worm, which targets Windows workstations and servers, exploits weak passwords to spread via Remote Desktop Protocol (RDP) connections (port 3389).

Mal/Morto-A drops a file, also detected as Mal/Morto-A, to one or more of the following locations:

<Windows>\clb.dll
<Windows>\Offline Web Pages\cache.txt

Mal/Morto-A tries to read and write to files in the remote folder \\tsclient\a\.

Mal/Morto-A typically creates registry entries at the following location:

HKLM\SYSTEM\Wpa

Mal/Morto-A may attempt to delete the following registry key:

HKCU\Software\Microsoft\Windows\CurrentVersion\Explorer\RunMRU

Mal/Morto-A may attempt to contact the following remote locations:

qfsl.net
jifr.info
jifr.co.cc

Components of Mal/Morto-A have been detected as Troj/SvcLoad-A, Troj/SvcLoad-B and Troj/Agent-TEE.

We are merging our detection and are now protecting against the worm as Mal/Morto-A.

Threat 2

Zbot Trojan could hijack your PC

Threat Name:

Troj/Agent-TDG

Users at Risk:

Windows users

Also Known As:

Avira TR/Fivfrom.A.6
AVP Backdoor.Win32.Agobot.rqq
Microsoft Trojan:Win32/Fivfrom

Removal Instructions:

Please follow the instructions for removing Trojans

About:

Troj/Agent-TDG is a Trojan affecting Windows users.

As a member of the Zbot family of malware, Troj/Agent-TDG looks for sensitive user information such as passwords. Remote hackers could also use the Trojan to hijack your computer to send out even more malware.

We've seen Troj/Agent-TDG spreading through spam messages with subjects including "Re: your changlog," typically including a fake ID or reference number.

The attachment is a zip file with names like:

change<date numbers><random characters>.zip
log<date numbers>.zip

This zip file is detected by Sophos as Mal/BredoZp-B.

The zip file contains a single executable, which has a Microsoft Office document icon.

Typically, the body of the spam messages is very short, consisting of a simple introduction (e.g., "good day"), a phrase containing "as promised," and then signed off with a name.

These messages are spammed out by infected machines around the world.

When run, the inner executable copies itself to the user's profile directory, under:

%PROFILE%\Local Settings\Temp\

The Trojan sets itself up in the registry to run on startup by using the key:

HKCU\Software\Microsoft\Windows\CurrentVersion\Run

We also detect this Trojan generically as Mal/Zbot-CX.

Threat 3

Trojan dropper threatens Windows users

Threat Name:

Troj/Mdrop-DQO

Users at Risk:

Windows users

Also Known As:

Avira TR/Dldr.AutoIt.rg
AVP Trojan-Downloader.Win32.AutoIt.rg

Removal Instructions:

Please follow the instructions for removing Trojans

About:

Troj/Mdrop-DQO is a Trojan for the Windows platform.

Troj/Mdrop-DQO has three components.

The downloader/dropper component is an AutoIT script which retrieves the other two components from:

hxxp://neivarp.web168.f1.k8.com.br/cap
hxxp://neivarp.web168.f1.k8.com.br/cpoutlook
hxxp://neivarp.web168.f1.k8.com.br/libmysql41.dll

The dropper saves these files to:

%USERPROFILE%\AppData\Local\<random letters>\

It then attempts to execute cap.exe and cpoutlook.exe.

The Trojan adds a registry entry for cap.exe to execute at system startup:

HKCU\Software\Microsoft\Windows\CurrentVersion\Run
ICompXpSp
%USERPROFILE%\AppData\Local\<random letters>\cap.exe

The cpoutlook.exe component searches the file system for .wab files.

Sophos detects all three files as Troj/Mdrop-DQO.

In addition to the standard detection provided for Troj/Mdrop-DQO, our proactive HIPS technology in Sophos Endpoint Security can block this malware and the additional malware it attempts to install.

When Troj/Mdrop-DQO runs, it will fire the following HIPS rules:

HIPS/IPConnect-001
HIPS/RegMod-001
HIPS/RegMod-014