Threat Spotlight

For the week of 14 Feb 2011
Threat 1

Fake package delivery malware

Threat Name:

Mal/Zbot-AV

Users at Risk:

Windows users

Also Known As:

  • Avira: TR/Agent.BKF
  • AVP: Trojan-Spy.Win32.Zbot.arve
  • Symantec: Trojan.Zbot!gen14
  • TrendMicro: TROJ_SPYEYE.SMEP

Removal Instructions:

Please follow the instructions for removing generically detected files to delete the file from your computer.

About:

Recently this malware appeared in the wild as an executable attached to e-mail spam messages with the subject that starts with:

Post Express!

The email contains information that a package has not been delivered to the receiver due to an incorrect address. The email message also includes an attachment claiming to be details of the package that didn't make it to the receiver. It's a very common social engineering trick to get the receiver to download the attachment.

In this case, the attachment will be an archive that has the name Post_Express_Label_[random_alphanumeric].zip.

On extracting the archive there will be an executable inside that holds the name Post_Express_Label.exe, which is detected as Mal/Zbot-AV.

The malware attachment, Mal/Zbot-AV, is a maliciously packed Fake AV downloader. Normally it has a Microsoft Word icon to try to convince users to run it. Once run, Mal/Zbot-AV it tries to download an MS Word file from http://interviewbuy.ru/forum/document.com and then open it. It then deletes itself.

The document contains some bogus information about a package that has supposedly arrived at the post office for you. This file will be downloaded to %MY_DOCUMENTS%\document.doc.

Mal/Zbot-AV will also drop more malware on the system in the following locations:

%PROFILE%\Application Data\palladium.exe
%PROFILE%\Application Data\startup.js
%PROFILE%\Application Data\temp.js
%STARTMENU%\Programs\Startup\Startup.js
%PROFILE%\Local Settings\Temp\[Random].tmp
%SYSTEM%\dll
%SYSTEM%\[Random].dll
%INTERNET_CACHE%\Content.IE5\[Random Name Dir]\load[1-5].htm

Mal/Zbot-AV will also add the following registry keys:

HKCU\Software\Microsoft\Windows\CurrentVersion\Policies\Explorer\Run Startup %PROFILE%\Application Data\temp.js
HKCU\Software\Microsoft\Windows\CurrentVersion\Run Startup %PROFILE%\Application Data\Startup.js
HKCU\Software\Microsoft\Windows\CurrentVersion\RunOnce sd cmd.exe /c del "%PROFILE%\Local Settings\Temp\[Random].tmp"
HKCU\Software\Microsoft\Windows NT\CurrentVersion\Winlogon Shell %PROFILE%\Application Data\palladium.exe

Mal/Zbot-AV uses the executables in %PROFILE%\Local Settings\Temp as placeholders for the downloaded data. The data comes from http://interviewbuy.ru/forum/load.php?file=[1-9].

Finally after going through all the files on the domain, the malware makes an http request to: hxxp : // interviewbuy . ru / forum / load . php?file = ftpgrabber hxxp : // interviewbuy . ru / forum / load . php?file = pokergrabber

When the last .tmp file in %PROFILE%\Local Settings\Temp\ runs, a copy is placed in %PROFILE%\Application Data\palladium.exe.

Startup.js and temp.js are identical and they execute an HTML application that downloads JavaScript from: http://network-solution-global.com/signup.php?did=[Random_ID].

The JavaScript will download:

%PROFILE%\Application Data\[Random].exe
%PROFILE%\Local Settings\Temp\[Random].tmp %PROFILE%\Application Data\palladium.exe %PROFILE%\Application Data\[Random].exe

All are detected as Troj/FakeAV-CQF. The files %PROFILE%\Application Data\startup.js and %PROFILE%\Application Data\temp.js are detected as Troj/Dwnldr-IUY. The file %SYSTEM%\dll is detected as Troj/Patched-Y. The file %SYSTEM%\[Random].dll is detected as Mal/Agent-RW.

The Microsoft HTML application that Troj/Dwnldr-IUY tries to execute using Microsoft HTML Application host (mshta.exe) is detected as Mal/FakeAvJs-A.

Threat 2

Downloader mirrors Conficker behaviors

Threat Name:

W32/Murofet-A

Users at Risk:

Windows users

Also Known As:

  • Avira: W32/Murofet.A
  • AVP: Virus.Win32.Murofet.a
  • F-Secure: Gen:Trojan.Heur.FU.am0@a0PbKwki
  • McAfee: W32/Zbot virus
  • Microsoft: TrojanDownloader:Win32/Murofet.gen!A
  • Symantec: Trojan.Zbot.B!inf
  • TrendMicro: PE_LICAT.A

Removal Instructions:

Please follow the instructions for disinfecting PE executables.

About:

W32/Murofet-A attempts to download further code from URLs it generates using an algorithm based on the current date and time, verifying the downloaded file before executing it. This technique is reminiscent of the Conficker family of malware.

We've seen evidence that the threat also spreads via payload from exploit kits in addition to infected files. The URLs contacted are in the following forms:

hxxp :// .biz / forum /
hxxp :// .info / forum /
hxxp :// .org / forum /
hxxp :// .net / forum /
hxxp :// .com / forum /

At the time of writing, the above URLs were unavailable; however, we had seen cases of the sites hosting malware related to Zbot.

The infection itself modifies the host file and it acts as a simple downloader —it will create a thread that will download from a pseudo-random downloaded domain name.

Threat 3

Norwegian Bredo spam

Threat Name:

Troj/BredoZp-BU

Users at Risk:

Windows users

Removal Instructions:

Please follow the instructions for removing Trojans.

About:

Troj/BredoZp-BU is a malicious file hidden in a password-protected email attachment zip file. The email typically has a subject line like these:

Hei Man

The malicious attachment is between 130-150 KB in size and has the following name:

Image <number>.zip

The message is usually written in Norwegian and the body often contains references to some pictures (together with a provided password to open them) and uses some form of social engineering trick to entice the user into opening them.

As is typical for Bredo spam, messages from infected hosts all over the world employ various ploys. In this case here, the ZIP file has been specifically password protected in an attempt to trick the recipient that the message might be safe to open.

This embedded malware inside the attachment is a Microsoft VB.NET file and is proactively detected as Mal/Behav-043.