icr wrote:Some more TDSS programs(renamed *._exe)b7b33895bb09802c1c4bf860a0ca57e2 packed with Lighty Compressor known to be predecessor of Mystic Compressor.
D8F03E7D476481D5922265E73362B316 (file drops two more files)
Uses KnownDlls msvcrt trick, works like autorun worm, which is capable with spreading through all available drives including shared network drives.
Example of autorun.inf below
Code: Select all
68cd276d5a6fefdef3f36abaec4e7ff7 - Nullsoft uninstaller, simulating uninstalling of the UNICCodec "codec", not malware[autorun]
;vcelsszvunxhrouhmvnoyteugkoicyszimtrnxudfnhvucxczujhxypbwsfdfkwwobkdydbjcpawdtlrupwyxqvqeudlwzpnlryxh
shellexecute="RECYCLER\S-8-5-67-100031458-100012049-100019303-9647.com z:\"
;zxadjjckzknxmgvzfrewnafwcpnjmgjijhveoyazomagtvlooknesrqq
shell\Open\command="RECYCLER\S-8-5-67-100031458-100012049-100019303-9647.com z:\"
;mieeucarfxmpwzrdfabvqtxxpkngangv
shell=Open
7c205ef7013b2c69ea4ed6fe8c8ab48f TDL2
2443fd7af22f6fe726b1f7e579aa57d9 TDL2
fbd379b7f107d3180cbbca702dc72c99 TDL2
ytasfw y t a s f w \ m o d u l e s \ m a i n \ i n j e c t o r \ d e l e t e \ c o n n e c t i o n s \systemroot\system32 %s\%s%s%s \\?\globalroot \??\ \ winlogon.exe * svchost.exe ytasfwcmd.dll % S * \ K E R N E L 3 2 . D L L LoadLibraryExA F i l e \ r e g i s t r y \ m a c h i n e \ s e c u r i t y \ p o l i c y \ p o l a c d m s i n s t a l l d a t e \ r e g i s t r y \ m a c h i n e \ s o f t w a r e \ m i c r o s o f t \ w i n d o w s n t \ c u r r e n t v e r s i o n %X%X%X%X a i d s i d % d . % d . % d . % d \ F i l e S y s t e m \ F l t M g r * \ S Y S T E M 3 2 \ N T O S K R N L . E X E * \ S Y S T E M 3 2 \ N T K R N L P A . E X E * \ S Y S T E M 3 2 \ C O N F I G \ S Y S T E M * \ S Y S T E M 3 2 \ C O N F I G \ S O F T W A R E chkdsk.exe \systemroot\system32\ytasfwcmd.dll s v c h o s t . e x e \ r e g i s t r y \ M A C H I N E \ S Y S T E M \ C u r r e n t C o n t r o l S e t \ C o n t r o l \ S e r v i c e G r o u p O r d e r L i s t % s \ % s G r o u p S t a r t S y s t e m %S \ r e g i s t r y \ M A C H I N E \ S Y S T E M \ C u r r e n t C o n t r o l S e t \ S e r v i c e s s t a r t t y p e i m a g e p a t h file system g r o u p \ r e g i s t r y \ m a c h i n e \ s y s t e m \ c u r r e n t c o n t r o l s e t \ e n u m \ r o o t \ l e g a c y _ \ 0 0 0 0 \ c o n t r o l \ 0 0 0 0 \ e n u m % . * s % s % S \systemroot\system32\drivers\ytasfwrk.sys \ s y s t e m r o o t \ d e v i c e \ h a r d d i s k % d d e v i c e p a r t i t i o n \ f i l e s y s t e m \ f a s t f a t \ f i l e s y s t e m \ n t f s \ d r i v e r \ t c p i p \ d r i v e r \ f t d i s k \ d r i v e r \ d i s k \ d r i v e r \ v o l s n a p \ d r i v e r \ p a r t m g r \ f i l e s y s t e m \ r a w \ d r i v e r \ a t a p i \ d r i v e r \ d m i o \ d r i v e r \ e c a c h e \ d r i v e r \ f v e v o l \ d r i v e r \ v o l m g r \ f i l e s y s t e m \ f l t m g r \ d r i v e r \ d i s k p e r f \ d r i v e r \ m o u n t m g r \ d r i v e r \ a c p i classpnp.sys ataport.sys scsiport.sys storport.sys hal.dll IofCompleteRequest IofCallDriver ZwSaveKey ZwSaveKeyEx ZwEnumerateKey ZwFlushInstructionCache System k e r n e l 3 2 . d l l TDL2 Loadedb3f6a1649ab556ec00f71c116b1a9c84 part of TDL2 (binary trash)
* \ y t a s f w * * \ T E M P \ y t a s f w * %.*S \ s y s t e m r o o t \ s y s t e m 3 2 \ % S KeServiceDescriptorTable
ecf01929d41c2dde974168e0867c2f0d
TDL3
[main]d99308c180d3725dd95663bb14144014
quote=Everybody's a jerk. You, me, this jerk. That's just my philosophy
version=3.273
botid=3f1b98c6-07dd-4f7d-a650-30bb6f39b0a3
affid=20376
subid=0
installdate=22.9.2011 6:53:33
builddate=2.4.2010 21:29:8
[injector]
*=tdlcmd.dll
[tdlcmd]
servers=hxxps://zz87jhfda88.com/;hxxps://91.212.226.65/;hxxps://19js810300z.com/;hxxps://01n02n4cx00.cc/
wspservers=hxxp://30xc1cjh91.com/;hxxp://j00k877x.cc/;hxxp://m01n83kjf7.com/
popupservers=hxxp://clkh71yhks66.com/
version=3.741
TDL3 original, z00clicker variant
[main]cb91b8695d3990b5b5eae8a714bd357e
botid=2F0C4FFA32EAC01665D637A84D3555BD
date=10674960
[injector]
iexplore.exe=z00clicker.dll
firefox.exe=z00clicker.dll
safari.exe=z00clicker.dll
TDL4
[main]
version=0.03
aid=66671
sid=0
builddate=351
installdate=22.9.2011 7:5:36
rnd=2956339178
[inject]
*=cmd.dll
* (x64)=cmd64.dll
[cmd]
srv=hxxps://lo4undreyk.com/;hxxps://sh01cilewk.com/;hxxps://cap01tchaa.com/;hxxps://kur1k0nona.com/;hxxps://u101mnay2k.com/
wsrv=hxxp://gnarenyawr.com/;hxxp://rinderwayr.com/;hxxp://jukdoout0.com/;hxxp://swltcho0.com/;hxxp://ranmjyuke.com/
psrv=hxxp://crj71ki813ck.com/
version=0.31
Ring0 - the source of inspiration