A forum for reverse engineering, OS internals and malware analysis 

Forum for analysis and discussion about malware.
 #1425  by EP_X0FF
 Tue Jul 06, 2010 10:55 am
Thank you for samples ;)

TDL3 is fresh.
[main]
version=3.273
quote=You people voted for Hubert Humphrey, and you killed Jesus
botid=
affid=20787
subid=0
installdate=6.7.2010 10:51:22
builddate=6.7.2010 10:10:13
rnd=515967899
[injector]
*=tdlcmd.dll
[tdlcmd]
servers=hxxps://19js810300z.com/;hxxps://lj1i16b0.com/;hxxps://li1i16b0.com/;hxxps://zz87jhfda88.com/;hxxps://n16fa53.com/;hxxps://01n02n4cx00.cc/
wspservers=hxxp://zl00zxcv1.com/;hxxp://zloozxcv1.com/;hxxp://71ha6dl01.com/;hxxp://axjau710h.com/;hxxp://rf9akjgh716zzl.com/;hxxp://dsg1tsga64aa17.com/;hxxp://l1i1e3e3oo8as0.com/;hxxp://7gafd33ja90a.com/;hxxp://n1mo661s6cx0.com/
popupservers=hxxp://clkh71yhks66.com/
version=3.82
 #1429  by PX5
 Tue Jul 06, 2010 2:47 pm
seriall.com added tdl3 loader back in a couple days ago, dont know how fresh the sample is itself.
 #1441  by EP_X0FF
 Wed Jul 07, 2010 5:16 pm
I believe this bug is "by design", it was since beginning. Nobody expected multiple reinfection of the same system.
 #1443  by EP_X0FF
 Wed Jul 07, 2010 5:41 pm
In [main] section of config.ini stored rootkit component version, since April it is non meaningful, authors stopped to update it. Current version can be determined as 3.28.
In [tdlcmd] stored actual tdlcmd.dll library version. Current last available 3.83/3.82 (difference in servers lists only).
Instead of rootkit itself, tdlcmd.dll can be updated.
 #1444  by SecConnex
 Wed Jul 07, 2010 5:52 pm
So, when they update TDLCMD, they are switching server lists?

I see that they only do partial upgrades to only certain components with each release.
 #1445  by EP_X0FF
 Wed Jul 07, 2010 5:59 pm
DragonMaster Jay wrote:So, when they update TDLCMD, they are switching server lists?
Not only. Usually with servers list update when tdlcmd version "grows" it means some additional modifications.
For example, new configuration values. As you see config.ini divided on parts, each responding for something

[main] - rootkit version, quote to be displayed in debugger for analysts, bot it, affid (see 1 page of this thread for more info) etc.
[injector] - when tdl3 just released there was two libraries - tdlwsp.dll and tdlcmd.dll. This section responsible for dll injection, where * means all running processes.
[tdlcmd] - keeps dll specific information and configuration values (servers, version) etc.
DragonMaster Jay wrote:I see that they only do partial upgrades to only certain components with each release.
Currently yes, there no major updates since March. However for fooling AV industry (most of vendors) it is enough.
I believe major developers switched to other project (TDL4?) or simple leaved it.
 #1446  by SecConnex
 Wed Jul 07, 2010 6:13 pm
I do have some belief that TDL authors have some connection to a certain rogue AV family.

Over in my group, we have discussions on how possibly the TDL authors can damage a computer without making it unbootable, so they can secure their backdoor access. Right now, they have taken it very far.
  • 1
  • 21
  • 22
  • 23
  • 24
  • 25
  • 40