15.07.2013 Views

sKyWIper (a.k.a. Flame a.k.a. Flamer): A complex ... - CrySyS Lab

sKyWIper (a.k.a. Flame a.k.a. Flamer): A complex ... - CrySyS Lab

sKyWIper (a.k.a. Flame a.k.a. Flamer): A complex ... - CrySyS Lab

SHOW MORE
SHOW LESS

You also want an ePaper? Increase the reach of your titles

YUMPU automatically turns print PDFs into web optimized ePapers that Google loves.

The malware contains the following modules:<br />

Related OCX files:<br />

mssecmgr.ocx (6 M) Main module<br />

-- resource 146 (2.5 M) Compressed file with some zlib-like compression<br />

advnetcfg.ocx (0.6 M) Injected part, possibly info stealer (screen shots and alike)<br />

msglu32.ocx (1.6 M) Created by main module<br />

nteps32.ocx (0.8 M) Created by main module<br />

soapr32.ocx (0.2 M) Can be found in resource 146, possibly network based propagation<br />

module<br />

The main module of the malware is mssegmgr.ocx, which is 6 MByte long. It is loaded at<br />

startup, and later copied to wavesup3.drv. The main module also creates other OCX modules<br />

as shown in the above list.<br />

Related files in the Windows/Temp folder:<br />

To691.tmp (1.5 M) Initial settings data file<br />

Related files in the Windows/System32 folder:<br />

ccalc32.sys Configuration settings table, fully encrypted. It is generated by the<br />

malware installer process, and stored in uncompressed Resource<br />

146 of mssecmgr.sys at position 0x00001E7118. It is encrypted by<br />

RC4 (128).<br />

boot32drv.sys (~1 K) Desktop window related data, encrypted by XOR with 0xFF<br />

Temporary files created by the malware:<br />

~DEB93D.tmp Encrypted file containing SQLite database of nmb lookups. Written<br />

by services.exe.<br />

~HLV084.tmp Compressed parts contain info on running processes. Written by<br />

winlogon.exe.<br />

~HLV294.tmp Purpose unknown. This and 4-5 similar files often appear on<br />

infected systems.<br />

~KWI Compressed parts contain info on running processes. Written by<br />

winlogon.exe.<br />

<strong>Lab</strong>oratory of Cryptography and System Security (<strong>CrySyS</strong>)<br />

Budapest University of Technology and Economics<br />

www.crysys.hu 10

Hooray! Your file is uploaded and ready to be published.

Saved successfully!

Ooh no, something went wrong!