15.07.2013 Views

Report - CrySyS Lab

Report - CrySyS Lab

Report - CrySyS Lab

SHOW MORE
SHOW LESS

Create successful ePaper yourself

Turn your PDF publications into a flip-book with our unique Google optimized e-Paper software.

The ~24kb size module from index3.hta contains 4 distinct MZ headers. We name them atl_1 to atl_4<br />

in the hash list. The 24k long file is compiled on 2005-04-04.<br />

Submodule atl_1<br />

refers to \atlsrv.exe \altnet32.exe \atlsrv.exe sdmnet32.dll srvshell.dll sdmnet.dll srvshell32.dll<br />

It contains debug information that gives hint on the code goal:<br />

i:\119prj\Bv\REPLACE Kasp\3 otdel\1.2m UnderKasper\installer\Release\installer.pdb<br />

The module communicates with other modules through the registry, under the key<br />

Software\Microsoft\Internet Explorer\MainFileSRC<br />

This module saves an interesting email address “” into the registry.<br />

The module also uses a mutex named “{118-32-FOOTBOLL-15}” and it is also able to set<br />

SOFTWARE\Microsoft\Windows\CurrentVersion\Run for its goals.<br />

It modifies “\AUTOEXE.BAT” (no typo) in some cases to:<br />

:LOOP<br />

DEL "%s"'<br />

IF EXIST "%s" GOTO LOOP<br />

DEL "%s"<br />

Module atl_2<br />

Figure 48 – .bat file created by submodule atl_1<br />

This module uses mutexes “{132-79-FOOTBOLL-18}” , “{118-32-FOOTBOLL-15}” and {167-53-<br />

BADFOOD-14}, as well as DLLs sdmnet32.dll sdmnet.dll srvshell.dll or srvshell32.dll<br />

It has some relation to explorer.exe, and it calls the _NetBiosDisconnectNt export of another module.<br />

Basically this module is a middle layer between atl_1 and atl_3.<br />

Module atl_3<br />

Compile time: 2005-04-04<br />

This module is UPX compressed (ver 1.92 – released in 2004). When uncompressed, this module is<br />

28kb long, therefore, it is the biggest “main” module among the four submodules.<br />

It provides functionality to other modules, the defined export functions are as follows, where the<br />

most important export function is probably NetBiosDisconnectNt:<br />

_NetBiosConnectNt@8<br />

_NetBiosDisconnectNt@8<br />

_NtDR@0<br />

46

Hooray! Your file is uploaded and ready to be published.

Saved successfully!

Ooh no, something went wrong!