15.07.2013 Views

Report - CrySyS Lab

Report - CrySyS Lab

Report - CrySyS Lab

SHOW MORE
SHOW LESS

You also want an ePaper? Increase the reach of your titles

YUMPU automatically turns print PDFs into web optimized ePapers that Google loves.

The module is capable to send emails, but also to receive emails from POP3 connection. It can send<br />

basic information about the victim e.g. Computer Name, Operating system language, available<br />

drives.<br />

Module atl_4<br />

Module atl_4 uses Mutex {119-36-FOOTBOLL-92}<br />

It sets the target addresses for atl_3.through registry keys: EX S2 S1<br />

The values to be used for user name and password for pop3 login are: bibi.lima/yergt37h for<br />

host pop.laposte.net Another likely name/password pair is bine.bono/hdyw386k<br />

Two corresponding email address also exists in the binary: <br />

smtp.laposte.net and <br />

Some host references can also be found, namely:<br />

mail.zoznam.sk post.freemail.lt<br />

politnews – n.txt<br />

MD5 hash: 22dd42246ebec969e1a9c608793a644e<br />

compile time: 2004-01-24<br />

The size of the module is ~160k.<br />

This module installs acxMonitor.exe and acxAgin.dll into the directory “c:\windows\system32”, then<br />

installs a new key to HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run,<br />

namely “acxMonitor” pointing to “C:\WINDOWS\system32\acxMonitor.exe”<br />

The MD5 hash of acxMonitor.exe is: 0b74db5420416129ce82c65c03df337e<br />

The MD5 hash of acxAgin.dll is: c75f7a3a1d1695797e1a55e1200a6044<br />

The compile time for the samples according to the binaries is: 1992-06-19<br />

The output files are c:\sysdll2.txt and c:\sysdll8.txt, where the latter contains debug data related to<br />

modem communications:<br />

11:32:27 PM ATR0<br />

11:32:28 PM ATDP**<br />

11:32:33 PM OPEN LINK.....COM3<br />

11:32:33 PM CHECK GDT.....OK<br />

11:32:33 PM CHECK GDT.....OK<br />

11:32:33 PM CHECK DT.....OFF<br />

48

Hooray! Your file is uploaded and ready to be published.

Saved successfully!

Ooh no, something went wrong!