Backdoor.Win32.Caphaw_QKKBAL_289637175d
Gen:Variant.Symmi.30687 (BitDefender), PWS:Win32/Zbot.gen!Y (Microsoft), HEUR:Trojan.Win32.Generic (Kaspersky), Trojan.Win32.Agent.adgv (v) (VIPRE), Trojan.PWS.Panda.368 (DrWeb), Gen:Variant.Symmi.30687 (B) (Emsisoft), PWSZbot-FDA!289637175DA3 (McAfee), Packed.Generic.457 (Symantec), Trojan.Inject (Ikarus), Gen:Variant.Symmi.30687 (FSecure), Generic34.BNXI (AVG), Win32:Crypt-PVY [Trj] (Avast), TROJ_GEN.R021C0DIK13 (TrendMicro), Gen:Variant.Symmi.30687 (AdAware), GenericInjector.YR, BackdoorCaphaw_QKKBAL.YR, TrojanPSWZbot.YR (Lavasoft MAS)
Behaviour: Trojan-PSW, Trojan, Backdoor, Packed
The description has been automatically generated by Lavasoft Malware Analysis System and it may contain incomplete or inaccurate information.
| Requires JavaScript enabled! |
|---|
MD5: 289637175da378be5cb4e3475e51afe2
SHA1: 7a1c9999e1227b73b7b2c382f6b4093f979bf44b
SHA256: da5b7728f8ebb09924a9ba33a1c0c657a1d024384f2e4f6adedcecabb02c3ad2
SSDeep: 3072:xscO/2F293rPMZcMskusAcqHa/u5mXhWlFJfU:xscO/2F2ZiPvMHakshEFJM
Size: 166912 bytes
File type: EXE
Platform: WIN32
Entropy: Not Packed
PEID: UPolyXv05_v6
Company: Firseria
Created at: 2013-08-26 08:09:54
Analyzed on: WindowsXP SP3 32-bit
Summary:
Backdoor. Malware that enables a remote control of victim's machine.
Payload
No specific payload has been found.
Process activity
The Backdoor creates the following process(es):
itov.exe:3152
itov.exe:2832
%original file name%.exe:1572
The Backdoor injects its code into the following process(es):
Explorer.EXE:1948
File activity
The process %original file name%.exe:1572 makes changes in the file system.
The Backdoor creates and/or writes to the following file(s):
%Documents and Settings%\%current user%\Application Data\Keraga\itov.exe (166 bytes)
%Documents and Settings%\%current user%\Local Settings\Temp\tmp49bdb140.bat (177 bytes)
Registry activity
The process itov.exe:3152 makes changes in the system registry.
The Backdoor creates and/or sets the following values in system registry:
[HKLM\SOFTWARE\Microsoft\Cryptography\RNG]
"Seed" = "B8 52 81 A9 27 F8 00 0F 3B 42 8B 4E D4 C6 CD E7"
[HKCU\Software\Microsoft\Windows\CurrentVersion\Explorer\Shell Folders]
"AppData" = "%Documents and Settings%\%current user%\Application Data"
The process itov.exe:2832 makes changes in the system registry.
The Backdoor creates and/or sets the following values in system registry:
[HKLM\SOFTWARE\Microsoft\Cryptography\RNG]
"Seed" = "7E 40 98 C9 13 F9 43 F5 6F 95 73 C5 AD 7F B5 CF"
The process %original file name%.exe:1572 makes changes in the system registry.
The Backdoor creates and/or sets the following values in system registry:
[HKLM\SOFTWARE\Microsoft\Cryptography\RNG]
"Seed" = "D8 F1 B8 5D 18 46 D9 47 04 5E 4B 21 B0 5F F6 0C"
[HKCU\Software\Microsoft\Windows\CurrentVersion\Explorer\Shell Folders]
"AppData" = "%Documents and Settings%\%current user%\Application Data"
Dropped PE files
| MD5 | File path |
|---|---|
| 0f8442071fa242cb51d16d9cf90f062c | c:\Documents and Settings\"%CurrentUserName%"\Application Data\Keraga\itov.exe |
HOSTS file anomalies
No changes have been detected.
Rootkit activity
The Backdoor installs the following user-mode hooks in WININET.dll:
HttpSendRequestExW
HttpSendRequestExA
InternetReadFileExA
HttpSendRequestA
HttpSendRequestW
InternetQueryDataAvailable
InternetCloseHandle
HttpQueryInfoA
InternetReadFile
The Backdoor installs the following user-mode hooks in CRYPT32.dll:
PFXImportCertStore
The Backdoor installs the following user-mode hooks in USER32.dll:
GetClipboardData
TranslateMessage
The Backdoor installs the following user-mode hooks in kernel32.dll:
GetFileAttributesExW
The Backdoor installs the following user-mode hooks in ntdll.dll:
LdrLoadDll
NtCreateThread
Propagation
VersionInfo
Company Name: PortableApps.com
Product Name: Pidgin Portable
Product Version: 1.6.9.0
Legal Copyright: John T. Haller
Legal Trademarks: PortableApps.com is a Trademark of Rare Ideas, LLC.
Original Filename: PidginPortable.exe
Internal Name: Pidgin Portable
File Version: 1.6.9.0
File Description: Pidgin Portable
Comments: Allows Pidgin to be run from a removable drive. For additional details, visit PortableApps.com/PidginPortable
Language: English (United States)
PE Sections
| Name | Virtual Address | Virtual Size | Raw Size | Entropy | Section MD5 |
|---|---|---|---|---|---|
| .text | 4096 | 47999 | 48128 | 4.6841 | 4555f48965463194029137d9185c716d |
| .rdata | 53248 | 16888 | 16896 | 4.08057 | 1e2486805d4eceb9c09e275202692a38 |
| .data | 73728 | 8128 | 4608 | 2.48281 | a0372aa0df55d45915667a57f56ff1d7 |
| .rsrc | 81920 | 95332 | 95744 | 4.67233 | d3babe7fee7b5c190a821c29827ec9b7 |
Dropped from:
Downloaded by:
Similar by SSDeep:
Similar by Lavasoft Polymorphic Checker:
URLs
| URL | IP |
|---|---|
| hxxp://89.36.31.215/~westcomp/administrator/language/config.bin |
IDS verdicts (Suricata alerts: Emerging Threats ET ruleset)
ET CNC Zeus Tracker Reported CnC Server group 21
ET TROJAN Possible Zbot Activity Common Download Struct
ET CURRENT_EVENTS Zbot Generic URI/Header Struct .bin
Traffic
GET /~westcomp/administrator/language/config.bin HTTP/1.1
Accept: */*
Connection: Close
User-Agent: Mozilla/4.0 (compatible; MSIE 8.0; Windows NT 5.1; Trident/4.0; .NET CLR 2.0.50727; .NET CLR 3.0.04506.648; .NET CLR 3.5.21022; .NET4.0C; .NET4.0E)
Host: 89.36.31.215
Cache-Control: no-cache
HTTP/1.1 404 Not Found
Date: Thu, 05 Jun 2014 04:44:10 GMT
Server: Apache/2.2.22 (Unix) mod_ssl/2.2.22 OpenSSL/1.0.0-fips mod_bwlimited/1.4 PHP/5.3.13
Accept-Ranges: bytes
Connection: close
Transfer-Encoding: chunked
Content-Type: text/html1.....1.....95..<!DOCTYPE html PUBLIC "-//W3C//DTD XHTML 1.0 Transi
tional//EN" "hXXp://VVV.w3.org/TR/xhtml1/DTD/xhtml1-transitional.dtd"&
gt;.<html>. <head>. <title>..579..404 Not Found&
lt;/title>. <meta http-equiv="Content-Type" content="text/htm
l; charset=utf-8" />. <style type="text/css">. body
{. .font-family: Verdana, Arial, Helvetica, sans-serif;.
.font-size: 12px;. .background-color:#367E8E;. .scroll
bar-base-color: #005B70;. .scrollbar-arrow-color: #F3960B;.
.scrollbar-DarkShadow-Color: #000000;. .color: #FFFFFF;....
margin:0;. }. a { color:#021f25; text-decoration:none}.
h1 {. .font-size: 18px;. .color: #FB9802;.
.padding-bottom: 10px;. .background-image: url(sys_cpanel/imag
es/bottombody.jpg);. .background-repeat: repeat-x;. .pad
ding:5px 0 10px 15px;....margin:0;. }. #body-content p {
. .padding-left: 25px;. .padding-right: 25px;. .l
ine-height: 18px;. .padding-top: 5px;. .padding-bottom:
5px;. }. h2 {. .font-size: 14px;. .font-we
ight: bold;. .color: #FF9900;. .padding-left: 15px;.
}. </style>. </head>. <body>. <div id
="body-content"> .<!-- start content-->..<!-- . instead o
f REQUEST_URI, we could show absolute URL via:. hXXp://HTTP_HOST/REQUE
ST_URI. but what if its hXXps:// or other protocol?. . SE<<< skipped >>>
GET /~westcomp/administrator/language/config.bin HTTP/1.1
Accept: */*
Connection: Close
User-Agent: Mozilla/4.0 (compatible; MSIE 8.0; Windows NT 5.1; Trident/4.0; .NET CLR 2.0.50727; .NET CLR 3.0.04506.648; .NET CLR 3.5.21022; .NET4.0C; .NET4.0E)
Host: 89.36.31.215
Cache-Control: no-cache
HTTP/1.1 404 Not Found
Date: Thu, 05 Jun 2014 04:44:16 GMT
Server: Apache/2.2.22 (Unix) mod_ssl/2.2.22 OpenSSL/1.0.0-fips mod_bwlimited/1.4 PHP/5.3.13
Accept-Ranges: bytes
Connection: close
Transfer-Encoding: chunked
Content-Type: text/html1.....1.....95..<!DOCTYPE html PUBLIC "-//W3C//DTD XHTML 1.0 Transi
tional//EN" "hXXp://VVV.w3.org/TR/xhtml1/DTD/xhtml1-transitional.dtd"&
gt;.<html>. <head>. <title>..579..404 Not Found&
lt;/title>. <meta http-equiv="Content-Type" content="text/htm
l; charset=utf-8" />. <style type="text/css">. body
{. .font-family: Verdana, Arial, Helvetica, sans-serif;.
.font-size: 12px;. .background-color:#367E8E;. .scroll
bar-base-color: #005B70;. .scrollbar-arrow-color: #F3960B;.
.scrollbar-DarkShadow-Color: #000000;. .color: #FFFFFF;....
margin:0;. }. a { color:#021f25; text-decoration:none}.
h1 {. .font-size: 18px;. .color: #FB9802;.
.padding-bottom: 10px;. .background-image: url(sys_cpanel/imag
es/bottombody.jpg);. .background-repeat: repeat-x;. .pad
ding:5px 0 10px 15px;....margin:0;. }. #body-content p {
. .padding-left: 25px;. .padding-right: 25px;. .l
ine-height: 18px;. .padding-top: 5px;. .padding-bottom:
5px;. }. h2 {. .font-size: 14px;. .font-we
ight: bold;. .color: #FF9900;. .padding-left: 15px;.
}. </style>. </head>. <body>. <div id
="body-content"> .<!-- start content-->..<!-- . instead o
f REQUEST_URI, we could show absolute URL via:. hXXp://HTTP_HOST/REQUE
ST_URI. but what if its hXXps:// or other protocol?. . SE<<< skipped >>>
GET /~westcomp/administrator/language/config.bin HTTP/1.1
Accept: */*
Connection: Close
User-Agent: Mozilla/4.0 (compatible; MSIE 8.0; Windows NT 5.1; Trident/4.0; .NET CLR 2.0.50727; .NET CLR 3.0.04506.648; .NET CLR 3.5.21022; .NET4.0C; .NET4.0E)
Host: 89.36.31.215
Cache-Control: no-cache
HTTP/1.1 404 Not Found
Date: Thu, 05 Jun 2014 04:44:05 GMT
Server: Apache/2.2.22 (Unix) mod_ssl/2.2.22 OpenSSL/1.0.0-fips mod_bwlimited/1.4 PHP/5.3.13
Accept-Ranges: bytes
Connection: close
Transfer-Encoding: chunked
Content-Type: text/html1.....1.....95..<!DOCTYPE html PUBLIC "-//W3C//DTD XHTML 1.0 Transi
tional//EN" "hXXp://VVV.w3.org/TR/xhtml1/DTD/xhtml1-transitional.dtd"&
gt;.<html>. <head>. <title>..579..404 Not Found&
lt;/title>. <meta http-equiv="Content-Type" content="text/htm
l; charset=utf-8" />. <style type="text/css">. body
{. .font-family: Verdana, Arial, Helvetica, sans-serif;.
.font-size: 12px;. .background-color:#367E8E;. .scroll
bar-base-color: #005B70;. .scrollbar-arrow-color: #F3960B;.
.scrollbar-DarkShadow-Color: #000000;. .color: #FFFFFF;....
margin:0;. }. a { color:#021f25; text-decoration:none}.
h1 {. .font-size: 18px;. .color: #FB9802;.
.padding-bottom: 10px;. .background-image: url(sys_cpanel/imag
es/bottombody.jpg);. .background-repeat: repeat-x;. .pad
ding:5px 0 10px 15px;....margin:0;. }. #body-content p {
. .padding-left: 25px;. .padding-right: 25px;. .l
ine-height: 18px;. .padding-top: 5px;. .padding-bottom:
5px;. }. h2 {. .font-size: 14px;. .font-we
ight: bold;. .color: #FF9900;. .padding-left: 15px;.
}. </style>. </head>. <body>. <div id
="body-content"> .<!-- start content-->..<!-- . instead o
f REQUEST_URI, we could show absolute URL via:. hXXp://HTTP_HOST/REQUE
ST_URI. but what if its hXXps:// or other protocol?. . SE<<< skipped >>>
GET /~westcomp/administrator/language/config.bin HTTP/1.1
Accept: */*
Connection: Close
User-Agent: Mozilla/4.0 (compatible; MSIE 8.0; Windows NT 5.1; Trident/4.0; .NET CLR 2.0.50727; .NET CLR 3.0.04506.648; .NET CLR 3.5.21022; .NET4.0C; .NET4.0E)
Host: 89.36.31.215
Cache-Control: no-cache
HTTP/1.1 404 Not Found
Date: Thu, 05 Jun 2014 04:44:05 GMT
Server: Apache/2.2.22 (Unix) mod_ssl/2.2.22 OpenSSL/1.0.0-fips mod_bwlimited/1.4 PHP/5.3.13
Accept-Ranges: bytes
Connection: close
Transfer-Encoding: chunked
Content-Type: text/html1.....1.....95..<!DOCTYPE html PUBLIC "-//W3C//DTD XHTML 1.0 Transi
tional//EN" "hXXp://VVV.w3.org/TR/xhtml1/DTD/xhtml1-transitional.dtd"&
gt;.<html>. <head>. <title>..579..404 Not Found&
lt;/title>. <meta http-equiv="Content-Type" content="text/htm
l; charset=utf-8" />. <style type="text/css">. body
{. .font-family: Verdana, Arial, Helvetica, sans-serif;.
.font-size: 12px;. .background-color:#367E8E;. .scroll
bar-base-color: #005B70;. .scrollbar-arrow-color: #F3960B;.
.scrollbar-DarkShadow-Color: #000000;. .color: #FFFFFF;....
margin:0;. }. a { color:#021f25; text-decoration:none}.
h1 {. .font-size: 18px;. .color: #FB9802;.
.padding-bottom: 10px;. .background-image: url(sys_cpanel/imag
es/bottombody.jpg);. .background-repeat: repeat-x;. .pad
ding:5px 0 10px 15px;....margin:0;. }. #body-content p {
. .padding-left: 25px;. .padding-right: 25px;. .l
ine-height: 18px;. .padding-top: 5px;. .padding-bottom:
5px;. }. h2 {. .font-size: 14px;. .font-we
ight: bold;. .color: #FF9900;. .padding-left: 15px;.
}. </style>. </head>. <body>. <div id
="body-content"> .<!-- start content-->..<!-- . instead o
f REQUEST_URI, we could show absolute URL via:. hXXp://HTTP_HOST/REQUE
ST_URI. but what if its hXXps:// or other protocol?. . SE<<< skipped >>>
GET /~westcomp/administrator/language/config.bin HTTP/1.1
Accept: */*
Connection: Close
User-Agent: Mozilla/4.0 (compatible; MSIE 8.0; Windows NT 5.1; Trident/4.0; .NET CLR 2.0.50727; .NET CLR 3.0.04506.648; .NET CLR 3.5.21022; .NET4.0C; .NET4.0E)
Host: 89.36.31.215
Cache-Control: no-cache
HTTP/1.1 404 Not Found
Date: Thu, 05 Jun 2014 04:44:16 GMT
Server: Apache/2.2.22 (Unix) mod_ssl/2.2.22 OpenSSL/1.0.0-fips mod_bwlimited/1.4 PHP/5.3.13
Accept-Ranges: bytes
Connection: close
Transfer-Encoding: chunked
Content-Type: text/html1.....1.....95..<!DOCTYPE html PUBLIC "-//W3C//DTD XHTML 1.0 Transi
tional//EN" "hXXp://VVV.w3.org/TR/xhtml1/DTD/xhtml1-transitional.dtd"&
gt;.<html>. <head>. <title>..579..404 Not Found&
lt;/title>. <meta http-equiv="Content-Type" content="text/htm
l; charset=utf-8" />. <style type="text/css">. body
{. .font-family: Verdana, Arial, Helvetica, sans-serif;.
.font-size: 12px;. .background-color:#367E8E;. .scroll
bar-base-color: #005B70;. .scrollbar-arrow-color: #F3960B;.
.scrollbar-DarkShadow-Color: #000000;. .color: #FFFFFF;....
margin:0;. }. a { color:#021f25; text-decoration:none}.
h1 {. .font-size: 18px;. .color: #FB9802;.
.padding-bottom: 10px;. .background-image: url(sys_cpanel/imag
es/bottombody.jpg);. .background-repeat: repeat-x;. .pad
ding:5px 0 10px 15px;....margin:0;. }. #body-content p {
. .padding-left: 25px;. .padding-right: 25px;. .l
ine-height: 18px;. .padding-top: 5px;. .padding-bottom:
5px;. }. h2 {. .font-size: 14px;. .font-we
ight: bold;. .color: #FF9900;. .padding-left: 15px;.
}. </style>. </head>. <body>. <div id
="body-content"> .<!-- start content-->..<!-- . instead o
f REQUEST_URI, we could show absolute URL via:. hXXp://HTTP_HOST/REQUE
ST_URI. but what if its hXXps:// or other protocol?. . SE<<< skipped >>>
GET /~westcomp/administrator/language/config.bin HTTP/1.1
Accept: */*
Connection: Close
User-Agent: Mozilla/4.0 (compatible; MSIE 8.0; Windows NT 5.1; Trident/4.0; .NET CLR 2.0.50727; .NET CLR 3.0.04506.648; .NET CLR 3.5.21022; .NET4.0C; .NET4.0E)
Host: 89.36.31.215
Cache-Control: no-cache
HTTP/1.1 404 Not Found
Date: Thu, 05 Jun 2014 04:43:59 GMT
Server: Apache/2.2.22 (Unix) mod_ssl/2.2.22 OpenSSL/1.0.0-fips mod_bwlimited/1.4 PHP/5.3.13
Accept-Ranges: bytes
Connection: close
Transfer-Encoding: chunked
Content-Type: text/html1.....1.....95..<!DOCTYPE html PUBLIC "-//W3C//DTD XHTML 1.0 Transi
tional//EN" "hXXp://VVV.w3.org/TR/xhtml1/DTD/xhtml1-transitional.dtd"&
gt;.<html>. <head>. <title>..579..404 Not Found&
lt;/title>. <meta http-equiv="Content-Type" content="text/htm
l; charset=utf-8" />. <style type="text/css">. body
{. .font-family: Verdana, Arial, Helvetica, sans-serif;.
.font-size: 12px;. .background-color:#367E8E;. .scroll
bar-base-color: #005B70;. .scrollbar-arrow-color: #F3960B;.
.scrollbar-DarkShadow-Color: #000000;. .color: #FFFFFF;....
margin:0;. }. a { color:#021f25; text-decoration:none}.
h1 {. .font-size: 18px;. .color: #FB9802;.
.padding-bottom: 10px;. .background-image: url(sys_cpanel/imag
es/bottombody.jpg);. .background-repeat: repeat-x;. .pad
ding:5px 0 10px 15px;....margin:0;. }. #body-content p {
. .padding-left: 25px;. .padding-right: 25px;. .l
ine-height: 18px;. .padding-top: 5px;. .padding-bottom:
5px;. }. h2 {. .font-size: 14px;. .font-we
ight: bold;. .color: #FF9900;. .padding-left: 15px;.
}. </style>. </head>. <body>. <div id
="body-content"> .<!-- start content-->..<!-- . instead o
f REQUEST_URI, we could show absolute URL via:. hXXp://HTTP_HOST/REQUE
ST_URI. but what if its hXXps:// or other protocol?. . SE<<< skipped >>>
GET /~westcomp/administrator/language/config.bin HTTP/1.1
Accept: */*
Connection: Close
User-Agent: Mozilla/4.0 (compatible; MSIE 8.0; Windows NT 5.1; Trident/4.0; .NET CLR 2.0.50727; .NET CLR 3.0.04506.648; .NET CLR 3.5.21022; .NET4.0C; .NET4.0E)
Host: 89.36.31.215
Cache-Control: no-cache
HTTP/1.1 404 Not Found
Date: Thu, 05 Jun 2014 04:44:21 GMT
Server: Apache/2.2.22 (Unix) mod_ssl/2.2.22 OpenSSL/1.0.0-fips mod_bwlimited/1.4 PHP/5.3.13
Accept-Ranges: bytes
Connection: close
Transfer-Encoding: chunked
Content-Type: text/html1.....1.....95..<!DOCTYPE html PUBLIC "-//W3C//DTD XHTML 1.0 Transi
tional//EN" "hXXp://VVV.w3.org/TR/xhtml1/DTD/xhtml1-transitional.dtd"&
gt;.<html>. <head>. <title>..579..404 Not Found&
lt;/title>. <meta http-equiv="Content-Type" content="text/htm
l; charset=utf-8" />. <style type="text/css">. body
{. .font-family: Verdana, Arial, Helvetica, sans-serif;.
.font-size: 12px;. .background-color:#367E8E;. .scroll
bar-base-color: #005B70;. .scrollbar-arrow-color: #F3960B;.
.scrollbar-DarkShadow-Color: #000000;. .color: #FFFFFF;....
margin:0;. }. a { color:#021f25; text-decoration:none}.
h1 {. .font-size: 18px;. .color: #FB9802;.
.padding-bottom: 10px;. .background-image: url(sys_cpanel/imag
es/bottombody.jpg);. .background-repeat: repeat-x;. .pad
ding:5px 0 10px 15px;....margin:0;. }. #body-content p {
. .padding-left: 25px;. .padding-right: 25px;. .l
ine-height: 18px;. .padding-top: 5px;. .padding-bottom:
5px;. }. h2 {. .font-size: 14px;. .font-we
ight: bold;. .color: #FF9900;. .padding-left: 15px;.
}. </style>. </head>. <body>. <div id
="body-content"> .<!-- start content-->..<!-- . instead o
f REQUEST_URI, we could show absolute URL via:. hXXp://HTTP_HOST/REQUE
ST_URI. but what if its hXXps:// or other protocol?. . SE<<< skipped >>>
GET /~westcomp/administrator/language/config.bin HTTP/1.1
Accept: */*
Connection: Close
User-Agent: Mozilla/4.0 (compatible; MSIE 8.0; Windows NT 5.1; Trident/4.0; .NET CLR 2.0.50727; .NET CLR 3.0.04506.648; .NET CLR 3.5.21022; .NET4.0C; .NET4.0E)
Host: 89.36.31.215
Cache-Control: no-cache
HTTP/1.1 404 Not Found
Date: Thu, 05 Jun 2014 04:43:59 GMT
Server: Apache/2.2.22 (Unix) mod_ssl/2.2.22 OpenSSL/1.0.0-fips mod_bwlimited/1.4 PHP/5.3.13
Accept-Ranges: bytes
Connection: close
Transfer-Encoding: chunked
Content-Type: text/html1.....1.....95..<!DOCTYPE html PUBLIC "-//W3C//DTD XHTML 1.0 Transi
tional//EN" "hXXp://VVV.w3.org/TR/xhtml1/DTD/xhtml1-transitional.dtd"&
gt;.<html>. <head>. <title>..579..404 Not Found&
lt;/title>. <meta http-equiv="Content-Type" content="text/htm
l; charset=utf-8" />. <style type="text/css">. body
{. .font-family: Verdana, Arial, Helvetica, sans-serif;.
.font-size: 12px;. .background-color:#367E8E;. .scroll
bar-base-color: #005B70;. .scrollbar-arrow-color: #F3960B;.
.scrollbar-DarkShadow-Color: #000000;. .color: #FFFFFF;....
margin:0;. }. a { color:#021f25; text-decoration:none}.
h1 {. .font-size: 18px;. .color: #FB9802;.
.padding-bottom: 10px;. .background-image: url(sys_cpanel/imag
es/bottombody.jpg);. .background-repeat: repeat-x;. .pad
ding:5px 0 10px 15px;....margin:0;. }. #body-content p {
. .padding-left: 25px;. .padding-right: 25px;. .l
ine-height: 18px;. .padding-top: 5px;. .padding-bottom:
5px;. }. h2 {. .font-size: 14px;. .font-we
ight: bold;. .color: #FF9900;. .padding-left: 15px;.
}. </style>. </head>. <body>. <div id
="body-content"> .<!-- start content-->..<!-- . instead o
f REQUEST_URI, we could show absolute URL via:. hXXp://HTTP_HOST/REQUE
ST_URI. but what if its hXXps:// or other protocol?. . SE<<< skipped >>>
GET /~westcomp/administrator/language/config.bin HTTP/1.1
Accept: */*
Connection: Close
User-Agent: Mozilla/4.0 (compatible; MSIE 8.0; Windows NT 5.1; Trident/4.0; .NET CLR 2.0.50727; .NET CLR 3.0.04506.648; .NET CLR 3.5.21022; .NET4.0C; .NET4.0E)
Host: 89.36.31.215
Cache-Control: no-cache
HTTP/1.1 404 Not Found
Date: Thu, 05 Jun 2014 04:44:10 GMT
Server: Apache/2.2.22 (Unix) mod_ssl/2.2.22 OpenSSL/1.0.0-fips mod_bwlimited/1.4 PHP/5.3.13
Accept-Ranges: bytes
Connection: close
Transfer-Encoding: chunked
Content-Type: text/html1.....1.....95..<!DOCTYPE html PUBLIC "-//W3C//DTD XHTML 1.0 Transi
tional//EN" "hXXp://VVV.w3.org/TR/xhtml1/DTD/xhtml1-transitional.dtd"&
gt;.<html>. <head>. <title>..579..404 Not Found&
lt;/title>. <meta http-equiv="Content-Type" content="text/htm
l; charset=utf-8" />. <style type="text/css">. body
{. .font-family: Verdana, Arial, Helvetica, sans-serif;.
.font-size: 12px;. .background-color:#367E8E;. .scroll
bar-base-color: #005B70;. .scrollbar-arrow-color: #F3960B;.
.scrollbar-DarkShadow-Color: #000000;. .color: #FFFFFF;....
margin:0;. }. a { color:#021f25; text-decoration:none}.
h1 {. .font-size: 18px;. .color: #FB9802;.
.padding-bottom: 10px;. .background-image: url(sys_cpanel/imag
es/bottombody.jpg);. .background-repeat: repeat-x;. .pad
ding:5px 0 10px 15px;....margin:0;. }. #body-content p {
. .padding-left: 25px;. .padding-right: 25px;. .l
ine-height: 18px;. .padding-top: 5px;. .padding-bottom:
5px;. }. h2 {. .font-size: 14px;. .font-we
ight: bold;. .color: #FF9900;. .padding-left: 15px;.
}. </style>. </head>. <body>. <div id
="body-content"> .<!-- start content-->..<!-- . instead o
f REQUEST_URI, we could show absolute URL via:. hXXp://HTTP_HOST/REQUE
ST_URI. but what if its hXXps:// or other protocol?. . SE<<< skipped >>>
The Backdoor connects to the servers at the folowing location(s):
.text
`.data
.reloc
PR_OpenTCPSocket
http://www.google.com/webhp
userenv.dll
del "%s"
if exist "%s" goto d
del /F "%s"
Mozilla/4.0 (compatible; MSIE 7.0; Windows NT 5.1; SV1)
HTTP/1.1
urlmon.dll
cabinet.dll
(2*-9#93
'."?%>#)0/9
!zGM^ZM]K}mJAWKTI_LgsSHZL_UG=6 <#>(;gdiplus.dllGdiplusShutdownole32.dllgdi32.dllhttp://https://HTTP/1.GetProcessHeapKERNEL32.dllExitWindowsExMsgWaitForMultipleObjectsGetKeyboardStateUSER32.dllRegCreateKeyExWRegOpenKeyExWRegCloseKeyADVAPI32.dllUrlUnescapeASHDeleteKeyWPathIsURLWSHLWAPI.dllShellExecuteWSHELL32.dllSecur32.dllWS2_32.dllPFXImportCertStoreCertDeleteCertificateFromStoreCertOpenSystemStoreWCertCloseStoreCertEnumCertificatesInStoreCertDuplicateCertificateContextPFXExportCertStoreExCRYPT32.dllHttpSendRequestExAHttpQueryInfoAHttpSendRequestExWHttpSendRequestWHttpSendRequestAInternetCrackUrlAHttpOpenRequestAHttpAddRequestHeadersAGetUrlCacheEntryInfoWHttpAddRequestHeadersWWININET.dllNETAPI32.dll9%9-93999^9e.datnspr4.dllkernel32.dll"%s" %s/c "%s"%sx.%s%sxGlobal\XXXGlobal\{82F3CDA2-12F4-71E0-899F-E973627BBD38}%Documents and Settings%\%current user%\Application Data{14887F87-A0D1-E79B-899F-E973627BBD38}%Documents and Settings%\%current user%\Application Data\Ewketi\moil.upi%Documents and Settings%\%current user%\Application Data\Ewketimoil.upi
Remove it with Ad-Aware
- Click (here) to download and install Ad-Aware Free Antivirus.
- Update the definition files.
- Run a full scan of your computer.
Manual removal*
- Scan a system with an anti-rootkit tool.
- Terminate malicious process(es) (How to End a Process With the Task Manager):
itov.exe:3152
itov.exe:2832
%original file name%.exe:1572 - Delete the original Backdoor file.
- Delete or disinfect the following files created/modified by the Backdoor:
%Documents and Settings%\%current user%\Application Data\Keraga\itov.exe (166 bytes)
%Documents and Settings%\%current user%\Local Settings\Temp\tmp49bdb140.bat (177 bytes) - Clean the Temporary Internet Files folder, which may contain infected files (How to clean Temporary Internet Files folder).
- Reboot the computer.
*Manual removal may cause unexpected system behaviour and should be performed at your own risk.