« Hexzone, RansomWare and, Finjan | Main | Ransom - Pay me more! »

2009.04.27

TrackBack

TrackBack URL for this entry:
http://www.typepad.com/services/trackback/6a00d835018afd53ef0115705324dc970b

Listed below are links to weblogs that reference BotnetWeb - Part II:

Comments

Feed You can follow this conversation by subscribing to the comment feed for this post.

keep up the good work guys, i can't wait to see more of these articles.

Here some more details for readers to one of the mentioned .exe, filename was 21ebbf888a25337e.exe

http://www.threatexpert.com/report.aspx?md5=b30dec0ec2b496d772b457435f3180c6
* Submission details:
o Submission received: 29 April 2009, 05:50:59
o Processing time: 6 min 17 sec
o Submitted sample:
+ File MD5: 0xB30DEC0EC2B496D772B457435F3180C6
+ File SHA-1: 0x624324E5726AC51074362B5E7A0751E9B75CDD3B
+ Filesize: 91,136 bytes
* The following files were created in the system:
# Filename(s) File Size File Hash
1 %Windir%\msacm32.drv 89,088 bytes MD5: 0xA70F58DCC4EF5970F080326DE6A69749
SHA-1: 0x2DD8EA11FEC0EAC399D264043A5C9AACF5A303B0
2 [file and pathname of the sample #1] 91,136 bytes MD5: 0xB30DEC0EC2B496D772B457435F3180C6
SHA-1: 0x624324E5726AC51074362B5E7A0751E9B75CDD3B
3 %Windir%\wuasirvy.dll 106 bytes MD5: 0xD610CE7D88980283BA5ECA0E15CA6EC9
SHA-1: 0x4D9238D44DE7E4CA34C33FACA6A1316EF140E30F

Rescan a few minutes ago:
http://www.virustotal.com/analisis/22557c86f56262fc523778891b023a53
File 21ebbf888a25337e.exe received on 04.29.2009 22:55:58 (CET)
Current status: finished
Result: 0/40 (0%)

Found these samples on a customers notebook. The .exe appeared in temp on 12.04. and 13.04. (probably via some porn-site) and are not detected by all AVs I tried.

The 490700....dll was found at various places in ../Macromedia/Common/ like SilentBanker and was started via RUN and audio-drivers.

The .drv was found in system32 (60kb larger than original), also not detected by all AVs I tried. The wua...dll was there as well, but is detected by some AVs.

Could be tracks of a botnetweb-install. ....................

Keep your good work!

FYI, PIRADIUS has popped up several times in my investigations of RBN and Russkrainian cyber crime, so while it is not physically located in The Ukraine, you can bet that the post-RBN Russkrainian criminals involved in this have used PIRADIUS fro several years now.

- ferg


The comments to this entry are closed.