Auteur Sujet: [MMPC]MSRT June '12 - cleanup on aisle one  (Lu 4519 fois)

0 Membres et 1 Invité sur ce sujet

Hors ligne igor51

  • Admin
  • Mega Power Members
  • *****
  • Messages: 10419
[MMPC]MSRT June '12 - cleanup on aisle one
« le: juin 30, 2012, 04:01:41 »
MSRT June '12 - cleanup on aisle one

<div class="ExternalClassE03C32A100434167AFF8BE8BB9674564">
<p>In the June '12 installment of the <a href="http://www.microsoft.com/security/pc-security/malware-removal.aspx">Microsoft Malicious Software Removal Tool</a> (MSRT), we take on two threat families - <a href="http://www.microsoft.com/security/portal/Threat/Encyclopedia/Entry.aspx?Name=Win32/Kuluoz">Win32/Kuluoz</a> and <a href="http://www.microsoft.com/security/portal/Threat/Encyclopedia/Entry.aspx?Name=Win32/Cleaman">Win32/Cleaman</a>. This post includes information about Kuluoz as we'll discuss Cleaman later this month.</p>
<p>Win32/Kuluoz is a multi-component trojan family that that attempts to steal passwords that are stored in certain applications, and sensitive files from your computer. The trojan implements a downloader component that we observed being distributed via spam email as an attachment.</p>
<p>As is common with trojans, Kuluoz is known to use a file icon that comes from a popular application. In this case, it is a PDF document, and is installed into the Application Data subfolder, such as this:</p>
<p><a href="http://blogs.technet.com/cfs-file.ashx/__key/communityserver-blogs-components-weblogfiles/00-00-00-62-58/6052.appdata.png"><img border="0" alt="" src="http://blogs.technet.com/resized-image.ashx/__size/550x0/__key/communityserver-blogs-components-weblogfiles/00-00-00-62-58/6052.appdata.png" /></a><br /><br />Image 1 - View of Win32/Kuluoz stored on an infected computer</p>
<p>As for technique, Kuluoz doesn't innovate &ndash; it injects its payload into legitimate Windows executables like "svchost.exe". It is able to load modules that extend its abilities to perform additional payloads, including FTP password-theft and data file stealing, similar to other families of trojans, such as <a href="http://www.microsoft.com/security/portal/Threat/Encyclopedia/Entry.aspx?Name=Win32/Dofoil">Win32/Dofoil</a>, which we <a href="http://blogs.technet.com/b/mmpc/archive/2011/11/22/msrt-november-dofoil.aspx">included in MSRT previously</a>.</p>
<p>One thing we should mention is that the downloader component of Kuluoz also tries to send requests to some legitimate websites with the similar patterns used in C&amp;C communication:</p>
<p><a href="http://blogs.technet.com/cfs-file.ashx/__key/communityserver-blogs-components-weblogfiles/00-00-00-62-58/1016.code.png"><img border="0" alt="" src="http://blogs.technet.com/resized-image.ashx/__size/550x0/__key/communityserver-blogs-components-weblogfiles/00-00-00-62-58/1016.code.png" width="640" height="71" /></a></p>
<p>Image 2 - Legitimate domains mixed with malware domains as requested by Kuluoz</p>
<p>As visible in the above image, some of the domains requested by the malware include known 'good' domains, such as bing.com, twitter.com and google.com which results in a page not found error. It appears that this technique is performed by the malware to possibly confuse the human eye when reviewing access logs.</p>
<p>For additional details, please look into our <a href="http://www.microsoft.com/security/portal/Threat/Encyclopedia/Entry.aspx?Name=Win32/Kuluoz">Win32/Kuluoz</a> family description.</p>
<p></p>
<p>-- MMPC</p>
</div><div style="clear:both;"></div><img src="http://blogs.technet.com/aggbug.aspx?PostID=3503476" width="1" height="1">
Source: MSRT June '12 - cleanup on aisle one

Tags: