The initial infection came to my attention from an end user. He had reported all Google searches from his browser seemed to be forwarding to hxxp://findgala.com and he was getting warnings about malware on his computer. the system infected was a reasonably up to date Windows 7 notebook. the system was missing the latest patch for Adobe Flash (v 10.1.102.64). the user did not have administrator privileges, the windows firewall was enabled, Internet Explorer 8 with the default of medium/high security was set for the Internet Zone, and Symantec Endpoint 11.X was installed with up to date definition files. Note that Windows UAC was NOT enabled.
A quick assessment of the system determined it had been infected with some form of scareware. All existing desktop shortcuts had been removed and two shortcuts named "Computer" and "Internet Security Suite" remained. these pointed to "C:ProgramData891b6IS958.exe /z" and "C:ProgramDatae6db66ISe6d_2229.exe /hkd" respectively. the folder containing the executable was marked hidden and I noted the process was running via TACKIST /SVC. an icon running in the system tray when accessed presented the following screen.
Symantec Endpoint Protection seemed to be neutered by the infection as did several other Windows tools including Task Manager. Initial searching on the internet for the title of the malware only pulled links to legitimate Anti Malware products including CA, Zone Alarm, and Verizon's Internet Security Suite service.Virus Total returned the following analysis. here is a summary of the file submitted:
File name: ISe6d_2229.exe
File Type: Windows 32 bit Portable Executable
MD5: 699ebebcac9aaeff67bee94571e373a1
SHA1: ed763d1bc340db5b4848eeaa6491b7d58606ade2
File size: 3590656 bytes
First seen: 2010-11-14 01:20:29
Last seen: 2010-11-16 15:52:22My general impression of the GUI was this was a well designed piece of code. I imaged the system with dd and instructed the desktop engineers to wipe the system and reset all the user passwords. this proved to be a mistake on my part as I did not verify my image before they wiped the system. Later I found myself unable to boot the raw image in VMware after converting it to a VMDK with Raw2VMDK (blue screen on loading the OS).
Static Analysis
I began with static analysis of the file system by mounting the image with FTK Imager Lite. I exported the Master File Table and parsed it with analyzeMFT . With the estimated time of infection obtained from the victim I was able to pinpoint the file's created and modified during the initial infection.
The initial few files listed in the MFT caught my attention first.
Record Type Parent Filename 63861 Folder 602 e6db66 63915 File 2755 TASKKILL.EXE-8F5B2253.pf 63926 File 2755 SETUP_2229[1].EXE-11C68EE8.pf 63923 File 63861 ISe6d_2229.exe The two prefetch files should give a hint of the name and location of the payload. I use Prefetch Parser to parse the C:WindowsPrefetch folder to obtain some more details:
Record File Times Run UTC Time SETUP_2229[1].EXE-11C68EE8.pf SETUP_2229[1].EXE 1 Sat Nov 13 01:16:53 2010 TASKKILL.EXE-8F5B2253.pf TASKKILL.EXE 1 Sat Nov 13 01:16:53 2010 RUNDLL32.EXE-80EAA685.pf RUNDLL32.EXE 1 Sat Nov 13 01:17:16 2010 Further analysis of the .pf files gave me the location and names.
SETUP_2229[1].EXE-11C68EE8.pf
USERS%USERNAME%APPDATALOCALMICROSOFTWINDOWSTEMPORARY INTERNET FILESCONTENT.IE5G4KYBRHHSETUP_2229[1].EXE
TASKKILL.EXE-8F5B2253.pf
USERS%USERNAME%APPDATALOCALMICROSOFTWINDOWSTEMPORARY INTERNET FILESCONTENT.IE5G4KYBRHHANPRICE=85[1].HTM
RUNDLL32.EXE-80EAA685.pf
PROGRAMDATAE6DB66ISE6D_2229.EXEIt does appear the sample originated from the web. Unfortunately, I could not locate SETUP_2229[1].EXE or ANPRICE=85[1].HTM in the image. Most likely overwritten after several days of use post infection, I moved on the parsing the Internet browser history by using MiTeC Windows File Analyzer and began parsing the last few web sites and searches completed by the user. Unsuccessful in locating the source of the payload, I was not able to verify if it was delivered via a vulnerability or user interaction.
I moved on to use the MFT to locate all files associated with the infection and export the hashes. here is a summary files found in the /[root]/ProgramData folder:
MD5 File cd407baa9a55b9c303f0c184a68acc5c E6DB666139ba67beb5a1febb1e8cfc73a42e9c.ocx 699ebebcac9aaeff67bee94571e373a1 E6DB66ISE6D_2229.EXE 2e317d604f25e03b8e8448c6884f64e3 E6DB66ISS.ico 3ee5ee57af2f62a47d2e93e9346b950f E6DB66mcp.ico be44f801f25678e1ffdd12600f1c0bc7 ISKPQQMSISXPLLS.cfg The following summarizes files found in the /[root]/users/%username%/ folder:
MD5 File 2b7509a2221174a82f6a886bbdd2e115 DesktopComputer.lnk fb16300f2f9799376807b13ad8314ca2 DesktopInternet Security Suite.lnk fd00cfeecc333aedc56fd428f2b9b5ba AppDataRoamingInternet Security SuiteInstructions.ini 4635f17db7d2f51651bebe61ba2f4537 AppDataRoamingMicrosoftWindowsRecentANTIGEN.dll 6032703c3efc5f3d3f314a3d42e2a500 AppDataRoamingMicrosoftWindowsRecentcb.exe 12ddf77984d6f2e81a41f164bea12a1c AppDataRoamingMicrosoftWindowsRecentcid.sys 81c9ad6037c14537044b3e54d8b84c99 AppDataRoamingMicrosoftWindowsRecentddv.exe f28c20c6df79e9fe68b88fb425d36d57 AppDataRoamingMicrosoftWindowsRecenteb.sys 6274e77cd16d6dbec2bb3615ff043694 AppDataRoamingMicrosoftWindowsRecentenergy.drv a3342f285bfb581f0a4e786cc90176d2 AppDataRoamingMicrosoftWindowsRecentenergy.sys 1ac2fb2dbd0023b54a8f083d9abbf6db AppDataRoamingMicrosoftWindowsRecentexec.exe 2dc3df846ff537b6c3e6d74475a0d03d AppDataRoamingMicrosoftWindowsRecentFW.drv a32f789b1b6f281208fa1c8d54bf8cdc AppDataRoamingMicrosoftWindowsRecentgid.dll b48d1cc8765719a79a9352e2b8f891ef AppDataRoamingMicrosoftWindowsRecenthymt.exe 532c6465f4dd9c7bce31b7a7986e3270 AppDataRoamingMicrosoftWindowsRecenthymt.sys f941f6eedf5b33a0b49b9787d5f0dfc2 AppDataRoamingMicrosoftWindowsRecentkernel32.sys 2ff0c3a804b85d3e7e6487d9bece6416 AppDataRoamingMicrosoftWindowsRecentPE.dll 454f06575c9214f7b9cb01c606fd72fe AppDataRoamingMicrosoftWindowsRecentPE.sys 243b5a8a95bb4f8822790b8f0c81b82a AppDataRoamingMicrosoftWindowsRecentppal.exe 9d34330ec68d148cc5701d6cd279c84c AppDataRoamingMicrosoftWindowsRecentSICKBOY.drv 493fc17532f9b6ac330dbdb3a01a5361 AppDataRoamingMicrosoftWindowsRecentsld.drv d0d210a62cb66ff452e9a5cfc8e8f354 AppDataRoamingMicrosoftWindowsRecentSM.sys a2ca707ee60338ac5ec964f7685752ba AppDataRoamingMicrosoftWindowsRecentstd.dll a1e25ab2f19565f707d85e471f41e08f AppDataRoamingMicrosoftWindowsRecentsnl2w.dll I also noted that the hosts file had been modified at the time of infection. the following is a sample of entries that had been added (note: additional countries root domain entries for the top search engines were also added but are not included in this analysis for simplicity's sake):
74.125.45.100 4-open-davinci.com
74.125.45.100 securitysoftwarepayments.com
74.125.45.100 privatesecuredpayments.com
74.125.45.100 secure.privatesecuredpayments.com
74.125.45.100 getantivirusplusnow.com
74.125.45.100 secure-plus-payments.com
74.125.45.100 www.getantivirusplusnow.com
74.125.45.100 www.secure-plus-payments.com
74.125.45.100 www.getavplusnow.com
74.125.45.100 safebrowsing-cache.google.com
74.125.45.100 urs.microsoft.com
74.125.45.100 www.securesoftwarebill.com
74.125.45.100 secure.paysecuresystem.com
74.125.45.100 paysoftbillsolution.com
74.125.45.100 protected.maxisoftwaremart.com
69.72.252.252 www.google.com
69.72.252.252 google.com
69.72.252.252 www.google.no
69.72.252.252 www.google-analytics.com
69.72.252.252 www.bing.com
69.72.252.252 search.yahoo.com
69.72.252.252 www.youtube.comUsing bintext to pull the strings from ISe6d_2229.exe provided a few interesting things of note. Specifically a company and product name of "limnol" and file and product version of "1.1.0.1010". Searches for this reference with some added keywords found some additional submissions to virus total but nothing that was not already known from my earlier submission.
There were also strings associated with a Microsoft Windows manifest file. such a file can be embedded in software by the developer to instruct Windows Vista and Windows 7 on what Privileges the software needs to run as. the default setting of "run as the user" was obtained from the strings:
<security>
<requestedprivileges>
<requestedexecutionlevel level="asInvoker" uiaccess="false"></requestedexecutionlevel>
</requestedprivileges>
</security>I continued the analysis by taking a look at the Windows registry. this was done by exporting the HKCU and HKCM hives from the raw image and using both RegRipper and MiTeC Windows Registry Recovery to analyze the entries. the HKCU run key contained an entry to autostart the executable on startup.
[HKEY_CURRENT_USERSoftwareMicrosoftWindowsCurrentVersionRun]
"Internet Security Suite"=""C:ProgramDatae6db66ISe6d_2229.
exe" /s /d"In addition, I was able to verify that the registry contained an entry for findgala.com under:
[HKEY_CURRENT_USERSoftwareMicrosoftInternet ExplorerSearchScopes]
"URL"="http://findgala.com/?&uid=2229&q=searchTerms"The [HKEY_CURRENT_USERSoftwareInternet Security Suite] key contained several subkeys within it. the entries here seemed to be similar to the contents of the Instructions.ini file found earlier in the appdata folder of the user profile. this file resided in a hidden folder with the same name as the registry key. I have listed one entry as an example here.
[HKEY_CURRENT_USERSoftwareInternet Security Suite23071C180E1E]
"3016131C2F0B18311F0CF4D5EBEEE1"="4746574B4E544E4D4F4FA0B0B8B2B5BFB7BEA8D9C7"
"23071C180E1E31180D0CE1E6E7"=""
"2205012C0A1F2814131A"="4746574B4E544E4D4F4FA0B0B8B3BDBFB2B7A8D9C7"
"3A160B0D2E090534100CF4F3F7E0F0ECE9E9"="4746574B4E544E4D4F4FA0B0B8B2B5BFB7BEA8D9C7"
"3A160B0D3C1E19192E3BCD"="4746574B4E544E4D4F4FA0B0B8B3BDBFB2B7A8D9C7"
"3A160B0D2F0B181C0A1A"="4746574B4E544E4D4F4FA0B0B8B3BDBFB2B7A8D9C7"
"3A160B0D34140E101F13D5F1E6E2F0E0"="4746574B4E544E4D4F4FA0B0B8B2B5BFB7BEA8D9C7"
"3E22081D1B0F19"="46"
"24181415181A1F16"=""
"2205012C0A1F1D091B2DF5EFC1ECF1EBF2"="46"
"3E1E1C1D1F15290D1A1EF4E4C1ECF1EBF2"="46"
"3B1E0A0B15093F120B11F4"="46"
"3218151813154C"=""
"23071C180E1E"="46"Lastly, the [HKEY_LOCAL_MACHINESOFTWAREMicrosoftWindows NTCurrentVersionImage File Execution Options] key had several entries for what appeared to be legitimate software, tools, and other forms of malware. Entries included; taskmgr.exe, rtvscan.exe (Symantec Endpoint Protection), and dozens of other programs. All legitimate and illegitimate software was being blocked via an entry for debugger with a value of "svchost.exe".
Dynamic Analysis
I began dynamic analysis by first attempting to infect a virtualized Windows 7 system in my lab (Note: all initial attempts were with administrator privileges with UAC disabled). Running the executable seemed to generate a runtime error, so I attempted to run it from the command prompt with the /hkd switch found in the desktop shortcut during static analysis. Process Monitor was used in an attempt to capture all file, registry, and network connection changes during infection. the following error was displayed;
Thinking it picked up on Process Monitor, I tried again but without procmon.exe but I was presented with the same error. it seemed that this sample was VM aware. Again I attempted to infect a clean install of Windows 7 on physical hardware with procmon.exe and again, I was met with failure. I turned to utilizing CaptureBat to monitor file and registry changes during install. Infection proceeded but I noted my sample used for analysis had been removed. on further inspection, it appeared that a .bat file was the culprit. the contents of the file were as follows;
MD5 FileName
329e8a313f20cd8b4ebf67642331c007 UsersbugbearAppDataLocalTempdel.bat
:Repeat
del "C:UsersbugbearDesktope6db66ISE6D_~1.EXE"
if exist "C:UsersbugbearDesktope6db66ISE6D_~1.EXE" goto Repeat
del "C:UsersbugbearAppDataLocalTempdel.bat"I also noted the name of the files and folders associated with the malware seem to vary on each infection. Verification of hashes proved that it was indeed the same malicious program however. File and registry monitoring verified the findings from the static analysis and I noted some additional changes as well. it appeared the rogue software attempts to disable UAC by editing the following registry keys;
registry: SetValueKey C:UsersbugbearDesktope6db66ISe6d_2229.exe -> HKLMSOFTWAREMicrosoftWindowsCurrentVersionPoliciesSystemConsentPromptBehaviorAdmin
registry: SetValueKey C:UsersbugbearDesktope6db66ISe6d_2229.exe -> HKLMSOFTWAREMicrosoftWindowsCurrentVersionPoliciesSystemConsentPromptBehaviorUser
registry: SetValueKey C:UsersbugbearDesktope6db66ISe6d_2229.exe -> HKLMSOFTWAREMicrosoftWindowsCurrentVersionPoliciesSystemEnableLUAAdditional registry entries in HKEY_Current_User were also modified. Including the Internet Explorer proxy and wpad settings under [HKCUSoftwareMicrosoftWindowsCurrentVersionInternet Settings]. Additionally, rather than modify the host file directly, the executable seemed to create a temporary host file, remove the old one, and replace it with this new version.
file: Write C:UsersbugbearDesktope6db66ISe6d_2229.exe -> C:WindowsSystem32driversetchost_new
file: Delete C:UsersbugbearDesktope6db66ISe6d_2229.exe -> C:WindowsSystem32driversetchosts
file: Write C:UsersbugbearDesktope6db66ISe6d_2229.exe -> C:WindowsSystem32driversetchosts
file: Delete C:UsersbugbearDesktope6db66ISe6d_2229.exe -> C:WindowsSystem32driversetchost_newTypical "features" associated with scareware seemed to be included with this sample. the rogue software begins a "scan" of the infected system immediately upon execution. Scan results display "infected" files located in [root]Users%username%AppDataRoamingMicrosoftWindowsRecent folder identified during static analysis.
Please note, no attempt was made to identify these files as legitimate malware by myself, although that may be an interesting exercise for another time. Not unlike an episode of the Soprano's, the victim is intimidated into buying protection and is offered several opportunities to buy a subscription. Multiple subscription options are available.
At one point my lab system spewed a blood curdling scream from its speakers before displaying yet another option to "protect" oneself (a little over the top if you ask me). my favorite feature goes to Chat Support however.
I do not think Jane appreciated my bluntness. Network connections for both the subscription service and chat support sessions were collected with the following script which leverages the netstat command.
for /L %1 in (0,0,0) do netstat -anob>>C:netstat.txtBoth IP addresses associated with the subscription service and chat support sessions were registered to hosting providers here in the US. the strangest behavior observed however, was captured with Process Explorer and Wireshark post infection. Multiple instances of ping.exe running under cmd.exe were noted. Upon examination of the packet capture, it appeared the processes were spewing ICMP and SYN packets to two IP Addresses registered to .RU domains.
Soon after this behavor was noted. the executable associated with the infection was mysteriously removed from the system. Attempts to duplicate this behavior later failed.
Further analysis of the infection and sample was done without administrator rights and with UAC disabled. no edit of the hosts file or registry keys in HKLM were noted, however. the malware still setup shop within the ProgramData and User Profile locations noted with the earlier analysis but the fact the user with the original infection had no administrator rights and the host file and HKLM keys were modified remains a bit of a mystery. one might speculate, the original payload might behave differently.
Further Google searching utilizing these findings led me to Microsoft's Malware Protecton Center write-up on Rogue:Win32/FakeVimes. Although Virus Total had not indicated such, it would seem our sample has had many aliases and upgrades.
Lessons Learned
All in all I learned a lot and had fun analyzing the sample (it beats watching sitcoms). few things I noted for future analysis attempts.
- Always verify your images and keep the original copy if possible (aka don't be a dumbass Tim)
- Static file forensics techniques can be very useful during malware analysis
- Have multiple tools that can perform similar tasks is sometimes needed
- Fear is a powerful marketing angle and the bad guys are getting better at it
Feel free to ping me if you would like a copy of the sample. I would be more than happy to trade notes with others.
Security Braindump: Not Just Another Analysis of Scareware
