Virus Characteristics
“PWS-Zbot.gen.akq” is Trojan gather information, such as password credentials and personal information. The collected data will be sent to the remote attacker. It may try to hack servers using ftp client and download other malicious files to the compromised machine.
Upon Execution, the Trojan creates a file into the below location:
Upon execution the Trojan tries to connect to the following URL to download other payloads and to send the collected data from the compromised machine.
- hxxp://66.55.[Removed].150:8080/forum/viewtopic.php
- hxxp://66.55. [Removed].151:8080/forum/viewtopic.php
- hxxp://hote[Removed]on.com/oTW0P0v.exe
- hxxp://riso[Removed]eb.netsons.org/vua.exe
- hxxp://elektrab[Removed]k.cz/hs9HBpbT.exe
- hxxp://46.252. [Removed].14/cgi-sys/suspendedpage.cgi
- 150.89.55. [Removed]:8080
- srv-hg1.ne[Removed]ns.net:http
- www4.p[Removed]i.cz:http
- busine[Removed]ck-160-60.on3.ontelecoms.gr:http
When Trojan gets executed, the following registry entries have been added to the system.
- HKEY_USERS\S-1-5-[Varies]\Software\WinRAR
And the following registry values have been added to the System:
- HKEY_USERS\S-1-5-[Varies]\Software\WinRAR\
“HWID”= “7B 35 36 46 32 41 32 41 30 2D 43 30 36 37 2D 34 43 35 34 2D 38 39 38 38 2D 37 42 36 33 34 37 38 39 38 42 37 45 7D”
- HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap\
“UNCAsIntranet”=”0”
- HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap\
“AutoDetect”=”1”
And the following registry values have been deleted from the System:
- HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap\ProxyBypass
- HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap\IntranetName
- HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap\ProxyBypass
- HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap\IntranetName
The following are the information collected from the infected machine and send it to the remote attacker through remote port 8080
- HostName
- GetNativeSystemInfo
- GetLocaleInfoA
- GetSystemInfo
- gethostbyname
Captured POST request:
POST %s HTTP/1.0
Host: %s
Accept: */*
Accept-Encoding: identity, *;q=0
Content-Length: %lu
Connection: close
Content-Type: application/octet-stream
Content-Encoding: binary
User-Agent: Mozilla/4.0 (compatible; MSIE 5.0; Windows 98)
The Trojan tries to hack servers using below password list:
• password
• phpbb
• qwerty
• jesus
• abc123
• letmein
• test
• love
• password1
• hello
• monkey
• dragon
• trustno1
• iloveyou
• shadow
• christ
• sunshine
• master
• computer
• princess
The Trojan tries to search and hack a user accessed server using the below mentioned FTP clients with the above commonly used password list.
- FileZilla
- BulletProof Software
- SmartFTP
- CuteFTP
- TurboFTP
- FTP Explorer
- Frigate3
- VanDyke
- FTPRush
- LeapFTP