Malware YolRootX

Marco Ramilli
Date
6 April 2010
Read
Share

Hi Folks,

with no time for good posts, I just paste here some analysis performed on YolRootX, a new malware that I analyzed yesterday.

File System Changes:

(Adding a new certificate!)
- C:Documents and SettingsAdministratorApplication DataMicrosoftCryptoRSAS-1-5-21-1078081533-1677128483-1801674531-500699c4b9cdebca7aaea5193cae8a50098_5fc4e98d-1101-4864-b0bf-e0b3f6d9d878
(Some cookies ... just in case 😉 )
- C:Documents and SettingsAdministratorCookiesadministrator@globo[1].txt

- C:Documents and SettingsAdministratorCookiesadministrator@microsoft[2].txt
- C:Documents and SettingsAdministratorCookiesadministrator@www.globo[1].txt
(hidden content into Temp)
C:Documents and SettingsAdministratorLocal SettingsTemp~DFC517.tmp

(Internet Explorer settings ... )

..softwaremicrosoftinternet explorermain
(Ahh Ahmm ! autostart key under reguser !)
usercurrentsoftwareMicrosoftInternet ExplorerToolbarLocked = 01000000

(Did I ask for these queries ? 😉 )

Query DNS: www.oviedolocal3476.com
Query DNS: www.globo.com
Query DNS: ads.globo.com
Query DNS: ads.img.globo.com
Query DNS: fpdownloadocument.macromedia.com
Query DNS: fpdownloadocument.macromedia.com.gateway.2wire.net
Query DNS: activex.microsoft.com
Query DNS: codecs.microsoft.com
Query DNS: video.globo.com
Query DNS: www.google-analytics.com
Query DNS: imagem2.buscape.com.br
Query DNS: www.google.com
Query DNS: clients1.google.com
Query DNS: id.google.com
(I don't speak spanish at all ...)
Internet connection: Connects to "65.55.13.243" on port 80 (TCP - HTTP).
Internet connection: Connects to "201.7.178.53" on port 80 (TCP - HTTP).
Internet connection: Connects to "74.125.19.113" on port 80 (TCP - HTTP).
(Processes, new service and binary injection ?? )
Created process: (null),explorer.exe https://www.globo.com,(null)
Opened a service named: ShellHWDetection
Injected code into process: explorer.exe
Injected code into process: iexplore.exe
( loading interesting Windows API)
LoadLibrary(netapi32.dll)
LoadLibrary(kernel32.dll)
LoadLibrary(version.dll)
LoadLibrary(explorer.exe)
LoadLibrary(comctl32.dll)
LoadLibrary(shell32.dll)
LoadLibrary(windowsshell.manifest)
LoadLibrary(browselc.dll)
LoadLibrary(wsock32)
LoadLibrary(mswsock.dll)
LoadLibrary(hnetcfg.dll)
LoadLibrary(wshtcpip.dll)
LoadLibrary(actxprxy.dll)
LoadLibrary(msmsgs.exe)
LoadLibrary(jscript.dll)

Marco Ramilli
Date
6 April 2010
Read
Share
← Go back
Latest Posts

i-SOON Data Leak: Key Points

Introduction i-SOON (上海安洵), a prominent contractor for various Chinese government agencies such […]

Date
26.02.2024
Duration
5 min
Text
Marco Ramilli

X Gold Badges: a new proliferating market

When I saw a threat actor hijacking the X account of Google's […]

Date
08.01.2024
Duration
5 min
Text
Marco Ramilli

Technical Data Sheet: LOCKBIT 3.0

LOCKBIT 3.0 is a notorious Ransomware Group that was first identified on […]

Date
20.12.2023
Duration
5 min
Text
Marco Ramilli
1 2 3 236
Back to Top
magnifier