
Dell SonicWALL UTM Research team discovered a new info stealer Trojan in the wild that steals account information from FTP and Email configuration files. The Trojan also drops a variant of the Zbot Trojan on the system.
The Trojan arrives in the form of an email purporting to be a fax message delivered by eFax Corporate. The user is encouraged to download and execute the attachment to view the fax:

Upon infection the Trojan performs the following DNS queries:
The Trojan adds the following files to the filesystem:
abcd.bat contains the following data. This is used to clean up parts of the infection process:
:ijk del %1 if exist %1 goto ijk del %0 The Trojan adds the following key to the Windows registry to enable startup after reboot:
The Trojan downloads and runs the following files from various remote webservers:

The following encrypted communication was observed between the Trojan and a remote C&C webserver:

The unencrypted form of the above "CRYPTED" data that is sent is as follows. It contains sensitive system information::

The Trojan was observed iterating through the Program Files directory looking for FTP and Email configuration files. It steals credentials from the following FTP and Email softwares if present.
BulletProof FTPSmart FTPTurbo FTPSota's FTPFTP NavigatorFTP CommanderFlashFXPFileZillaCute FTPCore FTPUltra FXPFrigate3FTP ExplorerSecureFXClassic FTPFTPVoyagerWise FTPSeaMonkeyLeech FTPFTPGetter3D-FTPGo FTPBlazeFtpFTPNowPocomailThe Bat!ThunderbirdThe Trojan contains the following common word password list:

SonicWALL Gateway AntiVirus provides protection against this threat via the following signatures:
Share This Article

An Article By
An Article By
Security News
Security News