Sponsored by: █ Sparkhost - Hosting Without Compromises! █ Hybrid Performance Web Hosting █ Spark Host Stream Hosting █ Hybrid IRC & IRCd Server Shell Accounts
Polymorphic Virus
#1
Posted 07 October 2010 - 06:14 PM
more infomation: http://threatinfo.tr...Name=PE_LICAT.A
If anyone get the sample. Please post it here,
#2
Posted 08 October 2010 - 12:51 AM
With the limited details, I don't see anything polymorphic in this as well.
#3
Posted 08 October 2010 - 08:22 PM
Analysis of the PE_LICAT.A file infector has revealed further information on this emerging threat.
We have been able to isolate a copy of the main file infector, which we detect as PE_LICAT.A-O. (A main file infector is a file infector which triggers the process of infecting files, but is not infected itself.) It injects itself into the Explorer.exe process, which has two effects. First, it becomes memory resident. Secondly, any file executed afterwards becomes infected with malicious code and is detected as PE_LICAT.A.
We have looked into the pseudorandom domains that LICAT uses to download files from. Every time PE_LICAT.A is executed it attempts to download files from these domains, trying to do so a maximum of 800 times.
The following top-level domains are used by these created domains:
- biz
- com
- info
- org
- net
These domains appear to link PE_LICAT and ZeuS. Several of the domains that PE_LICAT was scheduled to download files from in late September are confirmed to be known ZeuS domains in that period. One of these domains, {BLOCKED}klklmssrr.com, was registered approximately one week before it would have been used by PE_LICAT. Another domain was hosted on an ISP that has seen significant levels of ZeuS-related activity in the past, and is a known haven for cybercrime.
We were able to obtain a sample from these LICAT-related domains, which we currently detect as TSPY_ZBOT.BYZ. The downloder file shows certain behavior often associated with ZeuS. However, downloader capability is not a functionality seen in ZeuS to date, therefore further analysis is taking place on this file. The file drops a copy of the main file infector, PE_LICAT.A-O. Files exhibiting similar behavior to the downloader will be proactively detected as TSPY_ZBOT.SMEQ.
PE_LICAT infections appear to have hit the North American and European regions hardest, with Latin America the lightest hit according to our Smart Protection Network™ feedback.
Trend Micro protects product users from this attack via the Trend Micro™ Smart Protection Network™. The domains generated by PE_LICAT are being analyzed in real-time and blocked as necessary. In addition, infected files are being detected and cleaned as well.
Read more: http://blog.trendmic.../#ixzz11peg5dFl
#4
Posted 09 October 2010 - 06:50 AM
Though, It has some interesting features like a backdoor and keystroke logger.
http://www.threatexp...LICAT.A&x=9&y=8
0 user(s) are reading this topic
0 members, 0 guests, 0 anonymous users












