It is currently Sun May 19, 2013 2:25 am

All times are UTC - 8 hours




Post new topic Reply to topic  [ 27 posts ]  Go to page Previous  1, 2
Author Message
 Post subject: Re: Bat To Exe Converter - Trojan.VkHost creator?
PostPosted: Fri Mar 12, 2010 12:21 pm 
Offline

Joined: Sat Feb 13, 2010 9:46 pm
Posts: 83
Can you get me a valid archive? That drop.io one is coming up corrupted for me too, and I suspect the problem is different versions of 7-Zip.

Do the redirects happen in Internet Explorer or Chrome, or just Firefox?
What version of Firefox do you have?
If you get Firefox 3.6 Portable, then look in the addons list, what do you see? (It's absolutely critical you get 3.6 - previous versions of Firefox allowed addons to specify a hidden tag, which was used to great advantage by malware writers. See here for a prime example of the frustration caused by this kind of thing)


Top
 Profile  
 
 Post subject: Re: Bat To Exe Converter - Trojan.VkHost creator?
PostPosted: Fri Mar 12, 2010 1:30 pm 
Offline

Joined: Mon Nov 02, 2009 7:24 am
Posts: 7
Can you get me a valid archive? That drop.io one is coming up corrupted for me too, and I suspect the problem is different versions of 7-Zip.
>> Sorry, I think I'm done posting archives. You could easily recreate the problem exe based on my 2nd post in this thread which is the 4th overall post. Or, you could use the latest 7-zip to open my archive and simultaneously update your 7-zip to latest! :)

Do the redirects happen in Internet Explorer or Chrome, or just Firefox?
>> Good question, I'm not sure. I'm completely FF focused so it had to be fixed asap. Another person trouble shooting something very similar (maybe the same) said it was only FF.

What version of Firefox do you have?
>> Like I said already "latest" which is 3.6. I guess latest could mean a beta/alpha but that would cause a mess with add ons.

If you get Firefox 3.6 Portable, then look in the addons list, what do you see? (It's absolutely critical you get 3.6 - previous versions of Firefox allowed addons to specify a hidden tag, which was used to great advantage by malware writers. See here for a prime example of the frustration caused by this kind of thing)
>> What do I see? I have a boat load of add ons so I see a ... boat load of add ons! They're all add ons I expect to see if that's what you're asking.

Seriously, thanks for the tip about malware writers doing FF add ons but like I've said several times in this thread with the invisible Bat to Exe running, random FF Google search redirect hijacks, with it stopped and deleted, all is fine. I really don't see how a malware FF add on would be triggered by my invisi Bat to Exe program.


Top
 Profile  
 
 Post subject: Re: Bat To Exe Converter - Trojan.VkHost creator?
PostPosted: Fri Mar 12, 2010 2:23 pm 
Offline
User avatar

Joined: Thu Apr 17, 2008 2:36 pm
Posts: 312
I did my own test of this method with making the bat and converting and running

a) yes some vcheckers see this as a potential dropper this is because (as you have it set up) the file opens (invisibly conhost) and leaves it open yet produces no window

b) my google was not affected on niether IE nor FF (nor safari nor Opera nor Chrome)

thus again I must state that While, Yes this program can be used for malicious means, and can, yes create a trojan from a properly made batch file, it is not injecting any code into the exe.

all this program is doing is UPXing the batch

Code:
File size: 21504 bytes
MD5...: c7c4399bac9247380c82d9fbdfe67f63
SHA1..: ab05ea316e90638e5263531d4abe35a66f07fe42
SHA256: c4ef4bae0d990c8610920b62695dc531f4ce5b98dc062f74bbd4b45325cbec4b
ssdeep: 384:2IiV728hUQ7Y2P/cVEccDdye7kjlWLe7grPiA8jyrMPhTjanbBoZYGYKaNJa
wcuf:2RGuY2P0Vo6r7SiAwyrMRjbyGYbnbcuc

PEiD..: -
PEInfo: PE Structure information

( base data )
entrypointaddress.: 0xe020
timedatestamp.....: 0x498d2b24 (Sat Feb 07 06:33:08 2009)
machinetype.......: 0x14c (I386)

( 3 sections )
name viradd virsiz rawdsiz ntrpy md5
UPX0 0x1000 0x9000 0x0 0.00 d41d8cd98f00b204e9800998ecf8427e
UPX1 0xa000 0x5000 0x4c00 7.90 ac7064cc39f73b7e7c91bea855086519
.rsrc 0xf000 0x1000 0x600 4.44 cc36a02310a0922ccf25195ca428a363

( 7 imports )
> KERNEL32.DLL: LoadLibraryA, GetProcAddress, VirtualProtect, VirtualAlloc, VirtualFree, ExitProcess
> COMCTL32.dll: InitCommonControls
> GDI32.dll: SetBkColor
> MSVCRT.dll: memset
> OLE32.dll: CoInitialize
> SHELL32.dll: ShellExecuteExA
> USER32.dll: IsChild

( 0 exports )

RDS...: NSRL Reference Data Set
-
pdfid.: -
trid..: UPX compressed Win32 Executable (39.5%)
Win32 EXE Yoda's Crypter (34.3%)
Win32 Executable Generic (11.0%)
Win32 Dynamic Link Library (generic) (9.8%)
Generic Win/DOS Executable (2.5%)
sigcheck:
publisher....: n/a
copyright....: n/a
product......: n/a
description..: n/a
original name: n/a
internal name: n/a
file version.: n/a
comments.....: n/a
signers......: -
signing date.: -
verified.....: Unsigned

packers (Kaspersky): UPX
packers (F-Prot): UPX_LZMA

all of that said:
This is not the first report of issues with this program nor this site (the originator site)
http://www.siteadvisor.com/sites/f2ko.de
so I voted down on it we should at least hear the poster out and see if we can have somebody look into it more (with a v-machine or sandboxie)


Top
 Profile  
 
 Post subject: Re: Bat To Exe Converter - Trojan.VkHost creator?
PostPosted: Fri Mar 12, 2010 5:15 pm 
Offline

Joined: Sat Feb 13, 2010 9:46 pm
Posts: 83
jxf011 wrote:
Can you get me a valid archive? That drop.io one is coming up corrupted for me too, and I suspect the problem is different versions of 7-Zip.
>> Sorry, I think I'm done posting archives. You could easily recreate the problem exe based on my 2nd post in this thread which is the 4th overall post. Or, you could use the latest 7-zip to open my archive and simultaneously update your 7-zip to latest! :)

I was hoping for the actual file triggering VT, since different batch files could have different results. I'll see what I can whip up, though.

jxf011 wrote:
Do the redirects happen in Internet Explorer or Chrome, or just Firefox?
>> Good question, I'm not sure. I'm completely FF focused so it had to be fixed asap. Another person trouble shooting something very similar (maybe the same) said it was only FF.

If I can reproduce your Fx redirects, I'll try it in IE & Chrome as well.

jxf011 wrote:
If you get Firefox 3.6 Portable, then look in the addons list, what do you see? (It's absolutely critical you get 3.6 - previous versions of Firefox allowed addons to specify a hidden tag, which was used to great advantage by malware writers. See here for a prime example of the frustration caused by this kind of thing)
>> What do I see? I have a boat load of add ons so I see a ... boat load of add ons! They're all add ons I expect to see if that's what you're asking.

Yep, that's what I was asking.

jxf011 wrote:
Seriously, thanks for the tip about malware writers doing FF add ons but like I've said several times in this thread with the invisible Bat to Exe running, random FF Google search redirect hijacks, with it stopped and deleted, all is fine. I really don't see how a malware FF add on would be triggered by my invisi Bat to Exe program.

A malicious addon wouldn't necessarily be triggered by bat2exe - it could be installed instead. That seems to be what happened in that InformAction thread I linked to.

jxf011 wrote:
see if we can have somebody look into it more (with a v-machine or sandboxie)

Malware-chasing is one of the things I most enjoy doing - count me in. :)
I won't be able to try this tonight, as I've got a boatload of stuff to do, but I'll test it ASAP.


Top
 Profile  
 
 Post subject: Re: Bat To Exe Converter - Trojan.VkHost creator?
PostPosted: Sun Apr 04, 2010 12:06 pm 
Offline

Joined: Sat Feb 13, 2010 9:46 pm
Posts: 83
I just tried converting a simple batch file to an exe; of course, I ran bat2exe inside Sandboxie. For some reason, the exe was never actually generated; bat2exe generated a lot of temp files, but no exe.
For the record, here's the batch file:
Code:
dir
pause

It didn't seem to matter what settings I used, either.
I'm not sure what happened, but I'm not particularly happy about it.

Unless/until we get to see the source for bat2exe, I won't touch it with a 10-foot pole.


Top
 Profile  
 
 Post subject: Re: Bat To Exe Converter - Trojan.VkHost creator?
PostPosted: Sun Apr 04, 2010 12:12 pm 
Offline
User avatar

Joined: Sat Mar 31, 2007 2:38 am
Posts: 902
Location: Kce,PL
computerfreaker wrote:
Malware-chasing is one of the things I most enjoy doing - count me in. :)
I won't be able to try this tonight, as I've got a boatload of stuff to do, but I'll test it ASAP.


computerfreaker wrote:
I just tried converting a simple batch file to an exe; of course, I ran bat2exe inside Sandboxie. For some reason, the exe was never actually generated; bat2exe generated a lot of temp files, but no exe.
For the record, here's the batch file:
Code:
dir
pause

It didn't seem to matter what settings I used, either.
I'm not sure what happened, but I'm not particularly happy about it.

Unless/until we get to see the source for bat2exe, I won't touch it with a 10-foot pole.

Is that how you usually chase malware?
Doesn't seem exhaustive.

_________________
Image


Top
 Profile  
 
 Post subject: Re: Bat To Exe Converter - Trojan.VkHost creator?
PostPosted: Sun Apr 04, 2010 12:26 pm 
Offline

Joined: Sat Feb 13, 2010 9:46 pm
Posts: 83
m^(2) wrote:
Is that how you usually chase malware?
Doesn't seem exhaustive.

I usually have something to work with; it's hard to chase/analyze anything when you can't get a sample. ;)
I didn't want to run it live on my PC, and I don't have a second one; I'll do it anyway, though.


Top
 Profile  
 
 Post subject: Re: Bat To Exe Converter - Trojan.VkHost creator?
PostPosted: Sun Apr 04, 2010 1:12 pm 
Offline

Joined: Sat Feb 13, 2010 9:46 pm
Posts: 83
OK, I just ran bat2exe live; I hope I'm not going to be sorry for this.

I don't know what's going on in bat2exe, but I don't think it's good. I tried to use RegFromApp and ProcessActivityView to attach to bat2exe; when I tried to run bat2exe from within RegFromApp, with "Start tracing immediately" on, bat2exe just showed a blank window. I used Process Monitor instead (which is what I should have done in the first place); bat2exe itself appears to be OK. It wrote a bunch of temp files, then finally converted the batch file to an exe. I made sure the "invisible application" setting was selected.
I then ran test.exe, the compiled batch file, with ProcMon tracking it again. For the most part, the exe seems to be doing fairly standard stuff; it's doing some monkeying with the Internet security zones, though. Here's part of the ProcMon log:

Quote:
[timestamp removed] test.exe 3752 RegOpenKey HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings\Zones SUCCESS Desired Access: Read
(about 2 dozen more reads to HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings\Zones and its subkeys)

Quote:
[timestamp removed] test.exe 3752 RegSetValue HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap\ProxyBypass SUCCESS Type: REG_DWORD, Length: 4, Data: 1
[timestamp removed] test.exe 3752 RegSetValue HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap\IntranetName SUCCESS Type: REG_DWORD, Length: 4, Data: 1
[timestamp removed] test.exe 3752 RegSetValue HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap\UNCAsIntranet SUCCESS Type: REG_DWORD, Length: 4, Data: 1
[timestamp removed] test.exe 3752 RegSetValue HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap\AutoDetect SUCCESS Type: REG_DWORD, Length: 4, Data: 1

Quote:
[timestamp removed] test.exe 3752 RegOpenKey HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings\Lockdown_Zones SUCCESS Desired Access: Read
(a couple of dozen reads to HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings\Lockdown_Zones and its subkeys)

It also did a bunch of reading from HKLM\Software\Microsoft\Cryptography and its subkeys; I'm somewhat inclined to dismiss that as normal behavior, though, as I've seen a lot of legit apps reading from there.

I didn't see any of my Google searches get redirected, and my AV (Microsoft Forefront Client Security) didn't pop up a warning, but I'm still not happy.
* Why wouldn't bat2exe work within Sandboxie? It could clearly create files, since it left a mess of temp files; did it detect the Sandboxie service and terminate? (That's entirely possible; there's a growing number of malware apps that detect virtualization products and shutdown if one is found)
* Why wouldn't bat2exe work when I tried to use RegFromApp on it? (In fairness, bat2exe worked if I ran it, then attached RegFromApp & ProcessActivityViewer to it)
* Why is the executable reading from, and writing to, Internet Zone registry keys? (Once again, in fairness, I've seen other legit apps accessing these keys; I haven't been able to get much information about the keys, except that a lot of malware seems to write to them. If anybody knows exactly what they do, I'd appreciate the info)

I didn't see anything that clearly brands bat2exe as malware, but I still don't want to use it. Then again, most of my friends say I'm overly paranoid. :roll:


Top
 Profile  
 
 Post subject: Re: Bat To Exe Converter - Trojan.VkHost creator?
PostPosted: Tue Apr 06, 2010 10:27 am 
Offline
User avatar

Joined: Tue Apr 06, 2010 10:11 am
Posts: 30
Location: Somewhere in Kentucky
I've found some INTERESTING things when decompiling a converted bat file with hidden set:

Quote:
KERNEL32.DLL COMCTL32.dll GDI32.dll MSVCRT.dll OLE32.dll SHELL32.dll USER32.dll LoadLibraryA GetProcAddress VirtualProtect VirtualAlloc VirtualFree ExitProcess InitCommonControls SetBkColor memset CoInitialize ShellExecuteExA IsChild


Notice the VirtualProtect and VirtualFree? I believe that protects the program from being run in Virtual Environments.

Also Here is the decompiled bat to exe converter lines that are suspicious:

Quote:
KERNEL32.DLL COMCTL32.dll COMDLG32.dll GDI32.dll MSVCRT.dll OLE32.dll SHELL32.dll SHLWAPI.dll USER32.dll LoadLibraryA GetProcAddress VirtualProtect VirtualAlloc VirtualFree ExitProcess ImageList_Add GetSaveFileNameA LineTo free CoInitialize DragQueryFileA PathFileExistsA GetDC

_________________
Over 15 programs coded. All Free, All Portable, and All Under 2 MB


Top
 Profile  
 
 Post subject: Re: Bat To Exe Converter - Trojan.VkHost creator?
PostPosted: Tue Apr 06, 2010 10:33 am 
Offline
User avatar

Joined: Sat Mar 31, 2007 2:38 am
Posts: 902
Location: Kce,PL
rcmaehl wrote:
I've found some INTERESTING things when decompiling a converted bat file with hidden set:

Quote:
KERNEL32.DLL COMCTL32.dll GDI32.dll MSVCRT.dll OLE32.dll SHELL32.dll USER32.dll LoadLibraryA GetProcAddress VirtualProtect VirtualAlloc VirtualFree ExitProcess InitCommonControls SetBkColor memset CoInitialize ShellExecuteExA IsChild


Notice the VirtualProtect and VirtualFree? I believe that protects the program from being run in Virtual Environments.

No. These are standard Windows memory management routines.

rcmaehl wrote:
Also Here is the decompiled bat to exe converter lines that are suspicious:

Quote:
KERNEL32.DLL COMCTL32.dll COMDLG32.dll GDI32.dll MSVCRT.dll OLE32.dll SHELL32.dll SHLWAPI.dll USER32.dll LoadLibraryA GetProcAddress VirtualProtect VirtualAlloc VirtualFree ExitProcess ImageList_Add GetSaveFileNameA LineTo free CoInitialize DragQueryFileA PathFileExistsA GetDC

Nothing suspicious here either.

_________________
Image


Top
 Profile  
 
 Post subject: Re: Bat To Exe Converter - Trojan.VkHost creator?
PostPosted: Tue Apr 06, 2010 10:41 am 
Offline
User avatar

Joined: Tue Apr 06, 2010 10:11 am
Posts: 30
Location: Somewhere in Kentucky
Would you like the decompiled program? I have it and I can barely make heads or tells of it, I don't do pure programming... :(

_________________
Over 15 programs coded. All Free, All Portable, and All Under 2 MB


Top
 Profile  
 
 Post subject: Re: Bat To Exe Converter - Trojan.VkHost creator?
PostPosted: Tue Apr 06, 2010 11:45 am 
Offline
User avatar

Joined: Sat Mar 31, 2007 2:38 am
Posts: 902
Location: Kce,PL
rcmaehl wrote:
Would you like the decompiled program? I have it and I can barely make heads or tells of it, I don't do pure programming... :(

No, thanks. If I wanted, I'd get it myself.
If you don't know programming, don't waste your time, you won't be able to differentiate crapware from legit software, seriously.

_________________
Image


Top
 Profile  
 
Display posts from previous:  Sort by  
Post new topic Reply to topic  [ 27 posts ]  Go to page Previous  1, 2

All times are UTC - 8 hours


Who is online

Users browsing this forum: No registered users and 0 guests


You cannot post new topics in this forum
You cannot reply to topics in this forum
You cannot edit your posts in this forum
You cannot delete your posts in this forum
You cannot post attachments in this forum

Search for:
Jump to:  

Protected by Anti-Spam ACP Powered by phpBB © 2000, 2002, 2005, 2007 phpBB Group