Authored By:
Christopher Bentley – @cbentle2
Description:
IOC for Ramnit, Advanced Malware that has rookit capabilities, and has been seen to drop addtional malware on the infected host including spam engine.
Reports:
http://contagiodump.blogspot.com/2012/01/blackhole-ramnit-samples-and-analysis.html#more
http://www.threatexpert.com/report.aspx?md5=e4633c77362e55dde5fdcda63f826c1b
Indicators:
OR
Process StringList is \\.\631D2408D44C4f47AC647AB96987D4D5
Process Handle Name is !IETld!Mutex
DriverItem/StringList/string is c:\project\demetra\loader~1\drivers\ssdt\driver~1\objfre_win7_x86\i386\SdtRestore.pdb
DriverItem/StringList/string is \Device\631D2408D44C4f47AC647AB96987D4D5
Process StringList contains <%IDBOT%><%REMOTE={*}%><#{*} {*}#>ECHOADDSUBSETDATECONTENT POST
DriverItem/StringList/string is 631D2408D44C4f47AC647AB96987D4D5
AND
Hook HookDescription is SystemCall
Hook Hooking Module contains \LOCALS~1\Temp\
Hook Hooked Module is ntoskrnl.exe
AND
Process StringList contains Micorsoft Windows Service
Process StringList contains TANGrabber
Process Name is services.exe
AND
Process arguments is not C:\WINDOWS\System32\svchost.exe -k netsvcs
Process arguments is not C:\WINDOWS\System32\svchost -k rpcss
Process arguments is not C:\WINDOWS\System32\svchost.exe -k LocalService
Process arguments is not C:\WINDOWS\System32\svchost.exe -k NetworkService
Process arguments is not C:\WINDOWS\System32\svchost -k DcomLaunch
Process Name is svchost.exe
Process arguments is not C:\WINDOWS\System32\svchost.exe -k imgsvc
AND
Process Name is svchost.exe
OR
Process StringList contains LOCALS~1\Temp\~TM4.tmp
Process StringList is Hide Browser v1.1
Process StringList is 220 220 RMNetwork FTP
Process StringList is Ftp Grabber v1.0
Process StringList is Virus Module v1.0 (exe, dll only)
Process StringList is VNC Module v1.0 (Zeus Model)
Process StringList is Byob Ernie Gild Lotto 2002-2006
Process StringList is Reich.exe
Process Handle Name contains CTF.Compart.MutexDefaultS-1-5-21
Process Handle Name contains CTF.Layouts.MutexDefaultS-1-5-21
Process Handle Name contains CTF.TMD.MutexDefaultS-1-5-21
Process Handle Name contains CTF.TimListCache.FMPDefaultsS-1-5-21
Process Handle Name contains CTF.Asm.MutexDefaultS-1-5-21
Process Handle Name contains CTF.LBES.MutexDefaultS-1-5-21
Process Handle Name contains \Start Menu\Programs\Startup
AND
Process StringList is X:\old_backup\Delphi\Mailer4\cl\Sources\clMailMessage.pas
Process StringList is X:\old_backup\Delphi\Mailer4\cl\Sources\clSocket.pas
Process StringList is X:\old_backup\Delphi\Mailer4\cl\Sources\clCertificate.pas
Process StringList is X:\old_backup\Delphi\Mailer4\cl\Sources\clSspiTls.pas
Process StringList is X:\old_backup\Delphi\Mailer4\cl\Sources\clTlsSocket.pas
Process StringList is X:\old_backup\Delphi\Mailer4\cl\Sources\clSocks.pas
Process StringList is X:\old_backup\Delphi\Mailer4\cl\Sources\clTcpClient.pas
Process StringList is TModule_POPPeeper
Process StringList is TModule_Eudora
Process StringList is TModule_Gmail
Process StringList is TModule_IncrediMail
Process StringList is TModule_GroupMailFree
Process StringList is TModule_VypressAuvis
Process StringList is TModule_The_Bat
Process StringList is TModule_Outlook0
Process StringList is TOutlookIdentItem
Download:
5c03d9e7-c67c-45e8-aa2f-326bc5ddc76a.ioc