TROJ_BUNITU.YAY
Troj/Bunitu-L (Sophos) ,Trojan horse Proxy.BDLC (AVG) ,W32/Yakes.EZLE!tr (Fortinet) ,Trojan.Win32.Yakes.ezle (Kaspersky) ,TrojanProxy:Win32/Bunitu.F (Microsoft) ,RDN/Generic Proxy!i (McAfee) ,a variant of Win32/TrojanProxy.Agent.NWT trojan (Eset) ,Trojan.Win32.Generic!BT (Sunbelt)
Windows 2000, Windows Server 2003, Windows XP (32-bit, 64-bit), Windows Vista (32-bit, 64-bit), Windows 7 (32-bit, 64-bit)
Threat Type: Trojan
Destructiveness: No
Encrypted:
In the wild: Yes
OVERVIEW
This Trojan may be dropped by other malware.
TECHNICAL DETAILS
Arrival Details
This Trojan may be dropped by other malware.
Autostart Technique
This Trojan adds the following registry entries to enable its automatic execution at every system startup:
HKEY_CURRENT_VERSION\Software\Windows\
CurrentVersion\Run
{File Name} = "rundll32 "{Malware Path and File name}",{File Name}"
Other System Modifications
This Trojan adds the following registry keys:
HKEY_LOCAL_MACHINE\Software\Microsoft\
Windows NT\CurrentVersion\Winlogon\
Notify\{File Name}
It adds the following registry entries:
HKEY_LOCAL_MACHINE\Software\Microsoft\
Windows NT\CurrentVersion\Winlogon\
Notify\{File Name}
Impersonate = "1"
HKEY_LOCAL_MACHINE\Software\Microsoft\
Windows NT\CurrentVersion\Winlogon\
Notify\{File Name}
"Asynchronous" = "1"
HKEY_LOCAL_MACHINE\Software\Microsoft\
Windows NT\CurrentVersion\Winlogon\
Notify\{File Name}
MaxWait = "1"
HKEY_LOCAL_MACHINE\Software\Microsoft\
Windows NT\CurrentVersion\Winlogon\
Notify\{File Name}
DllName = "{Malware Path and File name}"
HKEY_LOCAL_MACHINE\Software\Microsoft\
Windows NT\CurrentVersion\Winlogon\
Notify\{File Name}
Startup = "{File Name}"
It creates the following registry entry(ies) to bypass Windows Firewall:
HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\
Services\SharedAccess\Parameters\
List
{Malware Path and File name} = "{Malware Path and File name}:*:Enabled:{File Name}"
Other Details
This Trojan connects to the following possibly malicious URL:
- ns0.{BLOCKED}pizzaeater.me.uk
- ns1.{BLOCKED}pizzaeater.me.uk
- ns8.{BLOCKED}pizzaeater.me.uk