Results 1 to 3 of 3

Thread: New Threat: Infostealer.Phax

  1. #1
    Member
    Join Date
    Jun 2006
    Posts
    42

    Exclamation New Threat: Infostealer.Phax

    Spybot should add this new threat for detection: Infostealer.Phax




    When the Trojan is executed, it creates the following file:

    %System%\wnvdsf.ax

    Next, the Trojan creates the following registry subkey:

    HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\VGADown

    The Trojan also adds the following winsock service provider:
    Name: MSAFD Tcpip [TCP/IP]
    GUID: {D69BD79E-10DD-43A0-0028-5F1530000100}

    The Trojan downloads the file server.exe from the following location:
    hxxp...wxx.club8.tw/serve

    The file server.exe then drops the following files:

    * avp.exe
    * hsvwer2.dll



    The file avp.exe is installed as the following service:
    VGADown

    The file hsvwer2.dll is installed as a Layered Service Provider.


    The Trojan may download a configuration file from the following location:
    .fh689.com/gunfile/fileo

    It may then download the file svch.exe from the following location:
    .fh689.com/gunfile/svch

    The file svch.exe drops the following files:

    * lsass.exe
    * md6media.dll



    The file md6media.dll is installed as a Layered Service Provider.

    The Trojan then targets several Taiwanese online gaming Web sites and games, including the following:

    * tw.gamania.com (Taiwanese game Web site, which operates 19 online games)
    * gameflier.com (Taiwanese game Web site, which operates 14 online games)
    * Rexue Jianghu online
    * Silkroad Online
    * Rohan



    The Trojan monitors Internet activity for the following strings:

    * cardno
    * cardanswer
    * bankpass
    * shoppass
    * tradepass
    * groupid
    * grouppass
    * user
    * pass
    * perpass
    * username
    * password
    * gashpass
    * gashid
    * name
    * personid
    * birthday
    * newgashpass
    * passhint
    * gameaccount
    * newgamepass


    It then gathers and sends sensitive information to a remote location.
    Last edited by tashi; 2007-04-05 at 23:42. Reason: Disabled three urls
    UNITE
    Unified Network of Instructors and Trained Eliminators

    ASAP
    Alliance of Security Analysis Professionals™

  2. #2
    Spybot Advisor Team [Retired] md usa spybot fan's Avatar
    Join Date
    Oct 2005
    Posts
    5,859

    Default

    SpySentinel:

    Quick question. Was this information gathered independently or are you quoting the signatures of Infostealer.Phax from some other source?

    Getting an answer is one thing, learning is another.


    Microsoft Windows XP Home Edition running on a 2.40GHz Intel® Pentium® 4 Processor with 512 MB of RAM and a 533 MHz System Bus.

  3. #3
    Member of Team Spybot tashi's Avatar
    Join Date
    Oct 2005
    Location
    USA
    Posts
    30,959

    Default

    md usa spybot fan.

    http://www.symantec.com/enterprise/s...222-99&tabid=2

    Writeup By: Robert X Wang

    I'd think most antivirus vendors will be covering this one soon.
    Microsoft MVP Reconnect 2018-
    Windows Insider MVP 2016-2018
    Microsoft Consumer Security MVP 2006-2016

Posting Permissions

  • You may not post new threads
  • You may not post replies
  • You may not post attachments
  • You may not edit your posts
  •