frame   frame
SANS Logo SANS Homepage SANS Bookstore SANS Reading Room SANS Portal
  border   border  
ISC Logo   Infocon: GREEN      
border Permanent Handler on Duty on This Page: Pedro Bueno  
  • "Humankind cannot stand very much reality." - TS Eliot

    • SECTION I - MALWARE ANALYSIS - PART 5 - week Dec 05
       

    BEFORE CONTINUE _ PLEASE READ THIS DISCLAIMER!

    The following file is a REAL piece of MALWARE! - If you decide to go further, please note that I WILL NOT be responsible for any damage that it may cause in your system!

    Okay! Now, some explanaitions about our little malware:

    First, it IS a real malware! It was captured on a compromised machine.

    Malware name and md5: ecd45b584f7a1e50bb044646f4abb0be - cretzu.exe-orig-ecd45b584f7a1e50bb044646f4abb0be
     

    Download it here! ( Password = infected)

    About our little malware...

    A user called the help desk complaining that his computer was too slow, after following the basic IR procedures, the Incident Response Team was called.

    What follows bellow are some real data from the compromised machine.

    C:\Documents and Settings\malware>netstat -an

    Active Connections

    Proto Local Address Foreign Address State
    TCP 0.0.0.0:135 0.0.0.0:0 LISTENING
    TCP 0.0.0.0:445 0.0.0.0:0 LISTENING
    TCP 127.0.0.1:1025 0.0.0.0:0 LISTENING
    TCP 192.168.0.53:139 0.0.0.0:0 LISTENING
    TCP 192.168.0.53:1036 195.47.220.2:6667 ESTABLISHED
    TCP 192.168.0.53:1088 xxx.80.0.50:4899 SYN_SENT
    TCP 192.168.0.53:1089 xxx.80.0.51:4899 SYN_SENT
    TCP 192.168.0.53:1090 xxx.80.0.52:4899 SYN_SENT
    TCP 192.168.0.53:1091 xxx.80.0.53:4899 SYN_SENT
    TCP 192.168.0.53:1092 xxx.80.0.54:4899 SYN_SENT
    TCP 192.168.0.53:1093 xxx.80.0.55:4899 SYN_SENT
    TCP 192.168.0.53:1094 xxx.80.0.56:4899 SYN_SENT
    TCP 192.168.0.53:1095 xxx.80.0.57:4899 SYN_SENT
    TCP 192.168.0.53:1096 xxx.80.0.58:4899 SYN_SENT
    TCP 192.168.0.53:1097 xxx.80.0.59:4899 SYN_SENT
    UDP 0.0.0.0:445 *:*
    UDP 0.0.0.0:500 *:*
    UDP 0.0.0.0:1026 *:*
    UDP 0.0.0.0:1088 *:*
    UDP 0.0.0.0:4500 *:*
    UDP 127.0.0.1:123 *:*
    UDP 127.0.0.1:1900 *:*
    UDP 192.168.0.53:123 *:*
    UDP 192.168.0.53:137 *:*
    UDP 192.168.0.53:138 *:*
    UDP 192.168.0.53:1900 *:*
     

    Also, bellow is a screenshot of the TaskManager:

    The Incident Response Team was called to check his computer and found the cretzu compacted file in his computer.

    Your mission, if you decided to accept :) is to answer the following questions, regarding this incident:

    1. Is this file packed? If so, which packer?

    2. Without running the file, is it possible to identify what this malware can and will do?

    3. Now, using any methods available to you, which changes, if any, will this malware do in the system, among new files and registry entries...?

    4. Now, what is the purpose of this malware?

    5. When will this malware be triggered/start?

    6. Can you explain the netstat output?

    7. What about the TaskManager screenshot? What useful information can you get?

    8. About the creztu file, please explain each of the files that it contain! :)

    Bonus Questions:

    9. Which other information about the channel can you provide?

    10. How would you call this Malware and describe what this category of malware do.

    PS. When running, this malware can do malicious activities in your network and on the Internet!

    Thanks!

    Pedro Bueno ( pbueno //%// isc. sans. org)  - Ah! The answers must be submitted until Dec 17 ! Ah, again...dont forget to submit on PDF format... 

    -->RESULTS!!! - Dec 20/2005!


    Well, well, well...! First, again, some statistics about our Malware Analysis Quiz 5 !

    Total downloads of our malware: 204!

    Total visits to our Quiz 5 page: 2476!

    so, from 2476 visits to our Quiz 5, only 204 decided to download it! And bellow is a list of 5 people who got some good points!

    Top 3:

    Next 2:

    Very good!!!

    I would recommend that each of the submiters, the readers and the top 5 people, to read each one of the five listed above, because each one had a different approach, excellent correlations and really good ideas!

    Well...now I will take some days off...and will return on January 9, to post new Quizes!

    I would like to receive feedback from the Quizes already posted, as well, suggestions for the next ones!

    Thanks a lot guys! It was really fun and I wish you all happy christmas and a really great new year!!!

    Pedro Bueno ( pbueno //&&// isc. sans. org)