German users targeted in Vodafone Spam Campaign (Mar 8, 2012)

By

SonicWALL UTM Research team discovered a new spam campaign targeting users in Germany. The email pretending to be from Vodafone informs the recipient that their new Vodafone bill has been generated and is attached to the email. The PDF attachment is malicious and if opened attempts to exploit Adobe reader via heap spray which in turn downloads a Trojan and executes it.

The spam campaign is shown below:

screenshot
The spam email is in German and is translated below:

screenshot

We discovered the following on analysis of the attached PDF:

  • The PDF attachment contains an obfuscated malaicious javascript shown below:

    screenshot

  • The javascript when deobfuscated was found exploiting Adobe reader and using heap spray to load and execute shell code:

    screenshot

  • On inspecting the shell code being used in the heap spray we discovered that it was downloading and executing a Trojan from a remote URL:

    screenshot

The downloaded Trojan performs the following activities:

  • It injects code in to csrss.exe
  • It checks for connectivity to the internet by querying google.com
  • It creates the following file:
    • %windir%system32wink.exe (Copy of itself) [Detected as GAV: Inject.DCGC (Trojan)]
  • It creates to following registry entry to add itself as a debugger for the userinit.exe process. This ensures it is executed in the execution sequence of userinit.exe at windows logon:
    • HKEY_LOCAL_MACHINESOFTWAREMicrosoftWindows NTCurrentVersionImage File Execution Optionsuserinit.exe Debugger “wink.exe”
  • It posts data to a remote server:

    screenshot

SonicWALL Gateway AntiVirus provides protection against this threat with the following signatures:

  • GAV: Pidief.AWT (Exploit)
  • GAV: Inject.DCGC (Trojan)
Security News
The SonicWall Capture Labs Threat Research Team gathers, analyzes and vets cross-vector threat information from the SonicWall Capture Threat network, consisting of global devices and resources, including more than 1 million security sensors in nearly 200 countries and territories. The research team identifies, analyzes, and mitigates critical vulnerabilities and malware daily through in-depth research, which drives protection for all SonicWall customers. In addition to safeguarding networks globally, the research team supports the larger threat intelligence community by releasing weekly deep technical analyses of the most critical threats to small businesses, providing critical knowledge that defenders need to protect their networks.