Threat behavior
Trojan:Win32/Siapag.A is a trojan that may download a data file containing instructions for downloading additional malware. In the wild, we have seen Siapag.A downloading additional trojans that may be used to capture credentials for online games.
Installation
When executed, Trojan:Win32/Siapag.A may drop the following file:
This file is detected as VirTool:WinNT/Siapag!gen.A and may be used to hide malicious activity on an affected machine.
Payload
Downloads Arbitrary Files
Win32/Siapag.A may attempt to download two data files from the following predefined domains:
The data files contain links to other files that Win32/Siapag may download and execute. In the wild, we have observed the data file being used to specify the location of the following malware:
-
TrojanDropper:Win32/Tilcun.E - a trojan that steals online game passwords and sends this captured data to remote sites
-
TrojanSpy:Win32/Treemz.gen!A - a trojan that monitors user data, and sends it to a remote user
-
PWS:Win32/Qqhook.gen!B - a trojan that captures passwords for the chat application 'QQ'
Stops Normal Execution of Files
Win32/Siapag.A may make numerous additions to the system registry that reference use of a debugger known as Microsoft NT Symbolic Debugger (NTSD). Listed below is an example of some of the changes made by the trojan.
Adds value: <filename>
To subkey: HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\
Adds value: debugger
With data: "ntsd -d"
To subkey: HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\<filename>
Where <filename> is from the following list of file names:
DrvAnti.exe
avp.com
avp.exe
runiep.exe
PFW.exe
FYFireWall.exe
rfwmain.exe
rfwsrv.exe
KAVPF.exe
KPFW32.exe
nod32kui.exe
nod32.exe
Navapsvc.exe
Navapw32.exe
avconsol.exe
webscanx.exe
drwebscd.exe
NPFMntor.exe
vsstat.exe
KPfwSvc.exe
Ras.exe
RavMonD.exe
mmsk.exe
WoptiClean.exe
QQKav.exe
spiderui.exe
QQDoctor.exe
EGHOST.exe
360Safe.exe
iparmo.exe
adam.exe
IceSword.exe
360rpt.exe
360tray.exe
AgentSvr.exe
AppSvc32.exe
autoruns.exe
avgrssvc.exe
AvMonitor.exe
CCenter.exe
ccSvcHst.exe
drwadins.exe
FileDsty.exe
FTCleanerShell.exe
HijackThis.exe
Iparmor.exe
isPwdSvc.exe
kabaload.exe
drwebscd.exe
spiderml.exe
KaScrScn.SCR
KASMain.exe
KASTask.exe
KAVDX.exe
KAVPFW.exe
KAVSetup.exe
KAVStart.exe
drwebupw.exe
spidernt.exe
KISLnchr.exe
KMailMon.exe
KMFilter.exe
KPFW32.exe
KPFW32X.exe
KPFWSvc.exe
KRegEx.exe
spml_set.exe
KRepair.com
KsLoader.exe
KVCenter.kxp
KvDetect.exe
KvfwMcl.exe
kvol.exe
kvolself.exe
KVSrvXP.exe
KVStub.kxp
kvupload.exe
nod32krn.exe
kvwsc.exe
KWatch.exe
KWatch9x.exe
KWatchX.exe
MagicSet.exe
mcconsol.exe
mmqczj.exe
KAV32.exe
nod32krn.exe
PFWLiveUpdate.exe
QHSET.exe
RavMon.exe
RavStub.exe
RegClean.exe
rfwcfg.exe
RfwMain.exe
rfwsrv.exe
RsAgent.exe
Rsaupd.exe
safelive.exe
scan32.exe
shcfg32.exe
SmartUp.exe
SREng.EXE
symlcsvc.exe
SysSafe.exe
TrojanDetector.exe
Trojanwall.exe
TrojDie.kxp
UIHost.exe
UmxAgent.exe
UmxAttachment.exe
UmxCfg.exe
UmxFwHlp.exe
UmxPol.exe
UpLive.exe
procexp.exe
OllyDBG.EXE
OllyICE.EXE
rfwstub.exe
RegTool.exe
rfwProxy.exe
RawCopy.exe
CCenter.exe
regedit.exe
filemon.exe
regmon.exe
AntiArp.exe
taskmgr.exe
GFUpd.exe
GFRing3.exe
GuardField.exe
RavTask.exe
RavCopy.exe
RavXP.exe
CCenter.exe
ravstub.exe
ravcopy.exe
rsaupd.exe
These actions prevent the above-listed programs from executing correctly.
Analysis by Vitaly Zaytsev
Prevention