Re: PGPcoder Trojan

From: Juergen Nieveler (juergen.nieveler.nospam_at_arcor.de)
Date: 05/24/05


Date: 24 May 2005 13:31:53 GMT

Axel Pettinger <api@worldonline.de> wrote:

> Read Symantec's and/or Trend Micro's description. Both say that the
> trojan drops a batch file which - after the encryption of all target
> files - will delete the trojan. The encryption is the only purpose of
> that trojan - its author wants money for the decryption -, so there's
> no need to keep a copy of the trojan.

In fact it would be foolish to leave the Trojan. Something I missed in
the write-ups was wether the key used to encrypt the files was generated
dynamically (and sent out somewhere else), or wether all copies use the
same key. In the latter case, the key would be hardcoded into the
trojan, so if you find a copy of that you can reverse-engineer it and
get the key out of it. Assuming symetrical encryption was used (which is
likely because it's faster) you'd then be able to decrypt all files.

Juergen Nieveler

-- 
Dawn is nature's way of telling you to go to bed


Relevant Pages

  • RE: Detecting trojans on random ports with encrypted traffic...
    ... One of the things I have noticed is that for any encryption the initial phase ... you can't tell bad (Trojan) traffic from good traffic. ... we can obviously see sub7 on port 27374 with its known signature ... But then they go and run it on a different port. ...
    (Focus-IDS)
  • Re: PGPcoder Trojan
    ... Read Symantec's and/or Trend Micro's description. ... trojan drops a batch file which - after the encryption of all target ... files - will delete the trojan. ...
    (microsoft.public.security.virus)
  • US-CERT Technical Cyber Security Alert TA05-189A -- Targeted Trojan Email Attacks
    ... Targeted Trojan Email Attacks ... attacks appear to target US information for exfiltration. ... US-CERT advises that system administrators take the ...
    (Cert)
  • trojan horse&firewall
    ... Can anyone tell me how this trojan horse program got thru' my firewall,what ... I can do to prevent hackers geting at my system and wether or not I am safe ... I started my PC only to find Norton AV screaming at me about the trojan ... not),went offline,now paranoid,back online updated NetworkIce Defender(my ...
    (comp.security.firewalls)