Home Security IBM sleuths find banking trojan that uses MS-SQL as C&C server

IBM sleuths find banking trojan that uses MS-SQL as C&C server

Researchers at IBM's X-Force Research have discovered a Windows banking trojan that is unusual in one major respect: it uses a Microsoft SQL Server database server as its command-and-control server.

The malware, named MnuBot, is concentrated in Brazil. No indication was given of the vector it uses to infect a Windows machine.

Most malware use either a Web server or an Internet relay chat channel as the C&C server. There are some variations: the recently discovered VPNFilter malware used a site known as photobucket[.]com as its primary C&C server and loaded an image in order to obtain an IP address for its next stage of operation.

The trojan creates a file called Desk.txt within the AppData Roaming folder and creates a new desktop instance, switching the user over to that and letting the existing desktop instance run side by side. If there is already a Desk.txt file on the system, then MnuBot does nothing.

It then monitors activity on the desktop and waits for the user to open an online banking site, carrying out continuous checks to see if the bank name matches one of those in its configuration which it downloads from the SQL Server C&C server..

If that happens, then the trojan asks the C&C server for a second-stage executable which is saved as Neon.exe in the C:\Users\Public folder.

This executable provides the attacker with full control over the infected machine. If MnuBot cannot obtain a configuration file, then it stays quiet on the infected machine and does nothing. The credentials for connecting to the SQL Server are stored in encrypted form and decrypted just before a connection is attempted.

This achieves two goals:

Dynamic configuration: At any time, the attackers can dynamically change MnuBot’s malicious activity (e.g., the banking sites that are targeted); and

Anti-Research: Once the attackers take down the server, it becomes almost impossible for a researcher to reverse engineer the behaviour of the malware sample.

The attacker has the following range of activities at his/her disposal:

  • Creating browser and desktop screenshots;
  • Keylogging;
  • Simulating user clicks and keystrokes;
  • Restarting the infected machine;
  • Uninstalling Trusteer Rapport from the system; and
  • Creating a form to overlay the bank’s forms and steal the data the user enters into the form.

Commenting on the trojan's design, researcher Jonathan Lusky said it was likely that the MnuBot authors wanted to evade regular anti-virus detection, which is based on malware traffic.

"To do so, they decided to wrap their malicious network communication using seemingly innocent Microsoft SQL traffic," he said.

"MnuBot is an excellent example of many malware families in the Brazilian region. It has many characteristics that are typical of other recently discovered malware strains. For example, the overlaying forms and the new desktop creation are well-known techniques that malware authors in the region use today."

LEARN HOW TO REDUCE YOUR RISK OF A CYBER ATTACK

Australia is a cyber espionage hot spot.

As we automate, script and move to the cloud, more and more businesses are reliant on infrastructure that has the high potential to be exposed to risk.

It only takes one awry email to expose an accounts’ payable process, and for cyber attackers to cost a business thousands of dollars.

In the free white paper ‘6 Steps to Improve your Business Cyber Security’ you’ll learn some simple steps you should be taking to prevent devastating and malicious cyber attacks from destroying your business.

Cyber security can no longer be ignored, in this white paper you’ll learn:

· How does business security get breached?
· What can it cost to get it wrong?
· 6 actionable tips

DOWNLOAD NOW!

RECOVERING FROM RANSOMWARE

Ransomware is a type of malware that blocks access to your files and systems until you pay a ransom.

The first example of ransomware happened on September 5, 2013, when Cryptolocker was unleashed.

It quickly affected many systems with hackers requiring users to pay money for the decryption keys.

Find out how one company used backup and cloud storage software to protect their company’s PCs and recovered all of their systems after a ransomware strike.

DOWNLOAD THE REPORT!

Sam Varghese

website statistics

A professional journalist with decades of experience, Sam for nine years used DOS and then Windows, which led him to start experimenting with GNU/Linux in 1998. Since then he has written widely about the use of both free and open source software, and the people behind the code. His personal blog is titled Irregular Expression.

 

Popular News

 

Telecommunications