Archive notice: This article was originally published on December 3, 2007. Links and embedded videos are preserved as part of the historical record.
During the past quarter, experts from Kaspersky Lab came across interesting parallels between a large number of malicious programs while analysing the encryption trojan Gpcode.ai. The trojan is based on a kind of “universal code” that occurs in different variants in Trojan-Downloaders, Trojan-Spys and backdoors. This discovery and further observations from the past three months can be read in the quarterly report “Malware Threats in the Third Quarter” at http://www.viruslist.de.
When analysing Gpcode.ai, Kaspersky Lab focused on several indicators, including the string SYSTEM_64AD0625 contained in the trojan body, with which Gpcode marks its presence in the working memory. When the experts searched their extensive virus collection for this line, the result was more than surprising: It appeared in the most varied trojan malicious programs, which include the Trojan-Downloader, Trojan-Spys and backdoors classes, for example. However, the samples had even more in common. They install numerous files, modify Windows folders and also match by more than 80 percent in the program code.
The antivirus experts had thus come across a kind of “universal code” that can be used in many ways. Among other things, its functions are suitable for data theft and for downloading malware onto already infected computers. Programs equipped with the “universal code” can also function as bots and connect infected computers to zombie networks.
In the next step, Kaspersky Lab analysed the links contained in the universal code using numerous current malware versions. As the research showed, there is a connection between pests such as Zhelatin, Warezov, Bancos.aam, Bzub and Gpcode.ai. The next task was to expose the programmer of the “universal code” and find out whether all malware created with it can be attributed to one and the same hacker group.
With ZeuS, the originator of the pests was soon found. The malware installs itself automatically on a system, infiltrates running processes, resists various antivirus programs and provides an http proxy server. All ZeuS variants immortalise themselves on infected systems with the string SYSTEM. Kaspersky Lab then grouped all versions of the malware into an independent family called Zbot.
All ZeuS variants can steal arbitrary information in diverse and sometimes quite original ways. It is therefore actually a “universal” code whose flexibility makes it particularly dangerous. Just as with Gpcode.ai, each new edition can be equipped with completely different functionality. The number of botnets that relied on its technology shows how popular the pest was in the Russian cybercriminal scene. This was based on the combination of Zupacha and ZeuS with Zunker as the control centre. One of the largest Zunker botnets comprised more than 106,000 computers and grew by more than 1500 machines daily before it was discovered. The rapid spread of Zupacha also results from its simple configuration.