Threat Research & Response Blog
As previously noted, one of the three families added to the November release of the Microsoft Malicious Software Removal Tool is Win32/Dofoil. TrojanDownloader:Win32/Dofoil is a configurable downloader. Dofoil will attempt to receive control instructions from a remote server. The response contains encrypted configuration data containing download URLs and execution options, as visible in a partially decrypted Dofoil configuration shown below:
Figure 1. Partially decrypted Dofoil configuration
The current generation of Dofoil can be purchased on illicit online marketplaces. Prices are advertised in US dollar equivalent WebMoney values. Depending on the version purchased, the price ranges between 150-250 $US for the main malware component. The cost for plugins ranges from an additional 25-150 $US. One example plugin is a password stealing component which targets many FTP, IM, poker and email clients.
Whilst often seen as an attachment as part of a spam campaign, the MMPC has observed Win32/Dofoil distributed and installed via other mechanisms such as by exploit. In the wild Win32/Dofoil variants are employed to download rogue security software such as Trojan:Win32/FakeSysdef and spam capable malware such as Trojan:Win32/Danmec.L.
Among observed spam campaigns, here is a small selection of spam lures employed during the last two months:
From: email@example.comSubject: IRS Notification
There are arrears reckoned on your account over a period of 2010-2011 year.You will find all calculations according to your financial debt, enclosed.You have to sick the debt by the 17 December 2011.
From: firstname.lastname@example.orgSubject: Your iTunes Gift Certificate
You have received an Itunes Gift Certificate in the amount of $50 You can find your certificate code in attachment below.
Then you need to open iTunes. Once you verify your account, $50 will be credited to your account. So you can start buying video, music, games right away.
Subject: Fwd: Scan from a Xerox W. Pro #16389356
Please open the attached document. It was scanned and sent to you using a Xerox WorkCentre Pro.
Sent by: GuestNumber of Images: 4Attachment File Type: ZIP [DOC]
WorkCentre Pro Location: machine location not setDevice Name: RXX135OO6MSX6732224
From: "Deutsche Post" (email@example.com)Subject: Holen Sie ihre Postsendung ab.
Es ist unserem Boten leider misslungen einen Postsendung an Ihre Adresse zuzustellen.Grund: Ein Fehler in der Leiferanschrift.Sie konnen Ihre Postsendung in unserer Postabteilung personlich kriegen.Anbei finden Sie einen Postetikett.Sie sollen dieses Postetikett drucken lassen, um Ihre Postsendung in der Postabteilung empfangen zu konnen.
Vielen Dank!Deutsche Post AG.
The Malicious Software Removal Tool reported variants of Win23/Dofoil on 13,488 unique machines this month. Forty-seven percent of these machines were running Windows XP, whilst approximately twenty-nine percent were running Windows 7. Looking at the geographic distribution of the machines which reported a Win32/Dofoil detection:
Figure 2. Geographic distribution of machines reporting