Home > Support > Global Security Advisor 

Virus Detail

Win32.HacDef

Date Published:
22 Jan 2004

Last Updated:
5 Sep 2006

Threat Assessment

Overall Risk:   Very Low
Wild:  Low
Destructiveness:  High
Pervasiveness:  None

Characteristics

Type : Trojan

Category : Win32

Also known as:  Win32/HacDef!generic, Win32.HacDef!generic, Win32.HacDef!INI, Win32.HacDef.073, Backdoor.HacDef.073.a (Kaspersky), Win32.Hacdef.084, Win32.HacDef.084, Backdoor.Hacdef.084 (Kapsersky), BKDR_HACDEF.73.A (Trend), Win32.HacDef.A, Win32.HacDef.AI, Win32/HacDef.AI, Win32.HacDef.E, Backdoor/Hackdef.084.Server, Backdoor/Hackdef.A.Server, Backdoor.HackDefender (Symantec), HackerDefender (McAfee), W32/HD.Rootkit.73 (F-Secure)

Immediate Protection Info

 
SignatureProductRemoval Instructions
23.63.68
eTrust Antivirus v7/8* (InoculateIT Engine)
6.x/5160
eTrust EZ Antivirus 6.1x
23.63.68
eTrust InoculateIT 6.0
eTrust Antivirus 6.0
45.68
Inoculan/InoculateIT 4.x
11.2x/8101
Vet 11.2x
10.5x/5160
Vet Anti-Virus 10.5x
10.6x/8101
Vet Anti-Virus 10.6x
 
 

Description

Win32.HacDef is a "rootkit", sometimes called "hacker defender" or "hxdef". It acts as a backdoor that allows an intruder to control an infected system remotely, as well as hide the presence of itself and other malicious files and processes.

HacDef only functions on Windows NT, 2000 and XP systems. Its functionality varies depending upon how it is configured.

Method of Installation

When the HacDef executable is run, it looks for a file in the current directory with the extension .INI, but otherwise the same name. For example, if the executable is called "hxdef100.exe", it will try to open "hxdef100.ini". HacDef may be run with a parameter to specify a different INI file.

The INI file contains configuration information for the trojan. These include directives for how it is installed, and its payload.

HacDef installs both a service and a device driver. The service is the trojan executable itself. This executable can drop the driver file to disk. The service name and description, as well as the driver name, are set in the INI file. The following are the entries used in the example INI file provided with the trojan:

ServiceName=HackerDefender100
ServiceDisplayName=HXD Service 100
ServiceDescription=powerful NT rootkit
DriverName=HackerDefenderDrv100
DriverFileName=hxdefdrv.sys

Method of Distribution

HacDef does not distribute itself. It must be installed manually through some other method of system compromise.

Payload

Backdoor Functionality

HacDef has two main payloads. First, it provides a backdoor shell using the Windows command interpreter (cmd.exe). It copies cmd.exe to the temporary directory, using a file name specified in the INI file (e.g. "hxdefß$.exe"). This backdoor does not open a new port to listen on. Instead, HacDef monitors network traffic coming into other servers on the system, and intercepts anything meant for itself. In this way, an intruder is able to connect to the backdoor through any open TCP port on the infected system, e.g. port 80 if a web server is running, or port 25 if a mail server is running. The backdoor requires a password, which is specified in the INI file.

The backdoor can also be used to redirect ports on the local machine to other ports on other machines.

Provides Stealth

The second payload involves the trojan hiding itself and other programs from the user. HacDef hooks many system functions in order to intercept and "stealth" different aspects of the system. It is able to:

  • Hide files and processes (e.g. hide any file or process beginning with "hxdef").
  • Hide services and drivers (the trojan's own service and driver are usually hidden).
  • Hide registry keys and values (the trojan's own registry entries are usually hidden).
  • Hide open ports (from programs like netstat, TCP View, etc).

The stealth methods used by HacDef are quite effective. Hidden files will be invisible to most programs, including Explorer and the command prompt. Hidden services will not appear in the Windows service list. Hidden processes will not appear in the task manager or most third party process viewers. Hidden registry entries will not appear in regedit.

At this time, hidden files CAN be seen from remote machines using Windows file sharing.

HacDef is also able to execute other programs, specified in its INI file, each time it is started.

Analysis by Hamish O'Dea

CA Global Security Advisor

Current threat condition: Low
Low
Find Threats
Viruses Spyware
Vulnerabilities All

Security Resources

 
 
Page Tools