Details:
Installation and Autostart Technique
This backdoor usually arrives either as a file dropped by other malware or as a file downloaded from the Internet by a user.
Upon execution, it drops a copy of itself as TCSVC.DLL in the Windows system folder. It then creates the following registry entry to ensure its automatic execution at every system startup:
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\
Windows\CurrentVersion\Run
Tcsvc = "rundll32.exe %System%\tcsvc.dll,start"
(Note: %System% is the Windows system folder, which is usually C:\Windows\System on Windows 98 and ME, C:\WINNT\System32 on Windows 2000, or C:\Windows\System32 on Windows XP and Server 2003.)
The file RUNDLL32.EXE is a legitimate file used by this backdoor program for its autostart routine.
Backdoor Routine
This backdoor listens to varying ports where it waits for certain commands from a remote malicious user. Some of the commands a malicious user can execute on an affected system include the following:
- Update itself via FTP
- Perform denial of service (DoS) attacks using the following methods:
- Conn flood
- ICMP flood
- Spaz flood
- SYN flood
HOSTS File Modification
On NT-based system, meaning Windows 2000, XP, and Server 2003, this backdoor modifies the system's HOSTS file, which contains host name to IP address mappings. It is usually located in the following folder:
%System%\drivers\etc\HOSTS
The said routine is done so that the following Web sites, most of which are related to antivirus companies, can no longer be accessed by affected users:
- ahnlab.com
- auth.ahnlab.com
- ca.com
- customer.symantec.com
- dispatch.mcafee.com
- download.mcafee.com
- f-secure.com
- kaspersky-labs.com
- kaspersky.com
- liveupdate.symantec.com
- liveupdate.symantecliveupdate.com
- mast.mcafee.com
- mcafee.com
- microsoft.com
- my-etrust.com
- nai.com
- networkassociates.com
- pandasoftware.com
- rads.mcafee.com
- secure.nai.com
- securityresponse.symantec.com
- sophos.com
- suc.ahnlab.com
- symantec.com
- trendmicro.com
- update.microsoft.com
- update.symantec.com
- updates.symantec.com
- us.mcafee.com
- viruslist.com
- virustotal.com
- www.ahnlab.com
- www.ca.com
- www.f-secure.com
- www.grisoft.com
- www.kaspersky.com
- www.mcafee.com
- www.microsoft.com
- www.my-etrust.com
- www.nai.com
- www.networkassociates.com
- www.pandasoftware.com
- www.sophos.com
- www.symantec.com
- www.trendmicro.com
- www.viruslist.com
- www.virustotal.com
Affected Platforms
This backdoor runs on Windows 98, ME, 2000, XP, and Server 2003.
Analysis By: Zeus M. Laguerta
Updated By: Millette Regulacio
Revision History:
| |
Mar 10, 2006 - Modified Virus Report |