Infection Channel: Downloaded from the Internet, Dropped by other malware
This backdoor arrives on a system as a file dropped by other malware or as a file downloaded unknowingly by users when visiting malicious sites.
It executes then deletes itself afterward.
File size: 96,256 bytes
File type: EXE
Memory resident: Yes
Initial samples received date: 11 Feb 2013
Payload: Downloads files, Compromises system security
Arrival Details
This backdoor arrives on a system as a file dropped by other malware or as a file downloaded unknowingly by users when visiting malicious sites.
Installation
This backdoor executes then deletes itself afterward.
It injects threads into the following normal process(es):
Autostart Technique
This backdoor adds the following registry entries to enable its automatic execution at every system startup:
HKEY_CURRENT_USER\Software\Microsoft\
Windows\CurrentVersion\Run
MSConfig = ""%User Profile%\{Random File Name}.exe""
Backdoor Routine
This backdoor connects to the following URL(s) to send and receive commands from a remote malicious user:
- http://{BLOCKED}.{BLOCKED}.99.252/load/asidfk11.dat?wv=51&bt=32
NOTES:
It downloads a .JPG file from the following link:
- {BLOCKED}lofhumor.com/wp-content/uploads/2013/01/0zXLM1-580x427.jpg
It then saves and opens it as %Current Folder%\{Malware Name}.jpg. This is done to trick users into thinking that the executed file is legitimate.
It then connects to the following URL to download the file, YouBitchPIC.exe:
- {BLOCKED}.{BLOCKED}.99.252/load/load.php
It saves a copy of the downloaded file as %User Profile%\{Random File Name}.exe and executes it. Trend Micro also detects the downloaded file as BKDR_DORIFEL.AD.
It may compose messages that can be part of its spamming routine. It uses any of the following Simple Mail Transfer Protocol (SMTP) servers to send its messages:
- {BLOCKED}.{BLOCKED}.100.11
- {BLOCKED}.{BLOCKED}.118.35
- {BLOCKED}x.l.google.com
- {BLOCKED}s.mail.ru
- {BLOCKED}1.aspmx.l.google.com
- {BLOCKED}2.aspmx.l.google.com
Connect with us on
| | | |