This backdoor is dropped by the malicious .PDF file attached to spammed messages related to the death of the late Korean leader, Kim Jong-il.
To get a one-glance comprehensive view of the behavior of this Backdoor, refer to the Threat Diagram shown below.

This backdoor connects to its C&C server using the parameter. If the backdoor connection is successful, it may perform the certain routines.
This backdoor may be dropped by other malware.
File size: 159,744 bytes
File type: EXE
Memory resident: Yes
Initial samples received date: 20 Dec 2011
Payload: Connects to URLs/IPs
Arrival Details
This backdoor may be dropped by the following malware:
- TROJ_PIDIEF.EGQ
- TROJ_PIDIEF.EGR
Installation
This backdoor drops and executes the following files:
- %Application Data%\GoogleUpdate.exe - also detected as BKDR_FYNLOS.A
(Note: %Application Data% is the current user's Application Data folder, which is usually C:\Documents and Settings\{user name}\Application Data on Windows 2000, XP, and Server 2003, or C:\Users\{user name}\AppData\Roaming on Windows Vista and 7.)
Autostart Technique
This backdoor adds the following registry entries to enable its automatic execution at every system startup:
HKEY_CURRENT_USER\Software\Microsoft\
Windows\CurrentVersion\Run
GoogleUpd = "%Application Data%\GoogleUpdate.exe"
Backdoor Routine
This backdoor connects to the following URL(s) to send and receive commands from a remote malicious user:
- {BLOCKED}.{BLOCKED}.173.119
As of this writing, the said sites are inaccessible.
Other Details
This backdoor connects to the following URL(s) to check for an Internet connection:
- http://www.google.com/search?qu=
NOTES:
It connects to its C&C server using the parameter:
- /search{numbers}?h1={value}&h2={value}&h3={encoded computer name}&h4={encoded volume serial number}
If the backdoor connection is successful, it may perform the following routines:
- Download / upload files
- Execute / delete / copy file
- List / terminate processes
- List / change directories
- Perform shell commands
Connect with us on
| | | |