Infection Channel: Dropped by other malware
This backdoor may be dropped by other malware.
It connects to a website to send and receive information.
File size: Varies
File type: PE
Memory resident: Yes
Initial samples received date: 07 May 2012
Payload: Drops files, Connects to URLs/IPs
Arrival Details
This backdoor may be dropped by the following malware:
Installation
This backdoor drops the following component file(s):
- %System%\svc32ex.dll - also detected as BKDR_INJECT.EVL
(Note: %System% is the Windows system folder, which is usually C:\Windows\System on Windows 98 and ME, C:\WINNT\System32 on Windows NT and 2000, or C:\Windows\System32 on Windows XP and Server 2003.)
Its DLL component is injected to the following process(es):
It adds the following mutexes to ensure that only one of its copies runs at any one time:
Autostart Technique
This backdoor registers itself as a system service to ensure its automatic execution at every system startup by adding the following registry entries:
HKEHKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\
Services\6to4\Parameters
ServiceDll = "%System%\svc32ex.dll"
Backdoor Routine
This backdoor connects to the following websites to send and receive information:
- http://www.{BLOCKED}ups.com/update/count.asp
NOTES:
This backdoor registers itself as a system service to ensure its automatic execution at every system startup by adding the following registry key:
HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\
Services\6to4
It is capable of executing the following commands:
- Download and execute file(s)
- Download an updated copy of itself
- Query/Open/Start/Stop/Delete Service(s)
- Uninstall itself
Connect with us on
| | | |