Infection Channel: Downloaded from the Internet, Dropped by other malware
This backdoor arrives on a system as a file dropped by other malware or as a file downloaded unknowingly by users when visiting malicious sites.
It executes commands from a remote malicious user, effectively compromising the affected system.
File size: 242,176 bytes
File type: EXE
Memory resident: Yes
Initial samples received date: 07 Feb 2013
Payload: Connects to URLs/IPs, Steals information, Drops files, Collects system information
Arrival Details
This backdoor arrives on a system as a file dropped by other malware or as a file downloaded unknowingly by users when visiting malicious sites.
Autostart Technique
This backdoor adds the following registry entries to enable its automatic execution at every system startup:
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\
Windows\CurrentVersion\Run
SonyAgent = "{Malware Path and File Name}"
Backdoor Routine
This backdoor executes the following commands from a remote malicious user:
- Request spam email messages structure and template
- Send spam email messages
- Send stolen information
- Get operating system information
- Get drive information
- List running processes
- Download and execute arbitrary files
- Update server with a list of compromised computers
- Manage registry
It connects to the following URL(s) to send and receive commands from a remote malicious user:
- http://{BLOCKED}.{BLOCKED}.165.213
- http://{BLOCKED}.{BLOCKED}.254.8
- http://{BLOCKED}.{BLOCKED}.171.3
- http://{BLOCKED}.{BLOCKED}.145.158
- http://{BLOCKED}.{BLOCKED}.82.85
- http://{BLOCKED}.{BLOCKED}.82.86
- http://{BLOCKED}.{BLOCKED}.192.204
Information Theft
This backdoor gathers the following data:
- Network traffic information
- Login credentials from FTP, POP3 and SMTP traffic
It attempts to steal stored account information used in the following installed File Transfer Protocol (FTP) clients or file manager software:
- 32 Bit FTP
- BitKinex
- Bullet Proof FTP
- BulletProof FTP Client
- BulletProof FTP Client 2009
- BulletProof FTP Client 2010
- Classic FTP
- Core FTP
- CuteFTP
- CuteFTP 6 Home
- CuteFTP 6 Professional
- CuteFTP 7 Home
- CuteFTP 7 Professional
- CuteFTP 8 Home
- CuteFTP 8 Professional
- CuteFTP Lite
- CuteFTP Pro
- Directory Opus
- FAR Manager FTP
- FFFTP
- FTP Commander
- FTP Commander Deluxe
- FTP Commander Pro
- FTP Control
- FTP Explorer
- FTP Navigator
- FTPRush
- Far
- Far2
- FileZilla
- FlashFXP
- Fling
- Fling FTP
- Frigate3 FTP
- GPSoftware
- GlobalSCAPE
- Ipswitch
- Leap FTP
- NetDrive
- SecureFX
- SmartFTP
- SoftX FTP Client
- Sota FFFTP
- Total Commander
- TurboFTP
- UltraFXP
- WebDrive
- WinSCP
NOTES:
This backdoor modifies its file attributes into Read-only and Hidden after execution.
It also installs WinPcap, a legitimate and commonly used Windows packet capture library, which is used to monitor the infected computer's network activities by dropping and installing the following files:
- %System%\packet.dll - non-malicious
- %System%\wpcap.dll - non-malicious
- %System%\drivers\npf.sys - non-malicious
It exchanges encrypted messages with a remote server via HTTP protocol (TCP port 80). It uses the following crafted User-Agent when communicating with the remote host:
- Mozilla/5.0 (Windows; U; Windows NT; rv:1.9.2.17) Gecko/20110420 Firefox/3.6.17
It sends spam email messages using Simple Mail Transfer Protocol (SMTP) connection. It harvests email addresses from the affected computer's local drive.
Connect with us on
| | | |