Infection Channel: Dropped by other malware, Downloaded from the Internet
This backdoor is downloaded on a system once the new Java 0-day vulnerability for versions Java v1.6 update 41 and Java v1.7 update 15 is exploited.
To get a one-glance comprehensive view of the behavior of this Backdoor, refer to the Threat Diagram shown below.

This backdoor arrives on a system as a file dropped by other malware or as a file downloaded unknowingly by users when visiting malicious sites.
It executes then deletes itself afterward.
File size: 73,728 bytes
File type: EXE
Memory resident: Yes
Initial samples received date: 01 Mar 2013
Payload: Compromises system security
Arrival Details
This backdoor arrives on a system as a file dropped by other malware or as a file downloaded unknowingly by users when visiting malicious sites.
Installation
This backdoor drops the following component file(s):
- %User Profile%\AppMgmt.dll - also detected as BKDR_MDMBOT.A
(Note: %User Profile% is the current user's profile folder, which is usually C:\Documents and Settings\{user name} on Windows 2000, XP, and Server 2003, or C:\Users\{user name} on Windows Vista and 7.)
Its DLL component is injected to the following process(es):
It executes then deletes itself afterward.
Autostart Technique
This backdoor modifies the following registry entries to ensure it automatic execution at every system startup:
HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\
Services\AppMgmt\Parameters
ServiceDll = "%User Profile%\AppMgmt.dll"
(Note: The default value data of the said registry entry is %System%\appmgmts.dll.)
Backdoor Routine
This backdoor connects to the following URL(s) to send and receive commands from a remote malicious user:
- {BLOCKED}.{BLOCKED}.55.187:80
Connect with us on
| | | |