This backdoor may be dropped by other malware.
It connects to a website to send and receive information.
File size: Varies
File type: PE
Memory resident: Yes
Initial samples received date: 25 Feb 2012
Payload: Compromises system security, Connects to URLs/IPs, Drops files
Arrival Details
This backdoor may be dropped by the following malware:
Installation
This backdoor drops the following files:
- %System%\adsmsexy.dll - also detected as BKDR_MECIV.LN
- %System%\datac1en.dll - also detected as BKDR_MECIV.LN
(Note: %System% is the Windows system folder, which is usually C:\Windows\System on Windows 98 and ME, C:\WINNT\System32 on Windows NT and 2000, or C:\Windows\System32 on Windows XP and Server 2003.)
Its DLL component is injected to the following process(es):
It creates the following folders:
- %System Root%\Documents and Settings\NetworkService\Local Settings\Application Data\Microsoft Office Update
(Note: %System Root% is the root folder, which is usually C:\. It is also where the operating system is located.)
It adds the following mutexes to ensure that only one of its copies runs at any one time:
Autostart Technique
This backdoor adds the following registry entries to enable its automatic execution at every system startup:
HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\
Services\WmdmPmSN\Parameters
ServiceStartAddr = {malware path and file name}
HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\
Services\WmdmPmSp\Parameters
ServiceDll = %System%\datac1en.dll
It modifies the following registry entries to ensure it automatic execution at every system startup:
HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\
Services\WmdmPmSN\Parameters
ServiceDll = %System%\adsmsexy.dll
(Note: The default value data of the said registry entry is %System%\mspmsnsv.dll .)
Other System Modifications
This backdoor adds the following registry entries as part of its installation routine:
HKEY_USERS\.DEFAULT\Software\
Microsoft\Windows\CurrentVersion\
Internet Settings
ProxyEnable = 0
Backdoor Routine
This backdoor connects to the following websites to send and receive information:
- {BLOCKED}p.{BLOCKED}l.com
- {BLOCKED}e.{BLOCKED}l-temp.com
NOTES:
It sends the following information to its C&C server:
- Hostname
- MAC address
- IP address
- Operating System
- Codepage
- Locale
- File name of the malicious executable
- Campaign name
- If a file named sys32time.ini exists and if its size is greater than or equal to 1MB Y/N
- If a file named ipop.dll exists Y/N
- Malware version
It is capable of executing the following commands:
- Download file(s)
- Upload file(s)
- Delete file(s)
- Move file(s)
- List files from a specific directory
- Create a directory
- Terminate process(es)
- Execute DOS commands
- Execute a specific file
Connect with us on
| | | |