This backdoor has received attention from independent media sources and/or other security firms. Specifically, it is the dropped file of TROJ_MSPOSER.ASM, a Trojan that takes advantage of the Epsilon data-breach incident.
To get a one-glance comprehensive view of the behavior of this Backdoor, refer to the Threat Diagram shown below.

It connects to specific sites to send and receive commands from a remote user, thus compromises system security.
This backdoor may be dropped by other malware.
File size: 194,048 bytes
File type: EXE
Memory resident: Yes
Initial samples received date: 19 Apr 2011
Arrival Details
This backdoor may be dropped by the following malware:
Autostart Technique
This backdoor adds the following registry entries to enable its automatic execution at every system startup:
HKEY_CURRENT_USER\Software\Microsoft\
Windows\CurrentVersion\Run
IE = "{malware path and file name}"
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\
Windows\CurrentVersion\Run
IE = "{malware path and file name}"
Other System Modifications
This backdoor adds the following registry keys:
HKEY_CURRENT_USER\Software\Microsoft\
Multimedia\DrawDib
It adds the following registry entries:
HKEY_CURRENT_USER\Software\Microsoft\
Multimedia\DrawDib
vga.drv {resolution} = "31,31,31,31"
HKEY_CURRENT_USER\Software\Microsoft\
Internet Explorer
Remove = "{time}"
NOTES:
Backdoor Routine
This backdoor executes the following commands from a remote malicious user:
- Capture screenshots
- Capture Web camera
- Create/Remove folders
- Download/Upload files
- Enumerate network adapters
- Execute arbitrary commands
- Execute DOS command
- Execute network statistics (netstat)
- Execute WMI commands
- Get access control list information
- Get certificates
- Get IP configuration settings
- Get system information (computer name, manufacturer, model, OS, system type, memory)
- Get user name and password
- List drives
- List SQL servers
- List/Start/Kill processes
- Log keystrokes
- Manipulate files
- Manipulate system sound volume
- Open Web pages
- Read/Write/Delete registry values
- Record sounds using microphone
- Remove itself
- Send emails
- Start/Stop services
- Update itself
It connects to the following URL to send and receive commands from a remote user:
- https://{BLOCKED}1.230.85/rh/
Connect with us on
| | | |