Infection Channel: Dropped by other malware
This backdoor may be dropped by other malware.
It executes commands from a remote malicious user, effectively compromising the affected system. It connects to a website to send and receive information.
File size: 84,992 bytes
File type: EXE
Memory resident: Yes
Initial samples received date: 08 Feb 2013
Payload: Compromises system security, Collects system information
Arrival Details
This backdoor may be dropped by the following malware:
- TROJ_MDROP.REF
- SWF_EXPLOIT.MC
Installation
This backdoor drops the following files:
- %Application Data%\config.sys - configuration file
(Note: %Application Data% is the current user's Application Data folder, which is usually C:\Documents and Settings\{user name}\Application Data on Windows 2000, XP, and Server 2003, or C:\Users\{user name}\AppData\Roaming on Windows Vista and 7.)
It drops the following copies of itself into the affected system:
- %Application Data%\googleupdate.exe
(Note: %Application Data% is the current user's Application Data folder, which is usually C:\Documents and Settings\{user name}\Application Data on Windows 2000, XP, and Server 2003, or C:\Users\{user name}\AppData\Roaming on Windows Vista and 7.)
Autostart Technique
This backdoor adds the following registry entries to enable its automatic execution at every system startup:
HKEY_CURRENT_USER\Software\Microsoft\
Windows\CurrentVersion\Run
Update = "%Application Data%\Googleupdate.exe"
Other System Modifications
This backdoor adds the following registry entries as part of its installation routine:
HKEY_CURRENT_USER\Software\Classes
softbin = "{encrypted code}"
Backdoor Routine
This backdoor executes the following commands from a remote malicious user:
- Download and Load plugins - saved as %Temp%\{random}_p.ax or %Temp%\{username}.ax
(Note: %Temp% is the Windows Temporary folder, which is usually C:\Windows\Temp.)
It connects to the following websites to send and receive information:
- {BLOCKED}.{BLOCKED}-job.com
Information Theft
This backdoor gathers the following data:
- Computer Name
- Admin rights
- OS Version
- Hostname
Other Details
This backdoor checks for the presence of the following process(es):
- avp.exe
- qqpctray.exe
- 360tray.exe
- kxetray.exe
Connect with us on
| | | |