Infection Channel: Dropped by other malware
This backdoor may be dropped by other malware.
It executes commands from a remote malicious user, effectively compromising the affected system.
It deletes itself after execution.
File size: 284,436 bytes
File type: EXE
Memory resident: Yes
Initial samples received date: 20 Jul 2012
Payload: Connects to URLs/IPs
Arrival Details
This backdoor may be dropped by the following malware:
Installation
This backdoor drops the following files:
- %System Root%\Documents and Settings\All Users\SxS\bug.log
- %System Root%\Documents and Settings\All Users\SxSv\rc.exe - normal file (Microsoft Resource Compiler)
- %System Root%\Documents and Settings\All Users\SxSv\rc.hlp - detected as TROJ_PLUGX.SME
- %System Root%\Documents and Settings\All Users\SxSv\rcdll.dll - detected as TROJ_PLUGX.AF
(Note: %System Root% is the root folder, which is usually C:\. It is also where the operating system is located.)
It creates the following folders:
- %System Root%\Documents and Settings\All Users\SxS
- %System Root%\Documents and Settings\All Users\SxSv
(Note: %System Root% is the root folder, which is usually C:\. It is also where the operating system is located.)
Autostart Technique
This backdoor registers its dropped component as a system service to ensure its automatic execution at every system startup. It does this by creating the following registry entries:
HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\
Services\SxSv
Description = "SxSv"
HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\
Services\SxSv
DisplayName = "SxSv"
HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\
Services\SxSv
ErrorControl = "0"
HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\
Services\SxSv
ImagePath = ""%System Root%\Documents and Settings\All Users\SxSv\rc.exe" 200 0"
HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\
Services\SxSv
ObjectName = "LocalSystem"
HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\
Services\SxSv
Start = "2"
HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\
Services\SxSv
Type = "110"
Other System Modifications
This backdoor adds the following registry keys:
HKEY_CLASSES_ROOT\FAST
HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\
Services\SxSv
Backdoor Routine
This backdoor executes the following commands from a remote malicious user:
- Collect network information
- Execute remote commands through Telnet
- Impersonate user privileges
- Log keystrokes
Dropping Routine
This backdoor drops the following file(s), which it uses for its keylogging routine:
- %System Root%\Documents and Settings\All Users\SxSv\kl.log
(Note: %System Root% is the root folder, which is usually C:\. It is also where the operating system is located.)
Other Details
This backdoor connects to the following possibly malicious URL:
- bangzi.{BLOCKED}00dy.net
- 111092231008.{BLOCKED}com.ixlink.netc
It deletes itself after execution.
NOTES:
This backdoor uses the normal file RC.EXE as a component to reconstruct itself after installation using its component files TROJ_PLUGX.SME and TROJ_PLUGX.AF.
Connect with us on
| | | |