Infection Channel: Dropped by other malware, Downloaded from the Internet
This is a Trend Micro detection for a backdoor component exploiting a Java Runtime Environments (JRE) vulnerability.
This backdoor may be downloaded by other malware/grayware from remote sites.
It connects to certain websites to send and receive information. It executes certain actions WITHIN the affected computer. It deletes itself after execution.
File size: 16,896 bytes
File type: EXE, DLL
Memory resident: Yes
Initial samples received date: 27 Aug 2012
Payload: Connects to URLs/IPs
Arrival Details
This backdoor may be downloaded by the following malware/grayware from remote sites:
It may be downloaded from the following remote sites:
- http://{BLOCKED}.{BLOCKED}.104.149/public/meeting/Flash_update.exe
- http://ok.{BLOCKED}4.net/meeting/hi.exe
Installation
This backdoor drops the following component file(s):
- %System%\mspmsnsv.dll - also detected as BKDR_POISON.BLW
(Note: %System% is the Windows system folder, which is usually C:\Windows\System on Windows 98 and ME, C:\WINNT\System32 on Windows NT and 2000, or C:\Windows\System32 on Windows XP and Server 2003.)
Its DLL component is injected to the following process(es):
It adds the following mutexes to ensure that only one of its copies runs at any one time:
Autostart Technique
This backdoor adds the following registry entries to enable its automatic execution at every system startup:
HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\
Control\Session Manager
PendingFileRenameOperations = "%User Temp%\{random file name}.dat"
Other Details
This backdoor connects to the following website to send and receive information:
It executes the following:
- Open and List active ports
- Manage registry, processes, services, devices, and installed applications
- Perform remote shell
- Downloads and execute other malicious files
- Update, restart, terminate itself
- Capture screen shots, webcam, audio
- Log keystrokes and active window
- Perform a shell command
It deletes itself after execution.
Connect with us on
| | | |