Infection Channel: Dropped by other malware
This backdoor may be dropped by other malware.
It executes commands from a remote malicious user, effectively compromising the affected system.
File size: 61,440 bytes
File type: EXE, TMP
Memory resident: Yes
Initial samples received date: 22 Feb 2013
Payload: Compromises system security, Connects to URLs/IPs, Steals information, Logs keystrokes
Arrival Details
This backdoor may be dropped by the following malware:
Autostart Technique
This backdoor adds the following registry entries to enable its automatic execution at every system startup:
HKEY_CURRENT_USER\Software\Microsoft\
Windows\CurrentVersion\Run
Load = "{malware path}\{malware filename}"
Backdoor Routine
This backdoor executes the following commands from a remote malicious user:
- Capture screenshots
- Download and inject remote codes to legitimate processes
- Listen to microphone audio
- Log keystrokes and active window
- Manage devices (View, Enable, Disable, Remove)
- Manage files (Search, Download, Upload, Execute, Rename, Delete)
- Manage processes (View, Kill, Suspend, Unload Module)
- Manage registries (Search, Modify, Delete, Rename, Create)
- Manage services (View, Start, Stop, Edit, Install, Uninstall)
- Manage windows
- Perform remote shell
- Relay server
- Retrieve cached passwords and hashes
- Send hardware information (CPU speed, Memory)
- Send system information (LAN IP, WAN IP, Computer name, User name, Account Type, OS)
- Update, Uninstall, Restart the malware
- View active ports
- View webcam activity
- View,copy and uninstall applications
It connects to the following URL(s) to send and receive commands from a remote malicious user:
- {BLOCKED}c.{BLOCKED}p.net
Connect with us on
| | | |