Infection Channel: Downloaded from the Internet
This backdoor may be downloaded by other malware/grayware from remote sites.
File size: 32,936 bytes
File type: EXE
Memory resident: Yes
Initial samples received date: 26 Jun 2012
Payload: Connects to URLs/IPs
Arrival Details
This backdoor may be downloaded by the following malware/grayware from remote sites:
Installation
This backdoor adds the following mutexes to ensure that only one of its copies runs at any one time:
It injects threads into the following normal process(es):
Autostart Technique
This backdoor adds the following registry entries to enable its automatic execution at every system startup:
HKLM\Software\Microsoft\
Active Setup\Installed Components\{C83EADBE-A0C7-19A8-501D-3A19D8877E63}
Stubpath = "%Current%\{malware filename}.exe"
Backdoor Routine
This backdoor connects to the following URL(s) to send and receive commands from a remote malicious user:
- {BLOCKED}rder.zapto.org - blocked
- {BLOCKED}rder.dyndns-mail.com - blocked
NOTES:
It gets the default Internet browser of the affected system by querying the following registry entry:
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\http\shell\open\command
(default) = "{path and file name of Internet Browser}"
It then injects a thread in the browser if an instance of it is running. If a running instance of the browser is not found, the malware opens a new process of the said browser where it injects its thread that connects to the remote server. This enables the remote user to execute arbitrary commands on the affected system.
Connect with us on
| | | |