This backdoor may be unknowingly downloaded by a user while visiting malicious websites.
It opens a hidden Internet Explorer window.
File size: 20,480 bytes
File type: EXE
Memory resident: Yes
Initial samples received date: 01 Feb 2012
Payload: Downloads files
Arrival Details
This backdoor may be unknowingly downloaded by a user while visiting malicious websites.
Installation
This backdoor drops the following files:
(Note: %System% is the Windows system folder, which is usually C:\Windows\System on Windows 98 and ME, C:\WINNT\System32 on Windows NT and 2000, or C:\Windows\System32 on Windows XP and Server 2003.)
It drops the following copies of itself into the affected system:
(Note: %System% is the Windows system folder, which is usually C:\Windows\System on Windows 98 and ME, C:\WINNT\System32 on Windows NT and 2000, or C:\Windows\System32 on Windows XP and Server 2003.)
It adds the following mutexes to ensure that only one of its copies runs at any one time:
It is injected into the following processes running in memory:
- explorer.exe
- msnmsgr.exe
- default browser
Autostart Technique
This backdoor adds the following registry entries to enable its automatic execution at every system startup:
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\
Active Setup\Installed Components\{55AB1BE6-FDF1-703C-25BA-48DD3A2DD6E7}
StubPath = "%System%\misys.exe"
Other Details
This backdoor opens a hidden Internet Explorer window.
NOTES:
Upon execution, this backdoor downloads and executes a shellcode from the following URL and executes it:
- http://{BLOCKED}ftibet.net/1207.html
As of this writing, the downloaded code is a variant of BKDR_POISON malware family. As a result, the routines of the said malware are also exhibited in the system.
The downloaded backdoor queries the value in the registry below to obtain the system's default browser:
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\http\shell\open\command
It then creates a hidden instance of the default browser and injects backdoor code into it.
It also connects to the C&C server dd.ip{BLOCKED}hq.com and uses the password admin.
Once connected, it is capable of doing the following routines:
- Capture screenshots, audio, video
- Delete, search and upload files
- Download and inject codes into legitimate processes
- Manage processes and services
- Modify and search registry entries
- Perform shell command
- Send system information (IP address, computer name, user name, operating system)
It also has a feature to log keystrokes and mouse events using the SetWindowsEx API. The logs are saved in the file %System%\misys.
Connect with us on
| | | |