Infection Channel: Dropped by other malware
This backdoor may be dropped by other malware.
It connects to a website to send and receive information.
It creates an event.
File size: 25,088 bytes
File type: EXE
Memory resident: Yes
Initial samples received date: 09 Apr 2012
Payload: Drops files
Arrival Details
This backdoor may be dropped by the following malware:
Installation
This backdoor adds the following processes:
Autostart Technique
This backdoor adds the following registry entries to enable its automatic execution at every system startup:
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\
Windows\CurrentVersion\policies\
Explorer\run
tpbar = "%System%S\tpframe.exe"
Other System Modifications
This backdoor adds the following registry keys:
HKEY_CURRENT_USER\Software\Local AppWizard-Generated Applications
Backdoor Routine
This backdoor connects to the following websites to send and receive information:
Process Termination
This backdoor terminates the following processes if found running in the affected system's memory:
- ravmond.exe
- ccenter.exe
- ravtask.exe
- op_mon.exe
- 360tray.exe
- pctstray.exe
- avp.exe
- vvserv.exe
- v3ltray.exe
- v3svc.exe
- ccsvchst.exe
- mcagent.exe
- avguard.exe
Other Details
This backdoor creates the following event(s):
NOTES:
It drops and executes the following component:
- %System%\resdr32.sys - detected as RTKT_SASFIS.EVL
(Note: %System% is the Windows system folder, which is usually C:\WINNT\System32 on Windows NT and 2000, or C:\Windows\System32 on Windows XP and Server 2003.)
It deletes the said file after executing it.
It gathers and sends the following system information to its C&C server to report successful infection:
- Computer name
- Operating system's Original Equipment Manufacturer (OEM) code page identifier
- User name
These information are sent in encrypted format.
It is capable of executing the following commands:
- Download and execute file(s)
- Search for files with .DOCX, .PPTX, and .XLSX extensions
- Update itself
Connect with us on
| | | |