This backdoor is capable of executing the several commands.
This backdoor may be dropped by other malware.
It connects to a website to send and receive information.
File size: 73,728 bytes
File type: PE
Memory resident: Yes
Initial samples received date: 12 Apr 2011
Arrival Details
This backdoor may be dropped by the following malware:
Installation
This backdoor injects itself into the following processes running in the affected system's memory:
Autostart Technique
This backdoor drops the following files:
- %Program Files%\Common Files\bak.dll - copy of original mspmsnsv.dll
- %System%\fi.txt - contains a list of recently used documents
- %System%\msimage.dat - component file also detected as BKDR_SHARK.WMP
- %System%\task.dat - contains list of running processes and their respective process IDs
(Note: %Program Files% is the default Program Files folder, usually C:\Program Files.. %System% is the Windows system folder, which is usually C:\Windows\System on Windows 98 and ME, C:\WINNT\System32 on Windows NT and 2000, or C:\Windows\System32 on Windows XP and Server 2003.)
Other System Modifications
This backdoor modifies the following registry entries:
HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\
Services\WmdmPmSN
Start = 2
(Note: The default value data of the said registry entry is 3.)
Backdoor Routine
This backdoor opens the following ports:
It connects to the following websites to send and receive information:
- {BLOCKED}.{BLOCKED}.123.123
NOTES:
It replaces the following legitimate files with its own AUTORUN component file:
- %System%\mspmsnsv.dll
- %System%\dllcache\mspmsnsv.dll
As a result, the malware is executed whenever the system executes the overwritten DLLs. Trend Micro also detects the autorun component file as BKDR_SHARK.WMP.
It is capable of executing the following commands:
- Retrieves operating system version
- Switches user profiles
- Retrieves process ID of processes/services
- Opens an FTP connection
- Downloads/Uploads files
- Modifies privileges
- Creates processes
- Uninstalls itself
Connect with us on
| | | |