This backdoor arrives on a system as a file dropped by other malware or as a file downloaded unknowingly by users when visiting malicious sites.
It executes then deletes itself afterward.
It executes commands from a remote malicious user, effectively compromising the affected system.
File size: 166,912 bytes
File type: EXE
Memory resident: Yes
Initial samples received date: 02 Aug 2011
Arrival Details
This backdoor arrives on a system as a file dropped by other malware or as a file downloaded unknowingly by users when visiting malicious sites.
Installation
This backdoor drops the following component file(s):
- %System Root%\Documents and Settings\All Users\winsvcfs.DLL - also detected as BKDR_SOGU.A
(Note: %System Root% is the root folder, which is usually C:\. It is also where the operating system is located.)
It executes then deletes itself afterward.
Autostart Technique
This backdoor registers itself as a system service to ensure its automatic execution at every system startup by adding the following registry entries:
HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\
Services\winsvcfs
It adds the following registry entries to enable its automatic execution at every system startup:
HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\
Services\winsvcfs\Parameters
ServiceDll = "%System Root%\Documents and Settings\All Users\winsvcfs.dll"
Other System Modifications
This backdoor modifies the following registry key(s)/entry(ies) as part of its installation routine:
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\
Windows NT\CurrentVersion\SvcHost
LocalService = "{user defined} winsvcfs"
(Note: The default value data of the said registry entry is {user defined}.)
Backdoor Routine
This backdoor executes the following commands from a remote malicious user:
- access a database in the infected machine, fetch and display specific data
- access a specified server which is possibly malicious
- enumerate registry value of an specified registry key
- stop a service
- start a service
- get drive space of drives except floppy drives
- lock the desktop
- shutdown the system
- list files in a specified directory
It connects to the following URL(s) to send and receive commands from a remote malicious user:
As of this writing, the said sites are inaccessible.
Connect with us on
| | | |