This backdoor may be unknowingly downloaded by a user while visiting malicious websites. It may be dropped by other malware.
It deletes the initially executed copy of itself.
File size: 40,960 bytes
File type: EXE
Memory resident: Yes
Initial samples received date: 07 Dec 2011
Payload: Connects to URLs/IPs
Arrival Details
This backdoor may be unknowingly downloaded by a user while visiting malicious websites.
It may be dropped by the following malware:
Installation
This backdoor drops the following files:
- %User Profile%\Local Settings\pdtpretty.tmp
- %User Profile%\Local Settings\ptpretty.tmp
- %User Profile%\Local Settings\WSE4EF1.TMP - also detected as BKDR_SYKIPOT.B
(Note: %User Profile% is the current user's profile folder, which is usually C:\Windows\Profiles\{user name} on Windows 98 and ME, C:\WINNT\Profiles\{user name} on Windows NT, and C:\Documents and Settings\{user name} on Windows 2000, XP, and Server 2003.)
It drops the following copies of itself into the affected system:
- %User Profile%\Local Settings\pretty.exe
(Note: %User Profile% is the current user's profile folder, which is usually C:\Windows\Profiles\{user name} on Windows 98 and ME, C:\WINNT\Profiles\{user name} on Windows NT, and C:\Documents and Settings\{user name} on Windows 2000, XP, and Server 2003.)
Its DLL component is injected to the following process(es):
- outlook.exe
- iexplore.exe
- firefox.exe
Autostart Technique
This backdoor adds the following registry entries to enable its automatic execution at every system startup:
HKEY_CURRENT_USER\Software\Microsoft\
Windows\CurrentVersion\Run
office = "%User Profile%\Local Settings\pretty.exe"
Other Details
This backdoor deletes the initially executed copy of itself
NOTES:
It creates the file %User Profile%\Local Settings\pdtpretty.tmp, which contains the following information:
- Active network connection
- Adapter information (from ipconfgi /all)
- Contents of boot.ini
- Process injected
- Result of the command dir c:\*.url /s
- Running processes
- Started Windows services
- System information (OS, processor, bios version, time zone, memory, etc.)
It then encrypts the created file and saves it as %User Profile%\Local Settings\ptpretty.tmp. This is later on sent to the following server upon initial connection:
- https://www.{BLOCKED}her.com/asp/kys_allow_get.asp?name=getkys.kys&hostname=%7bhostname%7d-%7bip%7d-pretty20111122
If the connection is successful, it may perform the following routines depending on the server's reply:
- Execute files
- Perform shell commands
- Reboot system
- Terminate processes
- Upload and download files
Connect with us on
| | | |