Infection Channel: Dropped by other malware
This backdoor may be dropped by other malware.
It executes commands from a remote malicious user, effectively compromising the affected system. It connects to a website to send and receive information.
It retrieves specific information from the affected system.
File size: Varies
File type: PE
Memory resident: Yes
Initial samples received date: 25 Apr 2012
Arrival Details
This backdoor may be dropped by the following malware:
Installation
This backdoor adds the following folders:
It drops the following component file(s):
- %User Temp%\print32.dll - also detected as BKDR_VISEL.FO
- %Program Files%\Common Files\odbc.nls - also detected as BKDR_VISEL.FO
(Note: %User Temp% is the current user's Temp folder, which is usually C:\Documents and Settings\{user name}\Local Settings\Temp on Windows 2000, XP, and Server 2003.. %Program Files% is the default Program Files folder, usually C:\Program Files.)
It drops the following copies of itself into the affected system:
- %Windows%\Temp\s{random numbers}.dat
(Note: %Windows% is the Windows folder, which is usually C:\Windows or C:\WINNT.)
Its DLL component is injected to the following process(es):
Other System Modifications
This backdoor deletes the following files:
- %Program Files%\Common Files\odbc_dmc.nls
- %Program Files%\Common Files\odbc_orp.nls
- %Program Files%\Common Files\odbc_res.nls
- %Program Files%\Common Files\odbc_lif.nls
- %Program Files%\Common Files\odbc_ger.nls
- %Program Files%\Common Files\odbc_rcs.nls
- %Program Files%\Common Files\odbc_div.nls
- %Program Files%\Common Files\odbc_dua.nls
- %Program Files%\Common Files\odbc_rehto.nls
- %Program Files%\Common Files\dumpodbc.exe
- %Program Files%\Common Files\odbc_txe.nls
- %Program Files%\Common Files\odbc_gpj.nls
- %Program Files%\Common Files\odbc_yek.nls
(Note: %Program Files% is the default Program Files folder, usually C:\Program Files.)
It modifies the following registry entries:
HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\
Services\Spooler
FailureActions = {HEX values}
(Note: The default value data of the said registry entry is {default value}.)
Backdoor Routine
This backdoor executes the following commands from a remote malicious user:
- Change the port it uses when connecting to its C&C server
- Check contents of %Program Files%\Common Files folder
- Connect to a new C&C IP address
- Connect to a website via HTTP
- Create/Manipulate threads
- Download and execute files
- Load/free libraries
- Log user keystrokes
(Note: %Program Files% is the default Program Files folder, usually C:\Program Files.)
It connects to the following websites to send and receive information:
- {BLOCKED}.{BLOCKED}.9.132
Process Termination
This backdoor terminates the following services if found on the affected system:
- spooler
- stisvc
- wuauserv
- Norton Internet Security
- Norton 360
- Norton AntiVirus
Information Theft
This backdoor retrieves the following information from the affected system:
- Computer name
- IP address
- Operating system information
Stolen Information
This backdoor saves the stolen information in the following file:
Connect with us on
| | | |