Infection Channel: Downloaded from the Internet
This backdoor gathers certain information on the affected system.
It logs active windows and user key strokes.
It is capable of executing several commands on the affected system.
This backdoor may be downloaded by other malware/grayware/spyware from remote sites.
It connects to a website to send and receive information.
File size: 459,948 bytes
File type: Other
Memory resident: Yes
Initial samples received date: 13 Feb 2012
Payload: Compromises system security, Connects to URLs/IPs, Steals information
Arrival Details
This backdoor may be downloaded by other malware/grayware/spyware from remote sites.
Installation
This backdoor drops the following files:
- %User Temp%\GoogleUp-date.exe - also detected as BKDR_ZAPCHAST.SG
- %User Temp%\_$temp - encrypted component
- %User Startup%\(Empty).lnk - autostart component
(Note: %User Temp% is the current user's Temp folder, which is usually C:\Documents and Settings\{user name}\Local Settings\Temp on Windows 2000, XP, and Server 2003.. %User Startup% is the current user's Startup folder, which is usually C:\Windows\Profiles\{user name}\Start Menu\Programs\Startup on Windows 98 and ME, C:\WINNT\Profiles\{user name}\Start Menu\Programs\Startup on Windows NT, and C:\Documents and Settings\{User name}\Start Menu\Programs\Startup.)
It creates the following folders:
(Note: %User Temp% is the current user's Temp folder, which is usually C:\Documents and Settings\{user name}\Local Settings\Temp on Windows 2000, XP, and Server 2003.)
It adds the following mutexes to ensure that only one of its copies runs at any one time:
Other System Modifications
This backdoor adds the following registry keys:
HKEY_CURRENT_USER\Software\DC3_FEXEC
Backdoor Routine
This backdoor connects to the following websites to send and receive information:
Stolen Information
This backdoor saves the stolen information in the following file:
- %User Temp%\dclogs\{current date}-{number}.dc
(Note: %User Temp% is the current user's Temp folder, which is usually C:\Documents and Settings\{user name}\Local Settings\Temp on Windows 2000, XP, and Server 2003.)
NOTES:
It gathers the following information on the affected system:
- Admin rights
- Computer/User name
- HWID
- Language/Country
- Operating System information
- RAM used
- Web Cam information
It logs active windows and user key strokes.
It is capable of executing the following commands:
- Disable notifications of antivirus software
- Display a message box
- Download an updated copy of itself
- Download and execute files
- List active windows
- Manipulate files
- Manipulate processes
- Manipulate registries
- Modify priveleges
- Modify the hosts file
- Modify user groups
- Monitor webcam activity
- Open command prompt
- Steal passwords
- Uninstall applications
- Uninstall itself
Connect with us on
| | | |