Infection Channel: Downloaded from the Internet, Dropped by other malware
This file infector arrives on a system as a file dropped by other malware or as a file downloaded unknowingly by users when visiting malicious sites.
It creates folders where it drops its files. It injects its dropped file/component to specific processes.
It creates an infection marker in infected files.
File size: 127,488 bytes
File type: EXE
Memory resident: Yes
Initial samples received date: 27 Aug 2012
Payload: Connects to URLs/IPs, Drops files
Arrival Details
This file infector arrives on a system as a file dropped by other malware or as a file downloaded unknowingly by users when visiting malicious sites.
Installation
This file infector drops the following component file(s):
- %User Profile%\Application Data\{Random Folder}\{Random File name}.EXE.LNK
- %User Profile%\Application Data\{Random Folder}\{Random File name}.EXE.INI
(Note: %User Profile% is the current user's profile folder, which is usually C:\Documents and Settings\{user name} on Windows 2000, XP, and Server 2003, or C:\Users\{user name} on Windows Vista and 7.)
It drops and executes the following files:
- %User Profile%\Application Data\{Random folder}\{Random File name}.exe - detected as PE_QUERVAR.D-0
(Note: %User Profile% is the current user's profile folder, which is usually C:\Documents and Settings\{user name} on Windows 2000, XP, and Server 2003, or C:\Users\{user name} on Windows Vista and 7.)
It creates the following folders:
- %User Profile%\Application Data\{Random Folder}
(Note: %User Profile% is the current user's profile folder, which is usually C:\Documents and Settings\{user name} on Windows 2000, XP, and Server 2003, or C:\Users\{user name} on Windows Vista and 7.)
It injects its dropped file/component to the following processes:
It terminates itself if it finds the following processes in the affected system's memory:
Autostart Technique
This file infector modifies the following registry entry(ies) to enable its automatic execution at every system startup:
HKEY_CURRENT_USER\Software\Microsoft\
Windows NT\CurrentVersion\Windows
Load = "%User Profile%\Application Data\{Random Folder}\{Random Filename}.EXE.LNK"
(Note: The default value data of the said registry entry is "".)
File Infection
This file infector infects the following file types:
It creates an infection marker in infected files.
Other Details
This file infector connects to the following possibly malicious URL:
- http://windows{BLOCKED}soft.com/update.apx
- http://{BLOCKED}w.com.br/includes/domit/way.php
- http://www.{BLOCKED}kes.com/way.php
NOTES:
This file infector renames the extension of the infected file as follows:
- .DOC to .COD.SCR
- .DOCX to .XCOD.SCR
- .XLS to .SLX.SCR
- .XLSX to .XSLX.SCR
It then deletes the original copy of the infected files. The infected files are already detected by Trend Micro as PE_QUERVAR.D.
Connect with us on
| | | |