Infection Channel: Downloaded from the Internet, Dropped by other malware, Infects files
This malware downloads a ransomware that pretends to enforce copyright laws and locks the affected system, preventing users from using it.
To get a one-glance comprehensive view of the behavior of this File infector, refer to the Threat Diagram shown below.

This file infector arrives on a system as a file dropped by other malware or as a file downloaded unknowingly by users when visiting malicious sites.
It injects its dropped file/component to specific processes.
It creates an infection marker in infected files.
File size: 332,800 bytes
File type: EXE
Memory resident: Yes
Initial samples received date: 27 Sep 2012
Payload: Connects to URLs/IPs, Downloads files
Arrival Details
This file infector arrives on a system as a file dropped by other malware or as a file downloaded unknowingly by users when visiting malicious sites.
Installation
This file infector drops the following copies of itself into the affected system:
- %User Profile%\Application Data\{random folder name}\{random file name}.exe
(Note: %User Profile% is the current user's profile folder, which is usually C:\Documents and Settings\{user name} on Windows 2000, XP, and Server 2003, or C:\Users\{user name} on Windows Vista and 7.)
It drops the following component file(s):
- %User Profile%\Application Data\{random folder name}\{random file name}.exe.lnk
- %User Profile%\Application Data\{random folder name}\{random file name}.exe.ini
(Note: %User Profile% is the current user's profile folder, which is usually C:\Documents and Settings\{user name} on Windows 2000, XP, and Server 2003, or C:\Users\{user name} on Windows Vista and 7.)
It creates the following folders:
- %User Profile%\Application Data\{random folder name}
(Note: %User Profile% is the current user's profile folder, which is usually C:\Documents and Settings\{user name} on Windows 2000, XP, and Server 2003, or C:\Users\{user name} on Windows Vista and 7.)
It injects its dropped file/component to the following processes:
It terminates the execution of the copy it initially executed and executes the copy it drops instead.
It terminates itself if it finds the following processes in the affected system's memory:
Autostart Technique
This file infector modifies the following registry entries to ensure it automatic execution at every system startup:
HKEY_CURRENT_USER\Software\Microsoft\
Windows NT\CurrentVersion\Windows
load = "%User Profile%\Application Data\{random folder name}\{random filename}.exe.lnk"
(Note: The default value data of the said registry entry is "".)
File Infection
This file infector infects the following file types:
It creates an infection marker in infected files.
Download Routine
This file infector connects to the following website(s) to download and execute a malicious file:
- http://{BLOCKED}l.ru/33797470/2a06754.50664748/3052832ace10d474336096b36fbd49f05f190.exe?{random characters} - detected by Trend Micro as TROJ_SIREFEF.SZP
- http://{BLOCKED}0.com/c/osnovnoj2.exe?{random number} - detected by Trend Micro as TROJ_RANSOM.CMY
Other Details
This file infector connects to the following possibly malicious URL:
- http://{BLOCKED}ewidea1.ru/1.php?{random characters}&pin={random characters}&crc={random characters}
- http://www. {BLOCKED}oservisi.com/test/php/way.php?{random characters}&pin=58252D00982BC1DA&crc={random characters}
NOTES:
This file infector rename the extension of the infected file as follows:
- .doc to .cod.scr
- .docx to .xcod.scr
- .xls to .slx.scr
- .xlsx to .xslx.scr
It then deletes the original copy of the infected files.
Connect with us on
| | | |