Infection Channel: Downloaded from the Internet, Dropped by other malware, Infects files
This file infector is part of a malware family that has affected users in Australia and several other countries on October 2012. Besides infecting files, it also infects the affected system's (MBR) Master Boot Record in order to automatically load itself at system startup, making removal difficult.
To get a one-glance comprehensive view of the behavior of this File infector, refer to the Threat Diagram shown below.

This file infector arrives on a system as a file dropped by other malware or as a file downloaded unknowingly by users when visiting malicious sites.
It infects certain file types by inserting code in the said files. It infects the Master Boot Record of the affected system.
File size: Varies
File type: EXE
Memory resident: Yes
Initial samples received date: 30 Nov 2011
Payload: Connects to URLs/IPs, Compromises system security, Terminates processes
Arrival Details
This file infector arrives on a system as a file dropped by other malware or as a file downloaded unknowingly by users when visiting malicious sites.
File Infection
This file infector infects files with the following file extensions by inserting code in the said files:
It infects the Master Boot Record of the affected system in order to perform the following routines:
- terminate several AV processes
- inject code to browser to download encrypted files
- automatically load PE_XPAJ.C-O every time the system boots.
Process Termination
This file infector terminates the following processes if found running in the affected system's memory:
- avp.exe
- avgnt.exe
- avguard.exe
- sched.exe
- avastui.exe
- ccsvchst.exe
- avgcsrvx.exe
- avgnsx.exe
- avgrsx.exe
- avgtray.exe
- avgwdsvc.exe
- egui.exe
Other Details
This file infector connects to the following URL(s) to check for an Internet connection:
It connects to the following possibly malicious URL:
- {BLOCKED}.{BLOCKED}.162.208:35516
- {BLOCKED].{BLOCKED}.152.218:35516
- {BLOCKED}.{BLOCKED}.71.249:35516
- {BLOCKED}.{BLOCKED}.60.108:35516
- {BLOCKED}.{BLOCKED}.123.153:35516
- {BLOCKED}.{BLOCKED}.132.25:35516
- {BLOCKED}.{BLOCKED}.183.224:35516
- {BLOCKED}.{BLOCKED}.204.90:80
- {BLOCKED}biok.info
- {BLOCKED}c.com
- {BLOCKED}kv.com
- {BLOCKED}tss.info
- {BLOCKED}ifhrf.net
- {BLOCKED}kowab.ru
- {BLOCKED}elertiong.com
- {BLOCKED}xw.ru
- {BLOCKED}naf.ru
- {BLOCKED}ppsfm.org
- {BLOCKED}r.info
- {BLOCKED}j.info
- {BLOCKED}bkxfn.biz
- {BLOCKED}hpte.com
- {BLOCKED}e.ru
- {BLOCKED}fbxrzn.com
- {BLOCKED}etobob.biz
- {BLOCKED}mullpy.info
- {BLOCKED}th.info
- {BLOCKED}medescriptor.com
- {BLOCKED}sncki.info
- {BLOCKED}hyjku.net
- {BLOCKED}mpyzh.net
- {BLOCKED}hez.com
- {BLOCKED}knddy.com
- {BLOCKED}vaweonearch.com
- {BLOCKED}qyhqtb.org
- {BLOCKED}gnfvhz.ru
- {BLOCKED}l.ru
- {BLOCKED}cut.biz
- {BLOCKED}pq.info
- {BLOCKED}eucnd.biz
- {BLOCKED}o.net
- {BLOCKED}ront.net
- {BLOCKED}rando.com
- {BLOCKED}minestar.org
- {BLOCKED}sysho.com
- {BLOCKED}niolosto.com
- {BLOCKED}usiceditior.com
NOTES:
This file infector downloads several encrypted files. It saves the downloaded files as %Windows%\{random file name}.{random 3 letters}. Upon analysis, a minimum of nine encrypted files are downloaded. These files may also perform file infection and MBR infection.
It generates 197 URLs to connect to using a Domain Generation Algorithm.
It also runs in 64-bit versions of Windows.
It maintains only one main execution of the malware code per unique infected sample per day.
The modified MBR is detected as BOOT_XPAJ.SM.
Connect with us on
| | | |