Infection Channel: Downloaded from the Internet, Dropped by other malware
This Trojan arrives on a system as a file dropped by other malware or as a file downloaded unknowingly by users when visiting malicious sites.
It creates folders where it drops its files.
File size: 1,665,506 bytes
File type: EXE
Memory resident: No
Initial samples received date: 27 Nov 2012
Payload: Drops files, Displays graphics/image
Arrival Details
This Trojan arrives on a system as a file dropped by other malware or as a file downloaded unknowingly by users when visiting malicious sites.
It creates the following folders:
(Note: %User Temp% is the current user's Temp folder, which is usually C:\Documents and Settings\{user name}\Local Settings\Temp on Windows 2000, XP, and Server 2003, or C:\Users\{user name}\AppData\Local\Temp on Windows Vista and 7.)
NOTES:
It disguises as Windows 8 Activator. It displays the following screenshots to trick users into thinking that the file being run is a legitimate installer of the said application:



Once it reaches the last screen, it asks the user to enter a password. It displays the following message in every attempt:

It terminates after 3 attempts.
It connects to the following websites upon execution to generate clicks for the said sites:
- http://{BLOCKED}rchant.net/api/open.php?aid=2102499&v
- http://{BLOCKED}rchant.net/50qjpr21e2bd/2102499/
Connect with us on
| | | |