Infection Channel: Dropped by other malware, Downloaded from the Internet
This destructive malware causes massive data loss.
To get a one-glance comprehensive view of the behavior of this Trojan, refer to the Threat Diagram shown below.

For the related story, you may read the blog post Unsophisticated Wiper Malware Makes Headlines
This Trojan arrives on a system as a file dropped by other malware or as a file downloaded unknowingly by users when visiting malicious sites.
File size: 185,928 bytes
File type: RAR, EXE
Memory resident: No
Initial samples received date: 17 Dec 2012
Payload: Deletes files, Drops files
Arrival Details
This Trojan arrives on a system as a file dropped by other malware or as a file downloaded unknowingly by users when visiting malicious sites.
Installation
This Trojan drops the following file(s)/component(s):
- %System%\juboot.exe - detected as TROJ_BATWIPER.A
- %System%\jucheck.exe - detected as TROJ_BATWIPER.A
(Note: %System% is the Windows system folder, which is usually C:\Windows\System32.)
It drops the following non-malicious files:
(Note: %System% is the Windows system folder, which is usually C:\Windows\System32.)
Autostart Technique
This Trojan adds the following registry entries to enable its automatic execution at every system startup:
HKEY_CURRENT_USER\Software\Microsoft\
Windows\CurrentVersion\Run
jucheck.exe = "%System%\jucheck.exe"
NOTES:
This malware checks for the current date and deletes desktop files and all of the files found on drives D to I when it runs on dates found within the following range:
- December 10-12, 2012
- January 21-23, 2013
- May 6-8, 2013
- July 22-24, 2013
- November 11-13, 2013
- February 3-5, 2014
- May 5-7, 2014
- August 11-13, 2014
- February 2-4, 2015
Connect with us on
| | | |