This malware is possibly connected with DUQU malware, which shares code similarities in STUXNET malware.
To get a one-glance comprehensive view of the behavior of this Trojan, refer to the Threat Diagram shown below.

This Trojan executes its main SYS component by installing it as a service. It does this by adding a registry key.
It also adds certain registry entries to install the .SYS file.
This Trojan arrives on a system as a file dropped by other malware or as a file downloaded unknowingly by users when visiting malicious sites.
File size: 241,664 bytes
File type: DLL
Initial samples received date: 01 Nov 2011
Arrival Details
This Trojan arrives on a system as a file dropped by other malware or as a file downloaded unknowingly by users when visiting malicious sites.
Installation
This Trojan drops the following files:
- %System%\drivers\cmi4432.sys - detected by Trend Micro as RTKT_DUQU.A
- %Windows%\inf\cmi4432.PNF - detected by Trend Micro as TROJ_DUQU.ENC
- %Windows%\inf\cmi4464.PNF - detected by Trend Micro as TROJ_DUQU.CFG
(Note: %System% is the Windows system folder, which is usually C:\Windows\System on Windows 98 and ME, C:\WINNT\System32 on Windows NT and 2000, or C:\Windows\System32 on Windows XP and Server 2003.. %Windows% is the Windows folder, which is usually C:\Windows or C:\WINNT.)
NOTES:
It executes its main SYS component by installing it as a service. It does this by adding the following registry key:
HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\cmi4432
It also adds the following registry entries to install the .SYS file:
HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\cmi4432
Description = "cmi4432"
HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\cmi4432
DisplayName = "cmi4432"
HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\cmi4432
ErrorControl = "0"
HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\cmi4432
Group = "Network"
HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\cmi4432
ImagePath = "\??\C:\WINDOWS\system32\Drivers\cmi4432.sys"
HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\cmi4432
Start = "1"
HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\cmi4432
Type = "1"
HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\cmi4432
FILTER = "{random values}"
As a result, the routines of RTKT_DUQU.A (.SYS files) are also exhibited on the system.
Connect with us on
| | | |