File size: 611,328 bytes
File type: EXE
Memory resident: Yes
Initial samples received date: 07 May 2013
Arrival Details
This Trojan arrives on a system as a file dropped by other malware or as a file downloaded unknowingly by users when visiting malicious sites.
Installation
This Trojan drops the following copies of itself into the affected system:
- %Application Data%\bee8695a139c2cb.exe
(Note: %Application Data% is the current user's Application Data folder, which is usually C:\Documents and Settings\{user name}\Application Data on Windows 2000, XP, and Server 2003, or C:\Users\{user name}\AppData\Roaming on Windows Vista and 7.)
It creates the following folders:
- %Start Menu%\Programs\New Folder (567)
- %Desktop%\New Folder (552)
- %Start Menu%\Programs\Win 8 Security System
(Note: %Start Menu% is the current user's Start Menu folder, which is usually C:\Windows\Start Menu or C:\Documents and Settings\{User name}\Start Menu on Windows 2000, XP, and Server 2003, or C:\Users\{user name}\AppData\Roaming\Microsoft\Windows\Start Menu on Windows Vista and 7.. %Desktop% is the current user's desktop, which is usually C:\Documents and Settings\{User Name}\Desktop on Windows 2000, XP, and Server 2003, or C:\Users\{user name}\Desktop on Windows Vista and 7.)
Autostart Technique
This Trojan adds the following registry entries to enable its automatic execution at every system startup:
HKEY_CURRENT_USER\Software\Microsoft\
Windows\CurrentVersion\Run
bee8695a139c2cb.exe = "%Application Data%\bee8695a139c2cb.exe"
Other System Modifications
This Trojan modifies the following file(s):
- %Application Data%\GDIPFONTCACHEV1.DAT
(Note: %Application Data% is the current user's Application Data folder, which is usually C:\Documents and Settings\{user name}\Application Data on Windows 2000, XP, and Server 2003, or C:\Users\{user name}\AppData\Roaming on Windows Vista and 7.)
It deletes the following files:
- %Application Data%\bee8695a139c2cb.exe:Zone.Identifier
- %Start Menu%\Programs\Win 8 Security System\Uninstall Win 8 Security System.lnk
- %Desktop%\Win 8 Security System.lnk
- %Desktop%\Win 8 Security System Order Information Page.lnk
- %User Temp%\ae3840d3.tmp
(Note: %Application Data% is the current user's Application Data folder, which is usually C:\Documents and Settings\{user name}\Application Data on Windows 2000, XP, and Server 2003, or C:\Users\{user name}\AppData\Roaming on Windows Vista and 7.. %Start Menu% is the current user's Start Menu folder, which is usually C:\Windows\Start Menu or C:\Documents and Settings\{User name}\Start Menu on Windows 2000, XP, and Server 2003, or C:\Users\{user name}\AppData\Roaming\Microsoft\Windows\Start Menu on Windows Vista and 7.. %Desktop% is the current user's desktop, which is usually C:\Documents and Settings\{User Name}\Desktop on Windows 2000, XP, and Server 2003, or C:\Users\{user name}\Desktop on Windows Vista and 7.. %User Temp% is the current user's Temp folder, which is usually C:\Documents and Settings\{user name}\Local Settings\Temp on Windows 2000, XP, and Server 2003, or C:\Users\{user name}\AppData\Local\Temp on Windows Vista and 7.)
It adds the following registry entries:
HKEY_CURRENT_USER\Software\Microsoft\
Windows NT
BuildVersion = "0"
HKEY_CURRENT_USER\Software\Microsoft\
Windows NT
BuildNumber = "0"
HKEY_CURRENT_USER\Software\Microsoft\
Windows\CurrentVersion\Internet Settings
GlobalUserOffline = "0"
HKEY_CURRENT_USER\Software\Microsoft\
Windows NT
FrameworkDetails = "1"
It modifies the following registry entries:
HKEY_CURRENT_USER\Software\Microsoft\
GDIPlus
FontCachePath = "%Application Data%"
(Note: The default value data of the said registry entry is %User Profile%\Local Settings\Application Data.)
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\
DirectDraw\MostRecentApplication
Name = "bee8695a139c2cb.exe"
(Note: The default value data of the said registry entry is iexplore.exe.)
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\
DirectDraw\MostRecentApplication
ID = "5425311"
(Note: The default value data of the said registry entry is 41107b81.)
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\
Direct3D\MostRecentApplication
Name = "bee8695a139c2cb.exe"
(Note: The default value data of the said registry entry is vfp6.exe.)
Dropping Routine
This Trojan drops the following files:
- %System%\drivers\9f0e.sys
- %Start Menu%\Programs\Win 8 Security System\Launch Win 8 Security System.lnk
- %Start Menu%\Programs\Win 8 Security System\Buy Win 8 Security System.lnk
- %Desktop%\Buy Win 8 Security System.lnk
- %User Temp%\VGX21.tmp
- %User Temp%\VGX25.tmp
- %User Temp%\VGX29.tmp
- %User Temp%\VGX2D.tmp
- %User Temp%\VGX31.tmp
- %User Temp%\VGX35.tmp
- %User Temp%\VGX39.tmp
- %User Temp%\VGX3D.tmp
(Note: %System% is the Windows system folder, which is usually C:\Windows\System32.. %Start Menu% is the current user's Start Menu folder, which is usually C:\Windows\Start Menu or C:\Documents and Settings\{User name}\Start Menu on Windows 2000, XP, and Server 2003, or C:\Users\{user name}\AppData\Roaming\Microsoft\Windows\Start Menu on Windows Vista and 7.. %Desktop% is the current user's desktop, which is usually C:\Documents and Settings\{User Name}\Desktop on Windows 2000, XP, and Server 2003, or C:\Users\{user name}\Desktop on Windows Vista and 7.. %User Temp% is the current user's Temp folder, which is usually C:\Documents and Settings\{user name}\Local Settings\Temp on Windows 2000, XP, and Server 2003, or C:\Users\{user name}\AppData\Local\Temp on Windows Vista and 7.)
Other Details
This Trojan connects to the following possibly malicious URL:
- http://{BLOCKED}t.com/z.php?ver=9
This report is generated via an automated analysis system.
Connect with us on
| | | |