Infection Channel: Spammed via email, Downloaded from the Internet, Dropped by other malware
This malware was involved in the Red October campaign, a series of attacks targeting diplomatic and government agencies. It drops malicious files onto the affected system and executes them, causing certain malicious routines to be exhibited.
To get a one-glance comprehensive view of the behavior of this Trojan, refer to the Threat Diagram shown below.

This Trojan arrives as an attachment to email messages spammed by other malware/grayware or malicious users. It arrives on a system as a file dropped by other malware or as a file downloaded unknowingly by users when visiting malicious sites.
It executes the files it drops, prompting the affected system to exhibit the malicious routines they contain.
File size: 576,512 bytes
File type: XLS
Initial samples received date: 15 Jan 2013
Payload: Drops files
Arrival Details
This Trojan arrives as an attachment to email messages spammed by other malware/grayware or malicious users.
It arrives on a system as a file dropped by other malware or as a file downloaded unknowingly by users when visiting malicious sites.
Installation
This Trojan drops the following non-malicious file:
- %Program Files%\Windows NT\wsdktr.ltp
- %User Temp%\{malware file name}.doc
(Note: %Program Files% is the default Program Files folder, usually C:\Program Files in Windows 2000, Server 2003, and XP (32-bit), Vista (32-bit), and 7 (32-bit), or C:\Program Files (x86) in Windows XP (64-bit), Vista (64-bit), and 7 (64-bit).. %User Temp% is the current user's Temp folder, which is usually C:\Documents and Settings\{user name}\Local Settings\Temp on Windows 2000, XP, and Server 2003, or C:\Users\{user name}\AppData\Local\Temp on Windows Vista and 7.)
Dropping Routine
This Trojan drops the following files:
- %Program Files%\Windows NT\svchost.exe - detected as TROJ_KRYPTIK.ROC
- %User Temp%\msmx21.exe - detected as TROJ_KRYPTIK.ROB
(Note: %Program Files% is the default Program Files folder, usually C:\Program Files in Windows 2000, Server 2003, and XP (32-bit), Vista (32-bit), and 7 (32-bit), or C:\Program Files (x86) in Windows XP (64-bit), Vista (64-bit), and 7 (64-bit).. %User Temp% is the current user's Temp folder, which is usually C:\Documents and Settings\{user name}\Local Settings\Temp on Windows 2000, XP, and Server 2003, or C:\Users\{user name}\AppData\Local\Temp on Windows Vista and 7.)
It takes advantage of the following software vulnerabilities to drop malicious files:
It executes the files it drops, prompting the affected system to exhibit the malicious routines they contain.
NOTES:
Upon execution, this Trojan opens its dropped non-malicious file %User Temp%\{malware file name}.doc in order to hide its malicious routines from the user.
Connect with us on
| | | |