This Trojan is the malware component of a spam campaign that leverages the death of North Korean leader Kim Jong-Il.
To get a one-glance comprehensive view of the behavior of this Trojan, refer to the Threat Diagram shown below.

It arrives as an attachment to spammed mails.
Upon execution, it checks the version of the Adobe Acrobat on the system. If the version is 9.4 or below, it attempts to exploit the following vulnerabilities to drop and execute files:
It drops and opens a non-malicious PDF file to trick the user that the file is non-malicious.
This Trojan executes the dropped file(s). As a result, malicious routines of the dropped files are exhibited on the affected system.
File size: 421,149 bytes
File type: PDF
Initial samples received date: 20 Dec 2011
Payload: Drops files
Installation
This Trojan drops the following component file(s):
- %User Profile%\Local Settings\fabc.scr
- %User Profile%\Local Settings\log1.txt
- %User Profile%\Local Settings\abc.scr - BKDR_FYNLOS.A
(Note: %User Profile% is the current user's profile folder, which is usually C:\Windows\Profiles\{user name} on Windows 98 and ME, C:\WINNT\Profiles\{user name} on Windows NT, and C:\Documents and Settings\{user name} on Windows 2000, XP, and Server 2003.)
It drops the following non-malicious file:
- %User Profile%\Local Settings\BriefintroductionofKim-Jong-il.pdf
(Note: %User Profile% is the current user's profile folder, which is usually C:\Windows\Profiles\{user name} on Windows 98 and ME, C:\WINNT\Profiles\{user name} on Windows NT, and C:\Documents and Settings\{user name} on Windows 2000, XP, and Server 2003.)
Dropping Routine
This Trojan executes the dropped file(s). As a result, malicious routines of the dropped files are exhibited on the affected system.
NOTES:
It arrives as an attachment to spammed mails:

It drops and opens a non-malicious PDF file to trick the user that the file is non-malicious:

Upon execution, it checks the version of the Adobe Acrobat on the system. If the version is 9.4 or below, it attempts to exploit the following vulnerabilities to drop and execute files:
It joins the files LOG1.TXT and FABC.SCR to form the file ABC.SCR which it executes afterwards.
Connect with us on
| | | |