Infection Channel: Dropped by other malware, Downloaded from the Internet
This Trojan arrives on a system as a file dropped by other malware or as a file downloaded unknowingly by users when visiting malicious sites. It may be downloaded by other malware/grayware from remote sites.
It connects to certain websites to send and receive information.
File size: 45,056 bytes
File type: EXE
Memory resident: Yes
Initial samples received date: 18 Jan 2013
Payload: Collects system information, Connects to URLs/IPs, Blocks user desktop
Arrival Details
This Trojan arrives on a system as a file dropped by other malware or as a file downloaded unknowingly by users when visiting malicious sites.
It may be downloaded by the following malware/grayware from remote sites:
It may be downloaded from the following remote sites:
- http://{BLOCKED}yacipta.com/mastersoft/disk.exe
Installation
This Trojan drops the following copies of itself into the affected system:
- %Application Data%\{random file name}.exe
(Note: %Application Data% is the current user's Application Data folder, which is usually C:\Documents and Settings\{user name}\Application Data on Windows 2000, XP, and Server 2003, or C:\Users\{user name}\AppData\Roaming on Windows Vista and 7.)
Autostart Technique
This Trojan adds the following registry entries to enable its automatic execution at every system startup:
HKEY_CURRENT_USER\Software\Microsoft\
Windows\CurrentVersion\Run
Microsoft = "%Application Data%\{random file name}.exe"
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\
Windows\CurrentVersion\Run
svñhîst = "{Malware Path and File Name}"
Other System Modifications
This Trojan adds the following registry entries:
HKEY_CURRENT_USER\Software\Microsoft\
Windows\CurrentVersion\Policies\
Attachments
SaveZoneInformation = "1"
HKEY_CURRENT_USER\Software\Microsoft\
Windows\CurrentVersion\Policies\
Associations
LowRiskFileTypes = ".exe;"
Other Details
This Trojan connects to the following URL(s) to check for an Internet connection:
It connects to the following website to send and receive information:
- http://{BLOCKED}ister.info/lending/tds.php
- http://{BLOCKED}ister.info/lending/getunlock.php
- http://{BLOCKED}ister.info/lending/EN.php
NOTES:
It locks the user's screen and displays the aforementioned sites in the screen. However, as of this writing, the said sites are already inaccessible.
It gathers the following information for its ransomware routine:
- OS version
- System default language ID
- System metrics (desktop width and height)
Connect with us on
| | | |