Infection Channel: Downloaded from the Internet
This Trojan may be downloaded by other malware/grayware from remote sites.
It connects to certain URLs. It may do this to remotely inform a malicious user of its installation. It may also do this to download possibly malicious files onto the computer, which puts the computer at a greater risk of infection by other threats. As of this writing, the said sites are inaccessible.
File size: Varies
File type: EXE
Memory resident: Yes
Initial samples received date: 05 Feb 2013
Payload: Downloads files
Arrival Details
This Trojan may be downloaded by the following malware/grayware from remote sites:
- JAVA_EXPLOYT.NTW
- JAVA_EXPLOYT.NEU
Installation
This Trojan drops the following copies of itself into the affected system:
- %Application Data%\skype.dat
(Note: %Application Data% is the current user's Application Data folder, which is usually C:\Documents and Settings\{user name}\Application Data on Windows 2000, XP, and Server 2003, or C:\Users\{user name}\AppData\Roaming on Windows Vista and 7.)
It injects threads into the following normal process(es):
Autostart Technique
This Trojan adds the following registry entries to enable its automatic execution at every system startup:
HKEY_CURRENT_USER\Software\Microsoft\
Windows NT\CurrentVersion\Winlogon
shell = "explorer.exe,%Application Data%\skype.dat"
Download Routine
This Trojan connects to the following malicious URLs:
- http://{BLOCKED}r.ru/qnjtixjxqnjtixjxjkxjzhmpxx_gbcuakvrdmalau-ebexceihdkzo-zmdkpv-radatfstqu_plhc_pixorz-dmzv-yx.php
As of this writing, the said sites are inaccessible.
Connect with us on
| | | |