Infection Channel: Downloaded from the Internet, Dropped by other malware
This Trojan is a ransomware using fake digital certificates to avoid digital signing checks.
To get a one-glance comprehensive view of the behavior of this Trojan, refer to the Threat Diagram shown below.

For the related story, you may read the blog post Ransomware Bears Fake Digital Signature
This Trojan arrives on a system as a file dropped by other malware or as a file downloaded unknowingly by users when visiting malicious sites.
It modifies the Internet Explorer Zone Settings.
It connects to certain websites to send and receive information.
File size: Varies
File type: DLL
Memory resident: Yes
Initial samples received date: 19 Nov 2012
Payload: Terminates processes, Compromises system security
Arrival Details
This Trojan arrives on a system as a file dropped by other malware or as a file downloaded unknowingly by users when visiting malicious sites.
Installation
This Trojan drops the following component file(s):
- {All User's Profile}\lsass.exe - Normal
- {All User's Profile}\{random}.pad
It injects codes into the following process(es):
- IEXPLORE.EXE
- IESTART.EXE
- FIREFOX.EXE
- OPERA.EXE
- CHROME.EXE
Autostart Technique
This Trojan drops the following shortcut pointing to its copy in the User Startup folder to enable its automatic execution at every system startup:
Other System Modifications
This Trojan adds the following registry entries:
HKEY_CURRENT_USER\Microsoft\Windows\
CurrentVersion\Internet Settings\Zones\
0
2500 = "3"
HKEY_CURRENT_USER\Microsoft\Windows\
CurrentVersion\Internet Settings\Zones\
1
2500 = "3"
HKEY_CURRENT_USER\Microsoft\Windows\
CurrentVersion\Internet Settings\Zones\
2
2500 = "3"
HKEY_CURRENT_USER\Microsoft\Windows\
CurrentVersion\Internet Settings\Zones\
3
2500 = "3"
HKEY_CURRENT_USER\Microsoft\Windows\
CurrentVersion\Internet Settings\Zones\
4
2500 = "3"
HKEY_CURRENT_USER\Software\Microsoft\
Internet\Explorer\Main
NoProtectedBanner = "1"
It modifies the following registry entries:
HKEY_CURRENT_USER\Microsoft\Windows\
CurrentVersion\Internet Settings\Zones\
0
1609 = "0"
(Note: The default value data of the said registry entry is 1.)
HKEY_CURRENT_USER\Microsoft\Windows\
CurrentVersion\Internet Settings\Zones\
1
1609 = "0"
(Note: The default value data of the said registry entry is 1.)
HKEY_CURRENT_USER\Microsoft\Windows\
CurrentVersion\Internet Settings\Zones\
2
1609 = "0"
(Note: The default value data of the said registry entry is 1.)
HKEY_CURRENT_USER\Microsoft\Windows\
CurrentVersion\Internet Settings\Zones\
3
1609 = "0"
(Note: The default value data of the said registry entry is 1.)
HKEY_CURRENT_USER\Microsoft\Windows\
CurrentVersion\Internet Settings\Zones\
4
1609 = "0"
(Note: The default value data of the said registry entry is 1.)
Process Termination
This Trojan terminates the following processes if found running in the affected system's memory:
Web Browser Home Page and Search Page Modification
This Trojan modifies the Internet Explorer Zone Settings.
Other Details
This Trojan connects to the following website to send and receive information:
Connect with us on
| | | |