Infection Channel: Dropped by other malware
This Trojan arrives on a system as a file dropped by other malware or as a file downloaded unknowingly by users when visiting malicious sites.
It connects to certain websites to send and receive information.
File size: 127,752 bytes
File type: EXE
Memory resident: Yes
Initial samples received date: 10 Jan 2013
Payload: Displays graphics/image, Collects system information
Arrival Details
This Trojan arrives on a system as a file dropped by other malware or as a file downloaded unknowingly by users when visiting malicious sites.
Autostart Technique
This Trojan adds the following registry entries to enable its automatic execution at every system startup:
HKEY_LOCAL_MACHINE\Software\Microsoft\
Windows\CurrentVersion\Run
Update = "{Malware Path and Filename}"
HKEY_CURRENT_USER\Software\Microsoft\
Windows\CurrentVersion\Run
Update = "{Malware Path and Filename}"
Other System Modifications
This Trojan adds the following registry entries:
HKEY_CURRENT_USER\Software\Microsoft\
Windows\CurrentVersion\Explorer
tKRGi7Gas = "{Hex Values}"
HKEY_CURRENT_USER\Software\Microsoft\
Windows\CurrentVersion\Explorer
Gs8FR8 = "{Hex Values}"
HKEY_CURRENT_USER\Software\Microsoft\
Windows\CurrentVersion\Explorer
HnYb3KZ8 = "{Hex Values}"
It deletes the following registry keys:
HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\
Control\SafeBoot
Other Details
This Trojan connects to the following URL(s) to get the affected system's IP address:
- http://www.ip-address.org/ip-checker.php
It connects to the following website to send and receive information:
- {BLOCKED}.{BLOCKED}.86.137/ndex.php
NOTES:
It gathers the following information for its ransomware routine:
- Malware Version & Subid
- OS Version
- System Default Language ID
- System Metrics(Desktop Width and Height)
- Ip Address,Location and ISP
Using this information, it locks the screen (disabling taskmgr.exe and explorer.exe) then display a ransomware threat.
Connect with us on
| | | |