Infection Channel: Downloaded from the Internet
This Trojan may be downloaded by other malware/grayware from remote sites.
It connects to a website to send and receive information.
File size: 263,680 bytes
File type: DLL
Memory resident: Yes
Initial samples received date: 10 Jan 2013
Payload: Displays graphics, Downloads files, Closes windows
Arrival Details
This Trojan may be downloaded by the following malware/grayware from remote sites:
- http://50ee59e132505.{BLOCKED}ee123.com/news/Edit.exe
Installation
This Trojan drops the following file(s)/component(s):
- {All User's Profile}\Application Data\{reversed malware filename}.js
It injects itself into the following processes as part of its memory residency routine:
- IEXPLORE.EXE
- IESTART.EXE
- FIREFOX.EXE
- OPERA.EXE
- CHROME.EXE
Autostart Technique
This Trojan drops the following file(s) in the Windows User Startup folder to enable its automatic execution at every system startup:
- %User Startup%\runctf.lnk - detected as Crypt_Reveton.LNK
(Note: %User Startup% is the current user's Startup folder, which is usually C:\Windows\Profiles\{user name}\Start Menu\Programs\Startup on Windows 98 and ME, C:\WINNT\Profiles\{user name}\Start Menu\Programs\Startup on Windows NT, and C:\Documents and Settings\{User name}\Start Menu\Programs\Startup.)
Other System Modifications
This Trojan adds the following registry entries:
HKEY_CURRENT_USER\Software\Microsoft\
Windows\CurrentVersion\Internet Settings\
Zones\0
2500 = "3"
HKEY_CURRENT_USER\Software\Microsoft\
Windows\CurrentVersion\Internet Settings\
Zones\1
2500 = "3"
HKEY_CURRENT_USER\Software\Microsoft\
Windows\CurrentVersion\Internet Settings\
Zones\2
2500 = "3"
HKEY_CURRENT_USER\Software\Microsoft\
Windows\CurrentVersion\Internet Settings\
Zones\3
2500 = "3"
HKEY_CURRENT_USER\Software\Microsoft\
Windows\CurrentVersion\Internet Settings\
Zones\4
2500 = "3"
HKEY_CURRENT_USER\Software\Microsoft\
Internet Explorer\Main
NoProtectedModeBanner = "1"
HKEY_CURRENT_USER\Software\Microsoft\
Internet Explorer\Main
NoProtectedModeBanner = "1"
It modifies the following registry entries:
HKEY_CURRENT_USER\Software\Microsoft\
Windows\CurrentVersion\Internet Settings\
Zones\0
1609 = "0"
(Note: The default value data of the said registry entry is 1.)
HKEY_CURRENT_USER\Software\Microsoft\
Windows\CurrentVersion\Internet Settings\
Zones\1
1609 = "0"
(Note: The default value data of the said registry entry is 1.)
HKEY_CURRENT_USER\Software\Microsoft\
Windows\CurrentVersion\Internet Settings\
Zones\2
1609 = "0"
(Note: The default value data of the said registry entry is 1.)
HKEY_CURRENT_USER\Software\Microsoft\
Windows\CurrentVersion\Internet Settings\
Zones\3
1609 = "0"
(Note: The default value data of the said registry entry is 1.)
HKEY_CURRENT_USER\Software\Microsoft\
Windows\CurrentVersion\Internet Settings\
Zones\4
1609 = "0"
(Note: The default value data of the said registry entry is 1.)
Backdoor Routine
This Trojan connects to the following websites to send and receive information:
- {BLOCKED}.{BLOCKED}.184.55
NOTES:
This Trojan downloads an encrypted file and saves it to the infected system as the following:
- {All User's Profile}\Application Data\{reversed malware filename}.pad - detected as Cryp_RevetonDEF
This encrypted file contains a .DLL file when decrypted. The contents of the encrypted file may vary depending on the remote server.
The DLL file contains a lock screen image which has images of various anti-virus companies stating that they signed a treaty to identify cybercriminals.
Once the malware is executed, It locks the user's system and displays the screen where a fake FBI message is displayed. To unlock the system, the user is forced to pay 100 GBP via Ukash or Paysafecard.
Connect with us on
| | | |