Infection Channel: Spammed via email
This is a keylogger found inside a spammed email message that purports to come from the Cabinet Office Information Systems Office.
To get a one-glance comprehensive view of the behavior of this Spyware, refer to the Threat Diagram shown below.

This spyware arrives as an attachment to email messages spammed by other malware/grayware or malicious users.
It logs a user's keystrokes to steal information.
It deletes the initially executed copy of itself.
File size: 234,328 bytes
File type: EXE
Memory resident: Yes
Initial samples received date: 24 Jan 2012
Arrival Details
This spyware arrives as an attachment to email messages spammed by other malware/grayware or malicious users.
Installation
This spyware drops the following files:
- {All Users Profile}\Microsoft\PDA\Mircosoft System..DLL
It creates the following folders:
- {All Users Profile}\Microsoft\PDA
Autostart Technique
This spyware registers itself as a system service to ensure its automatic execution at every system startup by adding the following registry entries:
HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\
Services\Mircosoft System.
Type = 10
HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\
Services\Mircosoft System.
Start = 2
HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\
Services\Mircosoft System.
ErrorControl = 1
HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\
Services\Mircosoft System.
ImagePath = %System%\svchost.exe -k LocalService
HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\
Services\Mircosoft System.
DisplayName = "Mircosoft System."
HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\
Services\Mircosoft System.
ObjectName = "LocalSystem"
HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\
Services\Mircosoft System.
Description = "Mircosoft System."
HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\
Services\Mircosoft System.\Parameters
ServiceDll = {All Users Profile}\Microsoft\PDA\Mircosoft System..DLL
Other System Modifications
This spyware modifies the following registry key(s)/entry(ies) as part of its installation routine:
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\
Windows NT\CurrentVersion\SvcHost
LocalService = {Default Value} Mircosoft System.
(Note: The default value data of the said registry entry is {Default Value}.)
It adds the following registry keys as part of its installation routine:
HKEY_CLASSES_ROOT\SS
Information Theft
This spyware logs a user's keystrokes to steal information.
Stolen Information
This spyware saves the stolen information in the following file:
(Note: %System% is the Windows system folder, which is usually C:\Windows\System32.)
It sends the gathered information via HTTP POST to the following URL:
- {BLOCKED}.{BLOCKED}.60.142
Other Details
This spyware deletes the initially executed copy of itself
Connect with us on
| | | |