Infection Channel: Downloaded from the Internet, Dropped by other malware
This spyware is downloaded and executed by JAVA_DLOADER.NTW.
This spyware arrives on a system as a file dropped by other malware or as a file downloaded unknowingly by users when visiting malicious sites. It may be downloaded by other malware/grayware from remote sites.
It executes the downloaded files. As a result, malicious routines of the downloaded files are exhibited on the affected system.
It logs a user's keystrokes to steal information.
It deletes the initially executed copy of itself.
File size: 85,592 bytes
File type: EXE
Memory resident: Yes
Initial samples received date: 18 Jan 2013
Payload: Connects to URLs/IPs
Arrival Details
This spyware arrives on a system as a file dropped by other malware or as a file downloaded unknowingly by users when visiting malicious sites.
It may be downloaded by the following malware/grayware from remote sites:
It may be downloaded from the following remote site(s):
- http://{BLOCKED}lcurrencyreport.com/cybercrime-suspect-arrested/up2.exe
Installation
This spyware adds the following mutexes to ensure that only one of its copies runs at any one time:
Autostart Technique
This spyware adds the following registry entries to enable its automatic execution at every system startup:
HKEY_CURRENT_USER\Software\Microsoft\
Windows\CurrentVersion\Run
igfxtray = "%Application Data%\igfx\igfxtray.exe"
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\
Active Setup\Installed Components\{GUID}
StubPath = %Application Data%\igfx\igfxtray.exe"
Download Routine
This spyware accesses the following websites to download files:
- http://{BLOCKED}yacipta.com/mastersoft/disk.exe
It saves the files it downloads using the following names:
- %User Temp%\{random file name}.exe - TROJ_RANSOM.ACV
(Note: %User Temp% is the current user's Temp folder, which is usually C:\Documents and Settings\{user name}\Local Settings\Temp on Windows 2000, XP, and Server 2003, or C:\Users\{user name}\AppData\Local\Temp on Windows Vista and 7.)
It then executes the downloaded files. As a result, malicious routines of the downloaded files are exhibited on the affected system.
Information Theft
This spyware attempts to steal stored email credentials from the following:
- Thunderbird
- Outlook
- WindowsLive
It attempts to get stored information such as user names, passwords, and hostnames from the following browsers:
- Mozilla Firefox
- Opera
- Google Chrome
- SeaMonkey
It logs a user's keystrokes to steal information.
Other Details
This spyware deletes the initially executed copy of itself
NOTES:
This spyware connects to the following URL to send the gathered information:
- wordpress.{BLOCKED}log.net:3360
Connect with us on
| | | |