The Trojan may arrive as a file with the following name:
%CurrentFolder%\mslogin.dll
When the Trojan is executed, it creates the following registry subkeys:
- HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap\IntranetName
- HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap\ProxyByPass
- HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap\UNCAsIntranet
The Trojan checks if it has been executed using rundll32.exe. If it has, it connects to the following URL:
https://www.google.com/accounts/Login
The Trojan uses a predetermined user name and password to authenticate to the Web site. When verified, a new connection is made to the following URL:
[http://]www.google.com/group/escape2sun/pa[REMOVED]
When this page is retrieved, encoded commands on the page are executed. Responses from the Trojan are uploaded using HTTP POST to the following URL:
[http://]www.google.com/group/escape2sun/po[REMOVED]
The Trojan logs the commands to the following file:
%CurrentFolder%\tmw.dat
The Trojan then exits.
Symantec Security Response encourages all users and administrators to adhere to the following basic security "best practices":