Once executed, the Trojan attempts to exploit
Adobe Flash Player, Acrobat Reader, and Acrobat 'authplay.dll' Remote Code Execution Vulnerability (BID 40586).
The Trojan then downloads a bitmap file from the following URL:
[http://]google-analytics.dynalias.org/intl/images/calc[REMOVED]
Note: The bitmap file contains an encrypted file (detected as
Backdoor.Trojan).
The downloaded file is extracted to %Temp%\upt.exe and executed.
It then creates the following files:
Next, it copies the file %System%\qmgr.dll to %System%\kernel64.dll.
It then connects to the following URL:
[http://]google-analytics.dynalias.org/ddr/ddrh[REMOVED]
Symantec Security Response encourages all users and administrators to adhere to the following basic security "best practices":