This Trojan may be dropped on to the computer by another threat.
It may arrive as one of the following files:
- %UserProfile%\Application Data\Google Talk\googletalk.exe
- %UserProfile%\Application Data\Skype\Phone\Skype.exe
When the Trojan is executed, it may create several configuration files at the following location:
%UserProfile%\Application Data\Microsoft\[RANDOM FOLDER NAME]\[RANDOM FILE NAME]
Next, the Trojan may create one of the following registry entries so that it is executed every time Windows starts:
- HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Run\"googletalk" = "%UserProfile%\Application Data\Google Talk\googletalk.exe /autostart"
- HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Run\"Skype" = "%UserProfile%\Application Data\Skype\Phone\Skype.exe\" /nosplash /minimized""
It then injects itself into the following process:
explorer.exe
The Trojan then opens a back door on TCP port 80 and connects to the following remote locations:
- 91.207.8.198
- 91.211.119.196
- 195.16.89.60
- 188.72.227.35
It may also connect to the following remote locations:
- famous.famoustattoos.net/booking/read?page=120&ylozseub=ZJRWYZFTYdqbPn*V22pQtQnJ25FsE6ucGAyeRJBo
- popa.morgatory.com/sound/cat?n=18&ysqaux=ZJRWYZFTYdspwzffvaxjR25YJX0rngGx
- bog.judaicabyjosh.com/insight/flourence?banner_id=386514&ysqaux=ZJRWYZFTYdspwzffvaxjR25YJX0rngGx
- famous.famoustattoos.net/booking/read?page=120&ysqaux=ZJRWYZFTYdspwzffvaxjR25YJX0rngGx
- igg.niksonic.com/booking/read?page=120&ysqaux=ZJRWYZFTYdspwzffvaxjR25YJX0rngGx
- surio.cubicksplace.com/sound/cat?n=18&ysqaux=ZJRWYZFTYdspwzffvaxjR25YJX0rngGx
- inc.kevinmilligangallery.com/insight/flourencebanner_id=386514&ysqaux=ZJRWYZFTYdspwzffvaxjR25YJX0rngGx
Symantec Security Response encourages all users and administrators to adhere to the following basic security "best practices":