The Trojan injects its code into the explorer.exe process.
The Trojan connects to the following locations on port 31439:
www.[DOMAIN NAME]/g.php
Note: [DOMAIN NAME] is variable and subject to change.
The Trojan drops the following file:
%UserProfile%\Application Data\Identities\[RANDOM CLSID]\LicenseValidator.exe
The Trojan creates the following registry subkeys:
- HKEY_CURRENT_USER\Software\Software\Microsoft\Windows\CurrentVersion\Explorer\Advanced\StartCurrId
- HKEY_CURRENT_USER\Software\Software\Microsoft\Windows\CurrentVersion\Explorer\Advanced\StartMainId
- HKEY_CURRENT_USER\Software\Software\Microsoft\Windows\CurrentVersion\Explorer\Advanced\PersistFolder
- HKEY_CURRENT_USER\Software\Software\Microsoft\Windows\CurrentVersion\Explorer\Advanced\PersistFile
- HKEY_CURRENT_USER\Software\Software\Microsoft\Windows\CurrentVersion\Explorer\Advanced\StartProcIrq
- HKEY_CURRENT_USER\Software\Software\Microsoft\Windows\CurrentVersion\Explorer\Advanced\StartMainMask
- HKEY_CURRENT_USER\Software\Software\Microsoft\Windows\CurrentVersion\Explorer\Advanced\StartCurrMask
- HKEY_CURRENT_USER\Software\Software\Microsoft\Windows\CurrentVersion\Explorer\StartPage\ReserveProgram
The Trojan creates the following registry entry so that it runs every time Windows starts:
- HKEY_CURRENT_USER\Software\Software\Microsoft\Windows\CurrentVersion\Run\"LicenseValidator" = "%UserProfile%\Application Data\Identities\[RANDOM CLSID]\LicenseValidator.exe"
The Trojan creates the following registry entries:
- HKEY_CURRENT_USER\Software\Software\Microsoft\Windows\CurrentVersion\Explorer\Advanced\"StartUrlId" = "0"
- HKEY_CURRENT_USER\Software\Software\Microsoft\Windows\CurrentVersion\Explorer\"Browse Files" = "[RANDOM CLSID]"
- HKEY_CURRENT_USER\Software\Software\Microsoft\Windows\CurrentVersion\Explorer\"Browse Folders" = "[RANDOM CLSID]"
The Trojan then drops modules in bzip+xor form to the following location:
%UserProfile%\Application Data\TeamViewer\[RANDOM CLSID]\[RANDOM CHARACTERS].dat
The Trojan may monitor activity on the following Web browsers in order to capture details of accessed Web pages:
- Sol
- Chrome
- Firefox
- Internet Explorer
- Opera
- Maxthon
- Netscape Navigator
The Trojan captures sensitive information such as data on all processes running, website browsing history, and details of accessed Internet banking sites, and sends it to the following remote locations:
- [http://]qualitymayorista.com/swf/[REMOVED]
- [http://]klthk.cz/pgm/[REMOVED]
- [http://]www.willowbendfitnessclub.com/com/[REMOVED]
- [http://]www.go-cube.ch/[REMOVED]
The Trojan may use a fake certificate for man-in-the-middle attacks on banking websites.
Symantec Security Response encourages all users and administrators to adhere to the following basic security "best practices":