When the Trojan is executed, it copies itself to the following location:
%UserProfile%\Application Data\froot\froot.exe
The Trojan then creates the following registry entry so that it executes whenever Windows starts:
HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Run\"Free" = "%UserProfile%\Application Data\froot\froot.exe -b"
Next, the Trojan connects to a remote location that is constructed from three components.
The first component is one of the following command-and-control (C&C) server domains:
- minkosoft.in
- mifkrosoft.in
- explorerie3.in
- explorerie4.in
- explorerie5.in
The next component is one of the following URLs on the C&C server:
- code/gate.php
- cow/gate.php
- leex/gate.php
- like/gate.php
- loc/gate.php
- milk/gate.php
- mozy/gate.php
- pic8/gate.php
- plea/gate.php
- prog/gate.php
- tron/gate.php
- win/gate.php
- zerro/gate.php
- zip.gate.php
- zuum/gate.php
Finally, the Trojan uses one of the following parameters at the above address:
- gate.php?getip=getip
- gate.php?getpic=getpic
- gate.php?user=%s&uid=%s&os=%i
- gate.php?user=%s&uid=%s&os=%i
- gate.php?user=%s&uid=%s&os=%i&pin=%s
- gate.php?user=%s&upg=upg
The Trojan then downloads commands from the remote location, which allow a remote attacker to perform the following actions on the compromised computer:
- Delete files
- Download and display a ransom message
- Download updates
- Submit a PIN
When the computer is locked with the ransom image, the Trojan ends the following processes:
- msconfig.exe
- narrator.exe
- regedit.exe
- seth.exe
- taskmgr.exe
- utilman.exe
Symantec Security Response encourages all users and administrators to adhere to the following basic security "best practices":