The Trojan may arrive through spam email.
When the Trojan is executed, it may create the following files:
- %TEMP%\[RANDOM CHARACTERS FILE NAME].bat
- %UserProfile%\Local Settings\Application Data\pny\pnd.exe
The Trojan then creates the following registry entry so that it executes whenever Windows starts: HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Run\"Microsoft PnD" = "%UserProfile%\Local Settings\Application Data\pny\pnd.exe"
It also creates the following registry entries:
- HKEY_CURRENT_USER\Software\WinRAR\"Client Hash" = "[RANDOM HEXADECIMAL CHARACTERS]"
- HKEY_CURRENT_USER\Software\WinRAR\"HWID" = "[RANDOM HEXADECIMAL CHARACTERS]"
The Trojan may then connect to any of the following remote locations:
- 91.231.156.36
- http://2.enzofavata.com/forum/viewtopic.php
- http://2.sardiniaexport.com/forum/viewtopic.php
- http://222119966122.su/cloud.php
- http://4.pianetapollo.com/ponyb/gate.php
- http://4.professionalsoft.com/ponyb/gate.php
- http://6.grapaimport.com/ponyb/gate.php
- http://6.grapainterfood.com/ponyb/gate.php
- http://atdsupdate.in/all/old.php
- http://banderbon.cz.cc/file/local/tool.exe
- http://bestinsighttours.com/bZ6.exe
- http://fokanal.cz.cc/gate.php
- http://milion8dreams.ru/cloud.php
- http://mjorart.com/jTc.exe
- http://powergames.com.pt/KVG.exe
- http://quranaqiq.com/1kH.exe
- http://rdquark.com/cAB.exe
- http://reymontstore.com/jJW5.exe
- http://staugustineblues.com/n8cZZi.exe
- http://www.rcrender.com/47NK.exe
- http://www.westquimica.com/AuNP5.exe
- onylkp.in
- weboffice.dyndns-office.com
- willowcreekcompany.mobi
The Trojan may then perform the following actions:
- Download additional malware
- Steal passwords
Symantec Security Response encourages all users and administrators to adhere to the following basic security "best practices":