When the Trojan is executed, it creates the following mutex so that only one instance of it runs on the compromised computer:
G46A33F21110
Next, it connects to Google docs and uses it as a proxy in order to receive commands from the following command-and-control (C&C) servers:
- 83.222.226.158
- akamaihub.com
- msupdatecdn.com
- stocksengine.net
The Trojan may then perform the following commands on the compromised computer:
- Open a console
- Download and execute a file
- Remove itself
- Exit
The Trojan downloads and executes the following file:
%CurrentFolder%\scvhost.exe
Next, the Trojan sends the following information to a remote location:
- Back door program status
- Back door program version number
- Current folder path
- Domain
- Domain admin user name
- Host name
- Local admin user name
- Operating System type
- User name
Symantec Security Response encourages all users and administrators to adhere to the following basic security "best practices":