The Trojan may be installed by other malicious software.
When the Trojan is executed, it may create the following file:
/lib/modules/2.6.32-5-amd64/kernel/sound/module_init.ko
It adds the following line to /etc/rc local:
insmod /lib/modules/2.6.32-5-amd64/kernel/sound/module_init.ko
The threat then hides the following files:
- zzzzzz_command_http_inject_for_module_init
- zzzzzz_write_command_in_file
- module_init.ko
- sysctl.conf
Next, it hides the following processes:
- backconnect_command_thread_name
- new_backconnect_command_thread_name
- read_command_http_inject_thread_name
- write_startup_command_thread_name
- write_se_linux_command_thread_name
- get_http_inj_from_server_thread_name
It then hooks the following functions:
- vfs_read
- vfs_readdir
- filldir64
- filldir
- dev_add_pack
- dev_remove_pack
- tcp_sendmsg
Next, the Trojan injects iframes into HTTP packets sent out from the compromised computer.
The Trojan then connects to the following remote location:
188.40.102.11
The Trojan hides connections to the following remote locations:
- 149.20.4.69
- 149.20.20.133
- 192.168.1.40
The threat aslo hides communication packets from the following IP address:
149.20.4.69
Symantec Security Response encourages all users and administrators to adhere to the following basic security "best practices":