This threat is downloaded and installed as a Chrome browser extension.
When the Trojan is executed, it may drop the following files:
- %UserProfile%\Application Data\Google\Chrome\User Data\Default\Extensions\fmphgefonmnoadmehmejfjnbmgoolboc\[EXTENSION VERSION]\TODO
- %UserProfile%\Application Data\Google\Chrome\User Data\Default\Extensions\fmphgefonmnoadmehmejfjnbmgoolboc\[EXTENSION VERSION]\sha1.h
- %UserProfile%\Application Data\Google\Chrome\User Data\Default\Extensions\fmphgefonmnoadmehmejfjnbmgoolboc\[EXTENSION VERSION]\sha1.c
- %UserProfile%\Application Data\Google\Chrome\User Data\Default\Extensions\fmphgefonmnoadmehmejfjnbmgoolboc\[EXTENSION VERSION]\LICENSE
- %UserProfile%\Application Data\Google\Chrome\User Data\Default\Extensions\fmphgefonmnoadmehmejfjnbmgoolboc\[EXTENSION VERSION]\INSTALL
- %UserProfile%\Application Data\Google\Chrome\User Data\Default\Extensions\fmphgefonmnoadmehmejfjnbmgoolboc\[EXTENSION VERSION]\main.js
- %UserProfile%\Application Data\Google\Chrome\User Data\Default\Extensions\fmphgefonmnoadmehmejfjnbmgoolboc\[EXTENSION VERSION]\icon.png
- %UserProfile%\Application Data\Google\Chrome\User Data\Default\Extensions\fmphgefonmnoadmehmejfjnbmgoolboc\[EXTENSION VERSION]\Makefile
- %UserProfile%\Application Data\Google\Chrome\User Data\Default\Extensions\fmphgefonmnoadmehmejfjnbmgoolboc\[EXTENSION VERSION]\make.bat
- %UserProfile%\Application Data\Google\Chrome\User Data\Default\Extensions\fmphgefonmnoadmehmejfjnbmgoolboc\[EXTENSION VERSION]\manifest.json
- %UserProfile%\Application Data\Google\Chrome\User Data\Default\Extensions\fmphgefonmnoadmehmejfjnbmgoolboc\[EXTENSION VERSION]\jquery.min.js
- %UserProfile%\Application Data\Google\Chrome\User Data\Default\Extensions\fmphgefonmnoadmehmejfjnbmgoolboc\[EXTENSION VERSION]\background.js
- %UserProfile%\Application Data\Google\Chrome\User Data\Default\Extensions\fmphgefonmnoadmehmejfjnbmgoolboc\[EXTENSION VERSION]\background.html
- %UserProfile%\Application Data\Google\Chrome\User Data\Default\Extensions\fmphgefonmnoadmehmejfjnbmgoolboc\[EXTENSION VERSION]\sha1_pwcrack.cc
- %UserProfile%\Application Data\Google\Chrome\User Data\Default\Extensions\fmphgefonmnoadmehmejfjnbmgoolboc\[EXTENSION VERSION]\sha1_pwcrack.nmf
- %UserProfile%\Application Data\Google\Chrome\User Data\Default\Extensions\fmphgefonmnoadmehmejfjnbmgoolboc\[EXTENSION VERSION]\sha1_pwcrack_64.o
- %UserProfile%\Application Data\Google\Chrome\User Data\Default\Extensions\fmphgefonmnoadmehmejfjnbmgoolboc\[EXTENSION VERSION]\sha1_pwcrack_32.o
- %UserProfile%\Application Data\Google\Chrome\User Data\Default\Extensions\fmphgefonmnoadmehmejfjnbmgoolboc\[EXTENSION VERSION]\sha1_pwcrack_x86_64.nexe
- %UserProfile%\Application Data\Google\Chrome\User Data\Default\Extensions\fmphgefonmnoadmehmejfjnbmgoolboc\[EXTENSION VERSION]\sha1_pwcrack_x86_32.nexe
- %UserProfile%\Application Data\Google\Chrome\User Data\Default\Extensions\fmphgefonmnoadmehmejfjnbmgoolboc\[EXTENSION VERSION]\pack_extension.bat
- %UserProfile%\Application Data\Google\Chrome\User Data\Default\Extensions\fmphgefonmnoadmehmejfjnbmgoolboc\[EXTENSION VERSION]\pack_extension - Copy.bat
It then attempts to steal user names and passwords entered into the Chrome browser. It also attempts to steal cookies stored in the browser.
It also collects user information and sends it to a remote server. It may also download files from the remote server.
Next, it opens a back door on the compromised computer and awaits commands sent from the remote attacker.
Symantec Security Response encourages all users and administrators to adhere to the following basic security "best practices":