When the Trojan is executed, it drops the following file:
%CommonProgramFiles%\Driver\IntelAMTPP.dll
The Trojan creates the following registry entries so that it runs every time Windows starts:
- HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Enum\Root\LEGACY_WMDMPMSP\"NextInstance" = "1"
- HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Enum\Root\LEGACY_WMDMPMSP\0000\"Class" = "LegacyDriver"
- HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Enum\Root\LEGACY_WMDMPMSP\0000\"ClassGUID" = "{8ECC055D-047F-11D1-A537-0000F8753ED1}"
- HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Enum\Root\LEGACY_WMDMPMSP\0000\"ConfigFlags" = "0"
- HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Enum\Root\LEGACY_WMDMPMSP\0000\"DeviceDesc" = "WmdmPmSp"
- HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Enum\Root\LEGACY_WMDMPMSP\0000\"Legacy" = "1"
- HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Enum\Root\LEGACY_WMDMPMSP\0000\"Service" = "WmdmPmSp"
- HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\WmdmPmSp\"Description" = "Windows Infrared Port Monitor."
- HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\WmdmPmSp\"ErrorControl" = "1"
- HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\WmdmPmSp\"ImagePath" = "%SystemRoot%\System32\svchost.exe -k netsvcs"
- HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\WmdmPmSp\"ObjectName" = "LocalSystem"
- HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\WmdmPmSp\"Start" = "2"
- HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\WmdmPmSp\"Type" = "32"
- HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\WmdmPmSp\Parameters\"ServiceDll" = "%ProgramFiles%\Common Program Files\Driver\IntelAMTPP.dll"
- HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\WmdmPmSp\Security\"Security" = "[BINARY DATA]"
The Trojan contacts the following command-and-control server:
ct.datangcun.com
The Trojan may then perform the following actions:
- Download files
- Execute files
- Find and upload files
- Execute shell commands
Symantec Security Response encourages all users and administrators to adhere to the following basic security "best practices":