This Trojan is a malicious AutoIT script that gets loaded by a digitally signed copy of an AutoIT.exe file.
It is normally dropped by a malicious installation package to the following location:
%CurrentFolder%\Plat.mod
Next, the Trojan may perform the following actions on the compromised computer:
- Check for antivirus processes
- Download and execute other malicious files
- Gather system information and upload it to a remote location
- Record key strokes and save them to a log file
- Send the log file to a remote location
The Trojan then opens a back door and communicates with a command-and-control (C&C) server at one of the following locations:
- NAT.game456.com-hell.game456.com_download.game456.com.sina456.news456.g[REMOVED]456.com
- NAT.game456.com-hell.game456.com_download.game456.com.sina456.new456.y[REMOVED]ve.com
Symantec Security Response encourages all users and administrators to adhere to the following basic security "best practices":