
Dell SonicWall Threats Research team received reports of a Trojan that aims at gathering sensitive system information from the victims machine and transmits it to a remote server.
Infection Cycle
Upon execution the Trojan scans %App Data% and %Program Files% folder for presence of executable files. It also carries a list of executable names that it scans, some of them are as follows:
Once it finds an executable, it appends s at the end of the executable name and drops a copy of itself along with the original executable.
It drops the following file on the system:
It adds the following Registry Keys to disable User Account Control prompts:
It adds an extensive list of Scheduled tasks for the executables that it drops at various locations:
The Trojan communicates with med.tripod.com and downloads configpublic96.dat. This file contains multiple instructions from the server.
The Trojan collects sensitive system related data and sends it to the attacker at load.org in a POST request. It sends this information in Base64 Encoded format, some of it is as follows:
Overall the motive of this Trojan is to steal sensitive user information and pass it on to the attacker. It remains to be seen if this threat is updated with more functionality in the time to come.
Dell SonicWALL Gateway AntiVirus provides protection against this threat via the following signature:
Share This Article

An Article By
An Article By
Security News
Security News