
SonicWALL UTM Research team observed reports of a new Trojan targeting Vietnamese speakers reported by Google here. Authors of this malware repackaged the binary together with Vietnamese keyboard driver VPSKeys. VPSKeys is a legitimate application that provides Vietnamese keyboard support to Windows users.
Users who downloaded this keyboard driver may not be aware that it is a tampered version since both the VPSKeys installer and the malicious binary looks the same except for the file size discrepancy.
Screenshot of VPSKeys
Installation
Files Installed
Registry Changes
Added to run the binary as a service
Added to run the binary on every Windows startup
Added to run the binary on Windows Safemode
Process Created
Network Activity
It tries to connect to the following domain:
This malware is also known as W32/Vulcanbot , Win32/VBbot.V , and VBbot.A
SonicWALL Gateway AntiVirus provides protection against this Trojan via GAV: Vulcanbot (Trojan), GAV: Dosvine (Trojan), GAV: Dosvine_2 (Trojan), GAV: Dosvine_3 (Trojan) and GAV: VBBot.V (Trojan) signatures.
Share This Article

An Article By
An Article By
Security News
Security News