
The Dell SonicWall Threats Research team has received reports of a Trojan which leaves no trace behind and steals information from the infected system which is spreading in the wild.
Infection Cycle:
The Trojan uses the following mutex:
Upon looking at the properties, the trojan is described as an application in Chinese, named Aspirate.
Upon execution, the Trojan creates a copy of itself in the following location:
It creates a autostart object at:
In order to start after reboot the malware creates the following registry key:
To make removal even more difficult, it disables the System Restore:
The trojan executes these commands:
It creates a file and tries to steal information at:
It tries to connect to the following domains:
It does the following request multiple times to the C&C servers. Once it receives the reply, it sends encrypted information to the servers.
Dell SonicWALL Gateway AntiVirus and Intrusion Prevention provides protection against this threat with the following signatures:
Share This Article

An Article By
An Article By
Security News
Security News