JAVA_ADWIND.YZZS
Trojan:Java/Adwind.J (Microsoft); Java/Adwind.HR (ESET-NOD32); Trojan.Java.Adwind (Ikarus); BackDoor-FCRJ!Adwind (McAfee); JAVA/Adwind.gfs (Avira); Java.Adwind.B (BitDefender)
Windows
Threat Type: Trojan
Destructiveness: No
Encrypted:
In the wild: Yes
OVERVIEW
This Trojan arrives on a system as a file dropped by other malware or as a file downloaded unknowingly by users when visiting malicious sites.
TECHNICAL DETAILS
101,361 bytes
JAR
10 Aug 2015
Arrival Details
This Trojan arrives on a system as a file dropped by other malware or as a file downloaded unknowingly by users when visiting malicious sites.
Installation
This Trojan drops the following copies of itself into the affected system:
- %User Profile%\JdhsLcg3p8x\JdhsLcg3p8x\9L49GQIzrjh.vlTV7c
(Note: %User Profile% is the current user's profile folder, which is usually C:\Documents and Settings\{user name} on Windows 2000, XP, and Server 2003, or C:\Users\{user name} on Windows Vista and 7.)
It drops the following files:
- %User Profile%\JdhsLcg3p8x\BHFtwe\{copies of files under Java Installation folder}
- %Windows%\t.txt
(Note: %User Profile% is the current user's profile folder, which is usually C:\Documents and Settings\{user name} on Windows 2000, XP, and Server 2003, or C:\Users\{user name} on Windows Vista and 7.. %Windows% is the Windows folder, where it usually is C:\Windows on all Windows operating system versions.)
It creates the following folders:
- %User Profile%\JdhsLcg3p8x
- %User Profile%\JdhsLcg3p8x\BHFtwe
- %User Profile%\JdhsLcg3p8x\JdhsLcg3p8x
- %User Profile%\JdhsLcg3p8x\v0yhUowT63u
(Note: %User Profile% is the current user's profile folder, which is usually C:\Documents and Settings\{user name} on Windows 2000, XP, and Server 2003, or C:\Users\{user name} on Windows Vista and 7.)
Autostart Technique
This Trojan adds the following registry entries to enable its automatic execution at every system startup:
HKEY_CURRENT_USER\Software\Microsoft\
Windows\CurrentVersion\Run
4NlMlMnpSwI = ""%User Profile%\JdhsLcg3p8x\BHFtwe\bin\javaw.exe" -jar "%User Profile%\JdhsLcg3p8x\JdhsLcg3p8x\9L49GQIzrjh.vlTV7c""
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\
Windows\CurrentVersion\Run
4NlMlMnpSwI = ""%User Profile%\JdhsLcg3p8x\BHFtwe\bin\javaw.exe" -jar "%User Profile%\JdhsLcg3p8x\JdhsLcg3p8x\9L49GQIzrjh.vlTV7c""
Other Details
This Trojan connects to the following possibly malicious URL:
- {BLOCKED}.{BLOCKED}.129.211