TROJ_CRYPGP.A
TrojanDownloader:Win32/Gulcrypt.B (MICROSOFT), a variant of Win32/Kryptik.CXIB trojan (NOD32)
Windows
Threat Type: Trojan
Destructiveness: No
Encrypted:
In the wild: Yes
OVERVIEW
This Trojan arrives on a system as a file dropped by other malware or as a file downloaded unknowingly by users when visiting malicious sites.
TECHNICAL DETAILS
987,648 bytes
EXE
Yes
05 Feb 2015
Arrival Details
This Trojan arrives on a system as a file dropped by other malware or as a file downloaded unknowingly by users when visiting malicious sites.
Installation
This Trojan drops the following files:
- %System Root%\xwintmp\filepas.tmp
- %System Root%\xwintmp\randseed.bin
- %System Root%\xwintmp\pubring.pgp
- %System Root%\xwintmp\chuingamshik
- %System Root%\xwintmp\filepas.asc
(Note: %System Root% is the Windows root folder, where it usually is C:\ on all Windows operating system versions.)
It drops and executes the following files:
- %System Root%\xwintmp\rar.exe
- %System Root%\xwintmp\pgp.exe
- %System Root%\xwintmp\manager.exe
(Note: %System Root% is the Windows root folder, where it usually is C:\ on all Windows operating system versions.)
It creates the following folders:
- %System Root%\xwintmp\
(Note: %System Root% is the Windows root folder, where it usually is C:\ on all Windows operating system versions.)
NOTES:
It creates the file "~files~(hostname)" in folders where it is able to archive files.
Archived files are renamed as {original file name}.{original file extension}.rar.