TROJ_AGENT.XXTXA
Windows
Threat Type: Trojan
Destructiveness: No
Encrypted:
In the wild: Yes
OVERVIEW
This Trojan arrives on a system as a file dropped by other malware or as a file downloaded unknowingly by users when visiting malicious sites.
TECHNICAL DETAILS
Varies
EXE
No
11 Nov 2014
Arrival Details
This Trojan arrives on a system as a file dropped by other malware or as a file downloaded unknowingly by users when visiting malicious sites.
Installation
This Trojan drops the following files:
- {malware path}\PS00000P.exe
- {malware path}\pos_update.exe
- {malware path}\regsvr32.exe
- {malware path}\Data\Wait.dat
- %System%\vcf132.ocx
(Note: %System% is the Windows system folder, where it usually is C:\Windows\System32 on all Windows operating system versions.)
It creates the following folders:
- {malware path}\Data
Other System Modifications
This Trojan adds the following registry keys:
HKEY_CLASSES_ROOT\VCF1.VCF1Ctrl.1
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\
VCF1.VCF1Ctrl.1
Other Details
This Trojan connects to the following possibly malicious URL:
- {BLOCKED}.{BLOCKED}.13.42
- http://{BLOCKED}.{BLOCKED}.159.37:8124/bin