HKTL_BINDER

 Analysis by: Homer Pacag

 ALIASES:

VirTool:Win32/Obfuscator.NL (Microsoft); Trojan.Win32.Llac.bsir (Kaspersky)

 PLATFORM:

Windows

 OVERALL RISK RATING:
 DAMAGE POTENTIAL:
 DISTRIBUTION POTENTIAL:
 REPORTED INFECTION:
 INFORMATION EXPOSURE:

  • Threat Type: Hacking Tool

  • Destructiveness: No

  • Encrypted: No

  • In the wild: Yes

  OVERVIEW


This hacking tool may be manually installed by a user.

  TECHNICAL DETAILS

File Size:

777,216 bytes

File Type:

EXE

Memory Resident:

Yes

Initial Samples Received Date:

14 May 2014

Arrival Details

This hacking tool may be manually installed by a user.

NOTES:

It is used to bind two individual files to be executed as one.

It requires the user to select two files to bind by clicking the “Select File1” and/or “Select File2” button and selecting the file in the dialog box.

The selected files will be bound and will generate an executable file when the“Bind Files” button is clicked. The user will be prompted to select which file name to use for the executable file created by this hacking tool.

It uses the following Graphical User Interface (GUI):

  SOLUTION

Minimum Scan Engine:

9.750

SSAPI PATTERN File:

1.509.01

SSAPI PATTERN Date:

14 May 2014

Step 1

Before doing any scans, Windows XP, Windows Vista, and Windows 7 users must disable System Restore to allow full scanning of their computers.

Step 2

Scan your computer with your Trend Micro product to delete files detected as HKTL_BINDER. If the detected files have already been cleaned, deleted, or quarantined by your Trend Micro product, no further step is required. You may opt to simply delete the quarantined files. Please check this Knowledge Base page for more information.


Did this description help? Tell us how we did.