BKDR_CYCBOT.NYDP
Windows 2000, Windows XP, Windows Server 2003
Threat Type: Backdoor
Destructiveness: No
Encrypted:
In the wild: Yes
OVERVIEW
This backdoor arrives on a system as a file dropped by other malware or as a file downloaded unknowingly by users when visiting malicious sites.
TECHNICAL DETAILS
Arrival Details
This backdoor arrives on a system as a file dropped by other malware or as a file downloaded unknowingly by users when visiting malicious sites.
Installation
This backdoor creates the following folders:
- %Application Data%\B0B2D
- %Program Files%\2D6E3
- %Program Files%\LP
(Note: %Application Data% is the current user's Application Data folder, which is usually C:\Windows\Profiles\{user name}\Application Data on Windows 98 and ME, C:\WINNT\Profiles\{user name}\Application Data on Windows NT, and C:\Documents and Settings\{user name}\Local Settings\Application Data on Windows 2000, XP, and Server 2003.. %Program Files% is the default Program Files folder, usually C:\Program Files.)
Other System Modifications
This backdoor adds the following registry entries as part of its installation routine:
HKEY_USERS\S-1-5-21-1614895754-436374069-682003330-1003\Software\
Microsoft\Windows\CurrentVersion\
Internet Settings
ProxyServer = "http=127.0.0.1:62020"
It modifies the following registry entries:
HKEY_CURRENT_USER\Software\Microsoft\
MessengerService
Server = "messenger.hotmail.com;64.4.61.35:1863"
(Note: The default value data of the said registry entry is messenger.hotmail.com;64.4.9.254:1863.)
HKEY_CURRENT_USER\Software\Microsoft\
Windows\CurrentVersion\Internet Settings
ProxyEnable = "1"
(Note: The default value data of the said registry entry is 0.)
HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\
Hardware Profiles\0001\Software\
Microsoft\windows\CurrentVersion\
Internet Settings
ProxyEnable = "1"
(Note: The default value data of the said registry entry is 0.)
HKEY_CURRENT_CONFIG\Software\Microsoft\
windows\CurrentVersion\Internet Settings
ProxyEnable = "1"
(Note: The default value data of the said registry entry is 0.)