TROJ_OTORUN.TICOGAU
December 14, 2018
PLATFORM:
Windows
OVERALL RISK RATING:
DAMAGE POTENTIAL:
DISTRIBUTION POTENTIAL:
REPORTED INFECTION:
INFORMATION EXPOSURE:
Threat Type: Trojan
Destructiveness: No
Encrypted:
In the wild: Yes
OVERVIEW
This Trojan arrives on a system as a file dropped by other malware or as a file downloaded unknowingly by users when visiting malicious sites.
TECHNICAL DETAILS
File Size: 45,000 bytes
File Type: INF
Memory Resident: No
Initial Samples Received Date: 05 Apr 2013
Arrival Details
This Trojan arrives on a system as a file dropped by other malware or as a file downloaded unknowingly by users when visiting malicious sites.
Propagation
The said .INF file contains the following strings:
[autorun]
;{garbage}
open=Updates\Drivers\System.exe
;{garbage}
icon=%SystemRoot%\system32\SHELL32.dll,7
;{garbage}
action=Open folder to view files
;{garbage}
shell\open=Open
;{garbage}
shell\open\Command=Updates\Drivers\System.exe
;{garbage}
UseAutoPlay = 1
;{garbage}
shell\explore\Command=Updates\Drivers\System.exe
;{garbage}
Other Details
This Trojan does the following:
- This Trojan automatically executes the following files when a user opens a drive:
- Updates\Drivers\System.exe