TROJ_UNRUY.SMP2
October 11, 2014
ALIASES:
TrojanDownloader:Win32/Unruy.Q (Microsoft), Win32/Kryptik.AJLF (ESET)
PLATFORM:
Windows
OVERALL RISK RATING:
DAMAGE POTENTIAL:
DISTRIBUTION POTENTIAL:
REPORTED INFECTION:
INFORMATION EXPOSURE:
Threat Type: Trojan
Destructiveness: No
Encrypted:
In the wild: Yes
OVERVIEW
This Trojan arrives on a system as a file dropped by other malware or as a file downloaded unknowingly by users when visiting malicious sites.
TECHNICAL DETAILS
File Size: Varies
File Type: EXE
Initial Samples Received Date: 31 Oct 2011
Arrival Details
This Trojan arrives on a system as a file dropped by other malware or as a file downloaded unknowingly by users when visiting malicious sites.
Installation
This Trojan drops the following copies of itself into the affected system:
- {Any folder}\{user's filename}.exe
Other Details
This Trojan connects to the following possibly malicious URL:
- {BLOCKED}s.{BLOCKED}3-domain.com
It does the following:
- It renames the user's executable files and sets the attribute of the original executable files as hidden:
- {user's filename}.exe to {user's filename}
such as C:\Program Files\7-Zip\7z.exe to 7z (with attribute hidden)
- {user's filename}.exe to {user's filename}
- It then drops copies of itself using the filename of the user's executable files