TrojanSpy.Win32.LOKI.TIOIBYPJ
Backdoor.Win32.Androm.tkwf (Kaspersky)
Windows
Threat Type: Trojan Spy
Destructiveness: No
Encrypted:
In the wild: Yes
OVERVIEW
This Trojan Spy arrives on a system as a file dropped by other malware or as a file downloaded unknowingly by users when visiting malicious sites.
TECHNICAL DETAILS
Arrival Details
This Trojan Spy arrives on a system as a file dropped by other malware or as a file downloaded unknowingly by users when visiting malicious sites.
Installation
This Trojan Spy adds the following processes:
- %Application Data%\Ilyhtv.exe
(Note: %Application Data% is the current user's Application Data folder, which is usually C:\Documents and Settings\{user name}\Application Data on Windows 2000(32-bit), XP, and Server 2003(32-bit), or C:\Users\{user name}\AppData\Roaming on Windows Vista, 7, 8, 8.1, 2008(64-bit), 2012(64-bit) and 10(64-bit).)
Autostart Technique
This Trojan Spy adds the following registry entries to enable its automatic execution at every system startup:
HKEY_CURRENT_USER\Software\Microsoft\
Windows\CurrentVersion\Run
Ily = "%AppDataLocal%\Ily\Ilyos.vbs"
Dropping Routine
This Trojan Spy drops the following files:
- %Application Data%\737FF7\73A3E3.exe
- %User Profile%\Music\Ilywek.exe
- %Application Data%\Ily.bmp
- %Application Data%\Ily.ocx
- %Application Data%\737FF7\73A3E3.lck
- %User Profile%\Music\Ily.bmp
- %AppDataLocal%\Ily\Ilyna.bat
- %Application Data%\Ilyhtv.exe
- %AppDataLocal%\Ily\Ilyos.vbs
(Note: %Application Data% is the current user's Application Data folder, which is usually C:\Documents and Settings\{user name}\Application Data on Windows 2000(32-bit), XP, and Server 2003(32-bit), or C:\Users\{user name}\AppData\Roaming on Windows Vista, 7, 8, 8.1, 2008(64-bit), 2012(64-bit) and 10(64-bit).. %User Profile% is the current user's profile folder, which is usually C:\Documents and Settings\{user name} on Windows 2000(32-bit), XP, and Server 2003(32-bit), or C:\Users\{user name} on Windows Vista, 7, 8, 8.1, 2008(64-bit), 2012(64-bit) and 10(64-bit).. %AppDataLocal% is the Local Application Data folder, which is usually C:\Documents and Settings\{user name}\Local Settings\Application Data on Windows 2000(32-bit), XP, and Server 2003(32-bit), or C:\Users\{user name}\AppData\Local on Windows Vista, 7, 8, 8.1, 2008(64-bit), 2012(64-bit) and 10(64-bit).)
Other Details
This Trojan Spy connects to the following possibly malicious URL:
- http://{BLOCKED}nams.com/nweke/fre.php