ALIASES:

Trojan.Bebloh (Symantec)

 PLATFORM:

Windows

 OVERALL RISK RATING:
 DAMAGE POTENTIAL:
 DISTRIBUTION POTENTIAL:
 REPORTED INFECTION:
 INFORMATION EXPOSURE:

  • Threat Type: Trojan

  • Destructiveness: No

  • Encrypted:

  • In the wild: Yes

  OVERVIEW

This Trojan arrives on a system as a file dropped by other malware or as a file downloaded unknowingly by users when visiting malicious sites.

It deletes itself after execution.

  TECHNICAL DETAILS

File Size: 221,184 bytes
File Type: EXE
Initial Samples Received Date: 07 Oct 2014

Arrival Details

This Trojan arrives on a system as a file dropped by other malware or as a file downloaded unknowingly by users when visiting malicious sites.

Installation

This Trojan drops the following copies of itself into the affected system:

  • %System%\{variable1}{variable2}.exe
    where {variable1} can be any of the following:
    • def
    • mem
    • dns
    • video
    • win

    where{variable2} can be any of the following:
    • exec
    • hlp
    • logon
    • mixer
    • mon
    • pack
    • play
    • setup
    • srv
    • user

(Note: %System% is the Windows system folder, where it usually is C:\Windows\System32 on all Windows operating system versions.)

It adds the following processes:

  • explorer.exe

Autostart Technique

This Trojan adds the following registry entries to enable its automatic execution at every system startup:

HKEY_CURRENT_USER\Software\Microsoft\
Windows\CurrentVersion\Run
{variable1}{variable2} = "%System%\{variable1}{variable2}.exe"

Other Details

This Trojan deletes itself after execution.