Analysis by: Jennifer Gumban

ALIASES:

Trojan:Win32/Trafog!rts (Microsoft), Backdoor.Win32.WinterLove.cu (Kaspersky), Artemis!0096A4F77480 (McAfee)

 PLATFORM:

Windows 2000, Windows Server 2003, Windows XP (32-bit, 64-bit), Windows Vista (32-bit, 64-bit), Windows 7 (32-bit, 64-bit)

 OVERALL RISK RATING:
 DAMAGE POTENTIAL:
 DISTRIBUTION POTENTIAL:
 REPORTED INFECTION:

  • Threat Type: Backdoor

  • Destructiveness: No

  • Encrypted:

  • In the wild: Yes

  OVERVIEW

This backdoor may arrive bundled with malware packages as a malware component. It arrives on a system as a file dropped by other malware or as a file downloaded unknowingly by users when visiting malicious sites.

It is a component of other malware.

  TECHNICAL DETAILS

Tamaño del archivo 651,264 bytes
Tipo de archivo EXE
Fecha de recepción de las muestras iniciales 20 Jul 2009

Arrival Details

This backdoor may arrive bundled with malware packages as a malware component.

It arrives on a system as a file dropped by other malware or as a file downloaded unknowingly by users when visiting malicious sites.

Installation

This backdoor is a component of other malware.

Other System Modifications

This backdoor adds the following registry entries as part of its installation routine:

HKEY_LOCAL_MACHINE\SOFTWARE\Softfy\
{Subkey}
{Random Name} = {Random Data}

Other Details

This backdoor connects to the following possibly malicious URL:

  • http://www.{BLOCKED}hi.com/Update/SoftUpdate.asp?action=exesoft
  • http://www.{BLOCKED}hi.com/band9/SoftUpdate.asp?action=exesoft
  • http://www.{BLOCKED}hi.com/band8/SoftUpdate.asp?action=exesoft
  • http://www.{BLOCKED}hi.com/band7/SoftUpdate.asp?action=exesoft
  • http://www.{BLOCKED}hi.com/band6/SoftUpdate.asp?action=exesoft
  • http://www.{BLOCKED}hi.com/band5/SoftUpdate.asp?action=exesoft
  • http://www.{BLOCKED}k.cn/Ads2.htm
  • http://www.{BLOCKED}y.com/Ads2.htm
  • http://www.{BLOCKED}k.cn/Ads1.htm
  • http://www.{BLOCKED}y.com/Ads1.htm
  • http://www.{BLOCKED}k.cn/Ads0.htm
  • http://www.{BLOCKED}y.com/Ads0.htm
  • http://www.{BLOCKED}hi.com/Ads8.htm
  • http://www.{BLOCKED}i.com/Ads7.htm
  • http://www.{BLOCKED}hi.com/Ads6.htm
  • http://www.{BLOCKED}hi.com/Ads5.htm
  • http://www.{BLOCKED}hi.com/Ads4.htm

NOTES:
Where Subkey can be any of the following: Common, Woyaozhi, Cnunion, Baidu, Band, PopUp.