Analysis by: Sabrina Lei Sioting

 PLATFORM:

Windows 2000, Windows Server 2003, Windows XP (32-bit, 64-bit), Windows Vista (32-bit, 64-bit), Windows 7 (32-bit, 64-bit)

 OVERALL RISK RATING:
 REPORTED INFECTION:
 SYSTEM IMPACT RATING:
 INFORMATION EXPOSURE:

  • Threat Type: Hacking Tool

  • Destructiveness: No

  • Encrypted:

  • In the wild: Yes

  OVERVIEW

This hacking tool arrives on a system as a file dropped by other malware or as a file downloaded unknowingly by users when visiting malicious sites.

  TECHNICAL DETAILS

Tamaño del archivo 592,832 bytes
Tipo de archivo EXE
Fecha de recepción de las muestras iniciales 09 Jan 2013

Arrival Details

This hacking tool arrives on a system as a file dropped by other malware or as a file downloaded unknowingly by users when visiting malicious sites.

Installation

This hacking tool drops the following files:

  • %Program Files%\FK_Monitor\freeklogger.exe
  • %Program Files%\FK_Monitor\how_works.htm
  • %Program Files%\FK_Monitor\tray.png
  • %Program Data%\Microsoft\Windows\Start Menu\Programs\Free_Key_logger\Free_Key_logger.lnk
  • %System Root%\Users\All Users\Microsoft\Windows\Start Menu\Programs\Free_Key_logger\Free_Key_logger.lnk

(Note: %Program Files% is the default Program Files folder, usually C:\Program Files in Windows 2000, Server 2003, and XP (32-bit), Vista (32-bit), and 7 (32-bit), or C:\Program Files (x86) in Windows XP (64-bit), Vista (64-bit), and 7 (64-bit).. %System Root% is the root folder, which is usually C:\. It is also where the operating system is located.)

It creates the following folders:

  • %Program Files%\FK_Monitor
  • %Program Data%\Microsoft\Windows\Start Menu\Programs\Free_Key_logger
  • %System Root%\Users\All Users\Microsoft\Windows\Start Menu\Programs\Free_Key_logger

(Note: %Program Files% is the default Program Files folder, usually C:\Program Files in Windows 2000, Server 2003, and XP (32-bit), Vista (32-bit), and 7 (32-bit), or C:\Program Files (x86) in Windows XP (64-bit), Vista (64-bit), and 7 (64-bit).. %System Root% is the root folder, which is usually C:\. It is also where the operating system is located.)