Once running on the victim machine, the Trojan serves multiple functions:
When it is run, the remote access trojan installs itself into %SysDir% (eg. C:\WINNT\SYSTEM32) with a random 8 character filename. A DLL is also dropped into this directory, again with a seemingly random 8 character filename. For example:
C:\WINNT\SYSTEM32\OQLCINEI.EXE (39,140 bytes - copy of Trojan)
Notification is sent to the hacker via HTTP, sending data to a remote PHP script. This data includes IP of machine, plus port numbers opened. It also includes as "identification string" - presumably used to validate communication to the Trojan.
More information can be found at this McAfee page.
Loading Comments...