|
When Julius Caesar arrogantly proclaimed “Veni. Vidi. Vici.” (I came. I saw. I conquered.) to describe his swift and total victory in the Battle of Zela, he must have been sitting atop his horse and looking over his spoils, contemplating the lethal brilliance of his planning. Sitting atop its Trojan spyware, one of this year’s most prevalent file infectors, PE_LOOKED, can lay claim to that same arrogance. To know why, read an in-depth article about PE_LOOKED’s routines and payloads here: PE Came, LOOKED, and Conquered. |
This mother file infector arrives on a system either downloaded from the Internet or dropped by another malware. When executed, it creates the folder, uninstall, in the Windows folder and then drops a copy of itself as, RUNDL132.EXE.
It also drops the file, RICHDLL.DLL, in the Windows folder. This .DLL file is detected by Trend Micro as TROJ_LOOKED.LU.
This mother file infector prepends its code to .EXE files located in drives C: to Z: of the affected system. All infected files are detected by Trend Micro as PE_LOOKED.MA. It then drops the file, _DESKTOP.INI, in every folder that this mother file infector has searched.
Moreover, it waits for active Internet connection and accesses the URL, http://{BLOCKED}90.222.233 to download and execute, on the affected system, files detected by Trend Micro as:
- TSPY_AGENT.FRF
- TSPY_LINEAGE.CEG
- TSPY_LINEAGE.CRQ
- TSPY_LINEAGE.DRX
- TSPY_LINEAGE.DRY
- TSPY_ONLINEGA.AB
- TSPY_QQPASS.AIF
- TSPY_WOWSTEAL.BA