Home Malware Programs Backdoors Backdoor.APT.Merong

Backdoor.APT.Merong

Posted: March 19, 2013

Threat Metric

Threat Level: 2/10
Infected PCs: 55
First Seen: March 19, 2013
OS(es) Affected: Windows

Backdoor.APT.Merong is a backdoor Trojan that is included in a malware attack, which affects companies. The malware campaign that is used by cybercriminals to distribute Backdoor.APT.Merong uses the name of the company it aims at in the CnC URL name. Backdoor.APT.Merong regularly uses either names of companies or a project that a particular company works on in its CnC URL name in order not to appear suspicious. Backdoor.APT.Merong propagates via malicious emails carrying harmful web addresses. The zip file encompasses 'Updated_office_contact_v1.exe', which when run creates 'ctfmon.exe' and 'Lanl_Office_Contact_oct.pdf' in the '%UserProfile%\Local Settings\Temp' directory. It then opens a decoy PDF document for instance, 'Lanl_Office_Contact_oct.pdf' from the Temp directory and then executes 'ctfmon.exe'. 'Lanl_office_contact_oct.pdf' belongs to 'Los Alamos National Lab' and the contacts can also be found in the PDF file on the website. 'ctfmon.exe' creates a copy of itself into the '%UserProfile%\Start Menu\Programs\Startup\ctfmon.exe' directory to load whenever the corrupted PC is switched on and starts to talk to the CnC server.

Technical Details

File System Modifications

Tutorials: If you wish to learn how to remove malware components manually, you can read the tutorials on how to find malware, kill unwanted processes, remove malicious DLLs and delete other harmful files. Always be sure to back up your PC before making any changes.

The following files were created in the system:



hxxp://americansystems.ddns.info/corporate/office/Updated_office_contact_v1.zip File name: hxxp://americansystems.ddns.info/corporate/office/Updated_office_contact_v1.zip
Mime Type: unknown/zip
Group: Malware file
hxxp://americansystems.ddns.info/corporate/office/Updated_office_contact_v2.zip File name: hxxp://americansystems.ddns.info/corporate/office/Updated_office_contact_v2.zip
Mime Type: unknown/zip
Group: Malware file
hxxp://americansystems.ddns.info/corporate/office/Updated_office_contact_v3.zip File name: hxxp://americansystems.ddns.info/corporate/office/Updated_office_contact_v3.zip
Mime Type: unknown/zip
Group: Malware file
hxxp://americansystems.ddns.info/corporate/office/Updated_office_contact_v4.zip File name: hxxp://americansystems.ddns.info/corporate/office/Updated_office_contact_v4.zip
Mime Type: unknown/zip
Group: Malware file
hxxp://americansystems.ddns.info/corporate/office/Updated_office_contact_v5.zip File name: hxxp://americansystems.ddns.info/corporate/office/Updated_office_contact_v5.zip
Mime Type: unknown/zip
Group: Malware file
hxxp://americansystems.ddns.info/corporate/office/Updated_office_contact_v6.zip File name: hxxp://americansystems.ddns.info/corporate/office/Updated_office_contact_v6.zip
Mime Type: unknown/zip
Group: Malware file
Updated_office_contact_v1.exe File name: Updated_office_contact_v1.exe
File type: Executable File
Mime Type: unknown/exe
Group: Malware file
Lanl_Office_Contact_oct.pdf File name: Lanl_Office_Contact_oct.pdf
Mime Type: unknown/pdf
Group: Malware file
ctfmon.exe File name: ctfmon.exe
File type: Executable File
Mime Type: unknown/exe
Group: Malware file
Loading...