Home Malware Programs Trojans Trojan.APT.LetsGo

Trojan.APT.LetsGo

Posted: March 19, 2013

Threat Metric

Threat Level: 9/10
Infected PCs: 28
First Seen: March 19, 2013
Last Seen: September 4, 2022
OS(es) Affected: Windows

Trojan.APT.LetsGo is a Trojan that is a component of a malware campaign, which targets companies. The malware attack that is used by attackers to spread Trojan.APT.LetsGo uses the name of the company it affects in the CnC domain name. Trojan.APT.LetsGo constantly uses either names of companies or a project that a certain company is working on in its CnC domain name in order not to raise any suspicion. Trojan.APT.LetsGo spreads via infected emails including malicious URLs. The .zip file includes 'Updated_office_contact_v1.exe', which once executed creates 'ctfmon.exe' and 'Lanl_Office_Contact_oct.pdf' in the '%UserProfile%\Local Settings\Temp' directory. It then opens a decoy PDF document for example, 'Lanl_Office_Contact_oct.pdf' from the Temp directory and then runs 'ctfmon.exe'. 'Lanl_office_contact_oct.pdf' belongs to 'Los Alamos National Lab' and in the PDF file the contacts on their website can be found as well. 'ctfmon.exe' replicates itself into the '%UserProfile%\Start Menu\Programs\Startup\ctfmon.exe' directory to run every time the affected computer is on turned on and starts talking to the CnC server.

Technical Details

File System Modifications

Tutorials: If you wish to learn how to remove malware components manually, you can read the tutorials on how to find malware, kill unwanted processes, remove malicious DLLs and delete other harmful files. Always be sure to back up your PC before making any changes.

The following files were created in the system:



hxxp://americansystems.ddns.info/corporate/office/Updated_office_contact_v1.zip File name: hxxp://americansystems.ddns.info/corporate/office/Updated_office_contact_v1.zip
Mime Type: unknown/zip
Group: Malware file
hxxp://americansystems.ddns.info/corporate/office/Updated_office_contact_v2.zip File name: hxxp://americansystems.ddns.info/corporate/office/Updated_office_contact_v2.zip
Mime Type: unknown/zip
Group: Malware file
hxxp://americansystems.ddns.info/corporate/office/Updated_office_contact_v3.zip File name: hxxp://americansystems.ddns.info/corporate/office/Updated_office_contact_v3.zip
Mime Type: unknown/zip
Group: Malware file
hxxp://americansystems.ddns.info/corporate/office/Updated_office_contact_v4.zip File name: hxxp://americansystems.ddns.info/corporate/office/Updated_office_contact_v4.zip
Mime Type: unknown/zip
Group: Malware file
hxxp://americansystems.ddns.info/corporate/office/Updated_office_contact_v5.zip File name: hxxp://americansystems.ddns.info/corporate/office/Updated_office_contact_v5.zip
Mime Type: unknown/zip
Group: Malware file
hxxp://americansystems.ddns.info/corporate/office/Updated_office_contact_v6.zip File name: hxxp://americansystems.ddns.info/corporate/office/Updated_office_contact_v6.zip
Mime Type: unknown/zip
Group: Malware file
Updated_office_contact_v1.exe File name: Updated_office_contact_v1.exe
File type: Executable File
Mime Type: unknown/exe
Group: Malware file
Lanl_Office_Contact_oct.pdf File name: Lanl_Office_Contact_oct.pdf
Mime Type: unknown/pdf
Group: Malware file
ctfmon.exe File name: ctfmon.exe
File type: Executable File
Mime Type: unknown/exe
Group: Malware file
Loading...