Home Malware Programs Backdoors BKDR_RARSTONE.A

BKDR_RARSTONE.A

Posted: February 28, 2013

Threat Metric

Threat Level: 6/10
Infected PCs: 33
First Seen: February 28, 2013
OS(es) Affected: Windows

BKDR_RARSTONE.A is a backdoor Trojan that is similar to PlugX, a type of Remote Access Trojan (RAT) used in certain high-profile APT attacks. PlugX is able to disguise its malicious codes by decrypting and loading a backdoor 'executable file' directly into memory, without the need to download the actual 'executable file'. BKDR_RARSTONE.A spreads via a spam phishing email that includes a specially-crafted .DOC file, detected as TROJ_ARTIEF.NTZ. BKDR_RARSTONE.A is dropped and executed by TROJ_ARTIEF.NTZ on the corrupted PC. When installed, BKDR_RARSTONE.A downloads and executes the potentially malicious files such as 'ymsgr_tray.exe'. BKDR_RARSTONE.A then opens a hidden Internet Explorer process, in which it inserts the codes included in the 'profile.dat'. As with PlugX, the inserted code decrypts itself in memory. Once decrypted BKDR_RARSTONE.A supposedly downloads a .DLL file from its C&C server and again loads it in the memory space of the hidden Internet Explorer process. This supposedly downloaded file is, in actuality, not downloaded onto the computer system, but instead directly loaded in memory, making file-based detection ineffective.

Technical Details

File System Modifications

Tutorials: If you wish to learn how to remove malware components manually, you can read the tutorials on how to find malware, kill unwanted processes, remove malicious DLLs and delete other harmful files. Always be sure to back up your PC before making any changes.

The following files were created in the system:



iExplorer.exe1 File name: iExplorer.exe1
Size: 51.2 KB (51200 bytes)
MD5: ebb28877ab3edc32ff3c9c3e1a2382f1
Detection count: 14
Mime Type: unknown/exe1
Group: Malware file
Last Updated: March 5, 2013
%System%\ymsgr_tray.exe File name: %System%\ymsgr_tray.exe
Mime Type: unknown/exe
Group: Malware file
%Application Data%\profile.dat File name: %Application Data%\profile.dat
File type: Data file
Mime Type: unknown/dat
Group: Malware file
Loading...