Virus Characteristics
----------Updated on June 1st, 2012---------------------------------
Aliases
- Kaspersky - HEUR:Trojan.Win32.Generic
- BitDefender- Gen:Variant.Zusy.7412
- Ikarus - Trojan.Win32.Medfos
- Microsoft - Trojan:Win32/Medfos.A
Upon execution, the Trojan connects to the site "11ikaod.cd[Removed]lp.com" through remote port 80 to download other malicious files.
The following registry value has been added.
- HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Run\astfac = "rundll32.exe"C:\DOCUME~1\User\LOCALS~1\Temp\astfac.dll
Above mentioned registry ensures that, the Trojan registers itself with the compromised system and execute itself upon every boot.
The following file has been added to the system.
After execution, the Trojan deletes itself from the compromised system.
-------------------------------------------------------------------------------------------------
Medfos.b is detection for this Trojan that downloads other malicious files from malicious sites.
Upon execution the Trojan tries to connect the following sites:
- d3lvr7[Removed]nt.net
- 2.17.[Removed].239
- 184.50.[Removed].239
When executed it may copies itself into the following location in random names:
Communicates with a remote host
Medfos.b connects to various remote servers using HTTP protocol (port 80) and attempts to download the arbitrary files. The Trojan was observed to contact domains with the following suffixes:
- [Removed].com
- [Removed.com
- [Removed].net