12.01.2016 Views

ASERT-Threat-Intelligence-Brief-Uncovering-the-Seven-Pointed-Dagger

ASERT-Threat-Intelligence-Brief-Uncovering-the-Seven-Pointed-Dagger

ASERT-Threat-Intelligence-Brief-Uncovering-the-Seven-Pointed-Dagger

SHOW MORE
SHOW LESS

Create successful ePaper yourself

Turn your PDF publications into a flip-book with our unique Google optimized e-Paper software.

<strong>ASERT</strong> <strong>Threat</strong> <strong>Intelligence</strong> Report – <strong>Uncovering</strong> <strong>the</strong> <strong>Seven</strong> <strong>Pointed</strong> <strong>Dagger</strong><br />

Figure 12:<br />

SqmApi.dll generates pop-up and initiates network connection<br />

Figure 13:<br />

Execution of SqmApi.dll results in <strong>the</strong> loading and execution of <strong>the</strong> file plgus_res.dll.<br />

Figure 14:<br />

Debugger illuminates <strong>the</strong> use of CreateProcessA to load plgus_res.dll<br />

18 Proprietary and Confidential Information of Arbor Networks, Inc.

Hooray! Your file is uploaded and ready to be published.

Saved successfully!

Ooh no, something went wrong!