18.03.2016 Views

03.2016

gib-buhtrap-report

gib-buhtrap-report

SHOW MORE
SHOW LESS

Create successful ePaper yourself

Turn your PDF publications into a flip-book with our unique Google optimized e-Paper software.

PROVISION OF THE TROJAN SURVIVABILITY<br />

20<br />

STAGES OF THE BUHTRAPWORM DISTRIBUTION<br />

remote control<br />

logins/passwords<br />

Buhtrap<br />

Infected<br />

computer<br />

Uninfected<br />

computer<br />

NO<br />

1<br />

Scans the network<br />

for<br />

\.\mailslot\46CA075C-165CBB2786<br />

YES<br />

Infected<br />

computer<br />

2<br />

Obtains remote control<br />

via public access directory<br />

ADMIN$, IPC$, C$<br />

3<br />

4<br />

Activates the launcher<br />

creates, launches and removes<br />

the service<br />

5<br />

Copies and launches<br />

the main module<br />

with further removal<br />

of the launcher<br />

Infected<br />

computer<br />

GROUP-IB.COM

Hooray! Your file is uploaded and ready to be published.

Saved successfully!

Ooh no, something went wrong!