Additional DetailsInstallation to the System
When run, Bifrose.SN copies itself under %SysDir% directory using the name winampxp.exe. It installs the following registry key to make sure it will be executed next time the system is started:
"startkey" = "winampxp.exe"
After the installation, Bifrose.SN tries to locate a web browser and inject code into it. The injected code is the actual backdoor. The backdoor starts to communicate with the following servers using a specially crafted HTTP queries:
The servers can instruct the backdoor to execute the following actions:
- Basic file operations (copy, delete, rename, find, execute)
- Download/upload files
- Process operations (list, kill)
- Registry operations (create/delete keys/values)
- Create screenshots of the desktop
F-Secure Anti-Virus detects this malware with the following updates:
Version = 2006-06-07_01.