This trojan may be downloaded from a malicious website. It may also arrive as an email attachment.Known email subjects associated with this malware are:
- Really cool photos
- Exclusive photos, you'll be happy
- Spam: Great photos for you
- Great photos for you
- The best photos for you
During installation, the trojan will drop a copy of itself to:
It also sets a launch point with the following registry key:
- HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run rs32net = %systemroot%\system32\rs32net.exe
It will then try to launch svchost.exe, and injects its code by replacing the launched svchost.exe code.
Upon execution, this malware will attempt to connect to the following websites:
It then attempts to download additional files from the following IP addresses:
As of this writing, these IP addresses are down and are not available.