Skip to main content

Trojan:W32/Recslurp

Classification

Category:

Malware

Type:

Trojan

Aliases:

  • Trojan:W32/Recslurp

Summary

Trojan:W32/Recslurp silently contacts remote servers and attempts to download additional files onto the infected machine.

Removal

Technical Details

Trojan:W32/Recslurp is distributed via spam email messages. The messages may contain either a link that leads to a downloadable executable file, or a zipped file attachment containing the malware, such as below:

Spam email messages distributing Trojan:W32/Recslurp

If the downloaded file or file attachment is opened on the machine, the malware runs and attempts to either overwrite the following system files with a copy of itself:

  • %systemroot%\csrss.exe
  • %systemroot%\svchost.exe
  • %systemroot%\rundll32.exe

Or drop a copy of itself at the following locations, with hidden and system file attributes:

  • %userprofile%\%appdata%\csrss.exe
  • %userprofile%\%appdata%\svchost.exe
  • %userprofile%\%appdata%\rundll32.exe

Next, Recslurp creates the following registry keys so that the copy automatically runs at each system startup:

  • HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Run Client Server Runtime Process <%userprofile%\%appdata% or %systemroot%>\csrss.exe
  • HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Run Service Host Process for Windows <%userprofile%\%appdata% or %systemroot%>\svchost.exe
  • HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Run Host-process Windows (Rundll32.exe) <%userprofile%\%appdata% or %systemroot%>\rundll32.exe

Once installed and running, Recslurp attempts to connect to the following hosts:

  • smtp.gmail.com
  • plust.smtp.mail.yahoo.com

It also contacts remote servers at the following IP addresses in order to download and execute additional files:

  • 61.250.[removed].132:9997 - Korea
  • 41.[removed].138.246:9631 - Uganda
  • 185.[removed].56.84:9997 - Netherlands
  • 5.27.[removed].82:9997 - Turkey
  • 186.[removed].131.131:9631 - Colombia
  • 197.[removed].152.225:9631 - Algeria

Protect your devices from malware with F‑Secure Total

Protecting your devices from malicious software is essential for maintaining online security. F‑Secure Total makes this easy, helping you to secure your devices in a brilliantly simple way.

  • Award‑winning antivirus and malware protection

  • Online browsing, banking, and shopping protection

  • 24/7 online identity and data breach monitoring

  • Unlimited VPN service to safe­guard your privacy

  • Password manager with private data protection

Choose how many devices you want to protect to get started.

  • Free customer support

  • Cancel anytime

  • The trial does not obligate you to buy the product

After 30 days your subscription will renew automatically for one year at €69.99.

More Support

Community

Ask questions in our Community.

User guides

Check the user guide for instructions.

Contact Support

Chat with with or call an agent.

Submit a Sample

Submit a file or URL for analysis.