Threat behavior
Backdoor:Win32/Protux.A!dll is a trojan backdoor that allows remote access and control.
Installation
Backdoor:Win32/Protux.A!dll is installed by TrojanDropper:Win32/Protux.A and may be present as the following:
<system folder>\workstation.dll
Note: the Windows system file by the same name may have been replaced or is renamed as "workstation.dl_" by the trojan dropper. The registry may be modified to execute the backdoor at each Windows start.
Modifies value: "ServiceDll"
With data: "<system folder>\workstation.dll"
To subkey: HKLM\SYSTEM\CurrentControlSet\Services\lanmanworkstation\parameters
Adds value: "WORKST~1"
With data: “rundll32.exe <system folder>\workstation.dll”, TStartUp WORKST~1 0”
To subkey: HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Run
Adds value: "WORKST~1"
With data: "rundll32.exe “<system folder>\WORKST~1.DLL”, TStartUp WORKST~1 0 WORKST~1 1”
To subkey: HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\Run
The trojan command and control is triggered when network operations are performed between workstations and servers in the network.
Payload
Allows remote access and control
The backdoor is capable of the following actions:
- obtain machine system information of the infected client
- download and execute other malware
- record user name, passwords, and other sensitive system information and send collected data to a remote attacker
- function as a trojan proxy server
In the wild, this backdoor trojan was observed downloading and executing malware executables from the website “sweetbug.selfip.net”.
Analysis by Rodel Finones
Prevention