W32.Craq

By GoldSparrow in Worms

Threat Scorecard

Ranking: 5,036
Threat Level: 10 % (Normal)
Infected Computers: 531
First Seen: April 4, 2014
Last Seen: September 20, 2023
OS(es) Affected: Windows

W32.Craq is a worm that proliferates through removable drives using the potentially infected files. W32.Craq may open a back door and steal information on the compromised PC. Upon execution, W32.Craq creates the potentially infected files. W32.Craq then creates the registry entries. W32.Craq looks for executable files in the %ProgramFiles% and %UserProfile%/Application Data/ directories and the subfolders within the specific directories. W32.Craq then replicates itself using the file name of the executable files that it finds under the particular format. W32.Craq then connects to one of several distant locations. W32.Craq may carry out the potentially harmful activities on the attacked PC such as show PNG files, log keystrokes, capture screenshots, undertake FTP operations, send emails, search for keywords in files, collect clipboard content and information on open windows, close windows and kill processes and reboot the computer.

File System Details

W32.Craq may create the following file(s):
# File Name Detections
1. %Windir%\Tasks\At[ONE NUMBER].job
2. %Windir%\winlogz.log
3. %Temp%\updatems.exe
4. %Windir%\w1sv32[ONE RANDOM LOWERCASE LETTER FROM 'e' TO 'n'].dll
5. %System%\w1sv32[ONE RANDOM LOWERCASE LETTER FROM 'e' TO 'n'].dll
6. %UserProfile%\Local Settings\Temp\w1sv32[ONE RANDOM LOWERCASE LETTER FROM 'e' TO 'n'].dll
7. %Temp%\w1sv32[ONE RANDOM LOWERCASE LETTER FROM 'e' TO 'n'].dll
8. %UserProfile%\Application Data\skype\update.exe
9. %UserProfile%\Application Data\google\update.exe
10. %UserProfile%\Application Data\java\update.exe
11. %UserProfile%\Application Data\quicktime\Qtupdate.exe
12. %UserProfile%\Application Data\yahoo\YahooUpdate.exe
13. %UserProfile%\Application Data\Internet Explorer\iexplorer.exe
14. %UserProfile%\Application Data\Internet Explorer\ieinstaller.exe
15. %UserProfile%\Application Data\chrome\update.exe
16. %UserProfile%\Application Data\firefox\update.exe
17. %ProgramFiles%\skype\update.exe
18. %ProgramFiles%\google\update.exe
19. %ProgramFiles%\java\update.exe
20. %ProgramFiles%\yahoo\YahooUpdate.exe
21. %ProgramFiles%\quicktime\Qtupdate.exe
22. %ProgramFiles%\Internet Explorer\iexplorer.exe
23. %ProgramFiles%\Internet Explorer\ieinstaller.exe
24. %ProgramFiles%\chrome\update.exe
25. %ProgramFiles%\firefox\update.exe
26. %DriveLetter%\recycler\files.ico
27. %DriveLetter%\recycler\Setup.exe
28. %DriveLetter%\Autorun.inf

Registry Details

W32.Craq may create the following registry entry or registry entries:
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Policies\System\"ConsentPromptBehaviorAdmin" = "0"
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Policies\System\"EnableLUA" = "0"

URLs

W32.Craq may call the following URLs:

Maria.00freehost.com/configpub
Nadamohammed.tripod.com/configpub
Squirk0.tripod.com/configpub
fileconvertertab.com

Trending

Most Viewed

Loading...