Win32/Turla [Threat Name] go to Threat

Win32/Turla.CE [Threat Variant Name]

Category trojan
Size 110592 B
Aliases Trojan.ADH.SMH (Symantec)
Short description

Win32/Turla.CE serves as a backdoor. It can be controlled remotely.


The trojan does not create any copies of itself.

In order to be executed on every system start, the trojan sets the following Registry entry:

  • [HKEY_CURRENT_USER\­SOFTWARE\­Microsoft\­Windows NT\­CurrentVersion\­Winlogon]
    • "Shell" = "explorer.exe, %malwarefilepath%"
Information stealing

The trojan collects the following information:

  • manufacturer of the product/hardware
  • CPU information
  • memory status
  • information about the operating system and system settings
  • computer name
  • user name
  • language settings
  • list of disk devices and their type
  • list of shared folders
  • list of active TCP and UDP connections
  • installed Microsoft Windows patches
  • list of running processes
  • the path to specific folders
  • list of files/folders on a specific drive

The trojan attempts to send gathered information to a remote machine.

Other information

The trojan creates and runs a new thread with its own program code within the following processes:

  • explorer.exe
  • iexplore.exe
  • firefox.exe
  • chrome.exe
  • opera.exe
  • msimn.exe
  • icq.exe
  • icqlite.exe
  • adobeupdater.exe

The trojan sleeps for certain period of time if it detects a running process containing one of the following strings in its name:

  • tcpdump.exe
  • windump.exe
  • ethereal.exe
  • wireshark.exe
  • ettercap.exe
  • snoop.exe
  • dsniff.exe

The trojan acquires data and commands from a remote computer or the Internet.

The trojan contains a list of (2) URLs. The HTTP protocol is used in the communication.

The network communication with remote computer/server is encrypted.

It can execute the following operations:

  • download files from a remote computer and/or the Internet
  • run executable files
  • upload files to a remote computer

The trojan may create the following files:

  • %temp%\­~D%variable%
  • %temp%\­winwtf.bat

A string with variable content is used instead of %variable% .

Please enable Javascript to ensure correct displaying of this content and refresh this page.