INF_BLACKEN.A
Windows

Threat Type: Trojan
Destructiveness: No
Encrypted: No
In the wild: Yes
OVERVIEW
Downloaded from the Internet
This malware is downloaded by the zero-day exploit leveraging the vulnerability covered under CVE-2014-4114, also known as "Sandworm."
To get a one-glance comprehensive view of the behavior of this Trojan, refer to the Threat Diagram shown below.

This Trojan may be downloaded from remote sites by other malware.
It is used to load and execute a file.
TECHNICAL DETAILS
446 bytes
INF
14 Oct 2014
Executes files
Arrival Details
This Trojan may be downloaded from remote site(s) by the following malware:
Other System Modifications
This Trojan modifies the following file(s):
- renames slide1.gif to slide1.gif.exe - detected as BKDR_BLACKEN.A
It adds the following registry entries as part of its installation routine:
HKEY_LOCAL_MACHINE\Microsoft\Windows\
CurrentVersion\RunOnce
Install = "{malware path}\slide1.gif.exe"
Other Details
This Trojan is used to load and execute the following file:
- {malware path}\slide1.gif.exe - detected as BKDR_BLACKEN.A
SOLUTION
9.700
11.210.05
14 Oct 2014
11.211.00
15 Oct 2014
Step 1
Before doing any scans, Windows 7, Windows 8, Windows 8.1, and Windows 10 users must to allow full scanning of their computers.
Step 2
Remove the malware/grayware file that dropped/downloaded INF_BLACKEN.A. (Note: Please skip this step if the threat(s) listed below have already been removed.)