
Research: Trend Micro
There are two packages
one is 'found in the wild' full and a set of hashes from Trend Micro (all but one file are already in the full package)
- 1st Full Plugin and its export function is called Plug. Full plugins run continuously until the infected system is restarted
- 2nd Light Plugin with an export function Scan. Light plugins terminate immediately after returning a buffer with the information they harvested off the victim’s machine.
- Strong encryption. The data sent is encapsulated using the XML-RPC protocol.
- MethodName value 10a7d030-1a61-11e3-beea-001c42e2a08b is always present in Potao traffic.
- After receiving the request the C&C server generates an RSA-2048 public key and signs this generated key with another, static RSA-2048 private key .
- In 2nd stage the malware generates a symmetric AES-256 key. This AES session key is encrypted with the newly received RSA-2048 public key and sent to the C&C server.
- The actual data exchange after the key exchange is then encrypted using symmetric cryptography, which is faster, with the AES-256 key
- The Potao malware sends an encrypted request to the server with computer ID, campaign ID, OS version, version of malware, computer name, current privileges, OS architecture (64 or 32bits) and also the name of the current process.
![]() |
File Name | MD5 | Size |
---|---|---|
_SD_IP_CF.dll_03718676311DE33DD0B8F4F18CFFD488 | 03718676311de33dd0b8f4f18cffd488 | 368 KB |
Disk from Houston_6FE6C03B938580EBF9B82F3B9CD4C4AA | 6fe6c03b938580ebf9b82f3b9cd4c4aa | 61 KB |
DoubleFantasy_2A12630FF976BA0994143CA93FECD17F | 2a12630ff976ba0994143ca93fecd17f | 216 KB |
EquationDrug_4556CE5EB007AF1DE5BD3B457F0B216D | 4556ce5eb007af1de5bd3b457f0b216d | 372 KB |
EquationLaser_752AF597E6D9FD70396ACCC0B9013DBE | 752af597e6d9fd70396accc0b9013dbe | 130 KB |
Fanny_0A209AC0DE4AC033F31D6BA9191A8F7A | 0a209ac0de4ac033f31d6ba9191a8f7a | 180 KB |
GrayFish_9B1CA66AAB784DC5F1DFE635D8F8A904 | 9b1ca66aab784dc5f1dfe635d8f8a904 | 560 KB |
GROK_24A6EC8EBF9C0867ED1C097F4A653B8D | 24a6ec8ebf9c0867ed1c097f4a653b8d | 160 KB |
nls_933w.dll_11FB08B9126CDB4668B3F5135CF7A6C5 | 11fb08b9126cdb4668b3f5135cf7a6c5 | 208 KB |
TripleFantasy_9180D5AFFE1E5DF0717D7385E7F54386 | 9180d5affe1e5df0717d7385e7f54386 | 18 KB |
TripleFantasy_BA39212C5B58B97BFC9F5BC431170827 | ba39212c5b58b97bfc9f5bc431170827 | 199 KB |