JAVA_BLACOLE.CR


 PLATFORM:

Windows 2000, Windows XP, Windows Server 2003

 OVERALL RISK RATING:
 DAMAGE POTENTIAL:
 DISTRIBUTION POTENTIAL:
 REPORTED INFECTION:

  • Threat Type: Trojan

  • Destructiveness: No

  • Encrypted:

  • In the wild: Yes

  OVERVIEW

This Trojan arrives on a system as a file dropped by other malware or as a file downloaded unknowingly by users when visiting malicious sites. It arrives as a component bundled with malware/grayware packages. It may be hosted on a website and run when a user accesses the said website.

  TECHNICAL DETAILS

File Size:

6,027 bytes

File Type:

Java Class

Initial Samples Received Date:

17 May 2012

Arrival Details

This Trojan arrives on a system as a file dropped by other malware or as a file downloaded unknowingly by users when visiting malicious sites.

It arrives as a component bundled with malware/grayware packages.

It may be hosted on a website and run when a user accesses the said website.

Download Routine

This Trojan saves the files it downloads using the following names:

  • %User Temp%\p{random number}j99p.exe

(Note: %User Temp% is the current user's Temp folder, which is usually C:\Documents and Settings\{user name}\Local Settings\Temp on Windows 2000, XP, and Server 2003.)

NOTES:
This Trojan downloads a possibly malicious file from a certain URL. The URL where this malware downloads the said file depends on the parameter passed on to it by its components.

It executes the downloaded file using the following commands:

  • regsvr32 -s "%User Temp%\p{random number}j99p.exe"
  • %User Temp%\p{random number}j99p.exe