TROJ_MONKIF.SMZ
October 08, 2012
PLATFORM:
Windows 2000, XP, Server 2003
OVERALL RISK RATING:
DAMAGE POTENTIAL:
DISTRIBUTION POTENTIAL:
REPORTED INFECTION:
SYSTEM IMPACT RATING:
INFORMATION EXPOSURE:
Threat Type: Trojan
Destructiveness: No
Encrypted: No
In the wild: Yes
OVERVIEW
This Trojan may be dropped by other malware.
It executes downloaded files whose malicious routines are exhibited by the affected system.
TECHNICAL DETAILS
File Size:
22,622 bytes
File Type:
DLL
Memory Resident:
No
Initial Samples Received Date:
16 Jul 2010
Arrival Details
This Trojan may be dropped by the following malware:
- TROJ_MONKIF.SMY
Download Routine
This Trojan accesses the following websites to download files:
- http://media9s.com/photo/{RANDOM}.php?{RANDOM}
- http://media9s.com/d/dl.php?{RANDOM}
It executes downloaded files :
Other Details
Based on analysis of the codes, it has the following capabilities:
- It executes the downloaded file then deletes it.
SOLUTION
Minimum Scan Engine:
8.900
VSAPI OPR PATTERN File:
7.352.06
VSAPI OPR PATTERN Date:
31 Jul 2010
Step 1
Scan your computer with your Trend Micro product and note files detected as TROJ_MONKIF.SMZ
Step 2
Restart in Safe Mode
[ Learn More ]
Did this description help? Tell us how we did.