W97M_DLOADR.XTRS
November 28, 2014
PLATFORM:
Windows
OVERALL RISK RATING:
DAMAGE POTENTIAL:
DISTRIBUTION POTENTIAL:
REPORTED INFECTION:
INFORMATION EXPOSURE:
Threat Type: Trojan
Destructiveness: No
Encrypted:
In the wild: Yes
OVERVIEW
This Trojan arrives as attachment to mass-mailed email messages.
It executes the downloaded files. As a result, malicious routines of the downloaded files are exhibited on the affected system.
TECHNICAL DETAILS
File Size:
32,256 bytes
File Type:
DOC
Initial Samples Received Date:
20 Nov 2014
Arrival Details
This Trojan arrives as attachment to mass-mailed email messages.
Download Routine
This Trojan saves the files it downloads using the following names:
- %Temp%\444.exe
(Note: %Temp% is the Windows temporary folder, where it usually is C:\Windows\Temp on all Windows operating system versions.)
It then executes the downloaded files. As a result, malicious routines of the downloaded files are exhibited on the affected system.
Other Details
This Trojan connects to the following possibly malicious URL:
- http://{BLOCKED}s.{BLOCKED}ice-hosts.org/updates.exe