JAVA_BANLOAD.TNA
Java/TrojanDownloader.Banload.AA (ESET), RDN/PWS-Banker!co (McAfee), Trojan-Spy.Win32.Banker.ct (Kaspersky)
Windows
Threat Type: Trojan
Destructiveness: No
Encrypted:
In the wild: Yes
OVERVIEW
This Trojan arrives on a system as a file dropped by other malware or as a file downloaded unknowingly by users when visiting malicious sites. It may be hosted on a website and run when a user accesses the said website.
TECHNICAL DETAILS
4,416 bytes
JAR
16 Sep 2014
Arrival Details
This Trojan arrives on a system as a file dropped by other malware or as a file downloaded unknowingly by users when visiting malicious sites.
It may be hosted on a website and run when a user accesses the said website.
Installation
This Trojan drops the following copies of itself into the affected system and executes them:
- C:/Winn/pdf.exe
Other Details
This Trojan connects to the following possibly malicious URL:
- http://{BLOCKED}dinis.qlix.com.br/images/Imagengif00987.jpg