HTML_PHISH.RC

 Analysis by: Jaime Benigno Reyes

 ALIASES:

Mal/Phish-B (Sophos), HTML/Phishing.Gen trojan (Nod32)

 PLATFORM:

Windows 2000, Windows XP, Windows Server 2003

 OVERALL RISK RATING:
 DAMAGE POTENTIAL:
 DISTRIBUTION POTENTIAL:
 REPORTED INFECTION:

  • Threat Type: Trojan

  • Destructiveness: No

  • Encrypted:

  • In the wild: Yes

  OVERVIEW


This Trojan may be hosted on a website and run when a user accesses the said website.

  TECHNICAL DETAILS

File Size:

Varies

File Type:

HTML, HTM

Initial Samples Received Date:

23 Jan 2012

Arrival Details

This Trojan may be hosted on a website and run when a user accesses the said website.

Other Details

This Trojan connects to the following possibly malicious URL:

  • http://fp1.{BLOCKED}il.com/cgi-bin/fm192
  • http://{BLOCKED}.{BLOCKED}.92.51/paypal.php
  • http://{BLOCKED}thewebs.com/wp-content/newauth.php
  • http://{BLOCKED}.{BLOCKED}.118.94/lego.php
  • http://unknow14.{BLOCKED}tee.fr/wayel.php?cmd=_account&access=5885d80a13c0db1f8e263663d3faee8db2b24f7b84f1819390b7e2d9283d70f1
  • http://{BLOCKED}.{BLOCKED}.78.43/online-fraud/confirm.php
  • http://{BLOCKED}.com/pp.php

NOTES:

This Trojan imitates online banking, payment, and credit card update sites.