JAVA_DLOADR.PHO

 Analysis by: kathleenno

 ALIASES:

Trojan Horse (Symantec); TrojanDownloader:Java/OpenConnection.JP (Microsoft); Trojan-Downloader.Java.OpenConnection.de (Kaspersky);

 PLATFORM:

Windows 2000, Windows XP, Windows Server 2003

 OVERALL RISK RATING:
 DAMAGE POTENTIAL:
 DISTRIBUTION POTENTIAL:
 REPORTED INFECTION:

  • Threat Type: Trojan

  • Destructiveness: No

  • Encrypted: No

  • In the wild: Yes

  OVERVIEW

This malware is a component of a malicious Java archive file (.JAR).

It may connect to remote sites to download possibly malicious files.

  TECHNICAL DETAILS

File Size:

2,006 bytes

File Type:

Java Class

Memory Resident:

Yes

Initial Samples Received Date:

26 Apr 2011

Payload:

Downloads files

NOTES:

This malware is a component of a malicious Java archive file (.JAR).

It may connect to remote sites to download possibly malicious files. It saves the downloaded file as %User Temp%\temp_h71x.exe.