TROJ64_DIANTI.A
May 29, 2015
PLATFORM:
Windows
OVERALL RISK RATING:
DAMAGE POTENTIAL:
DISTRIBUTION POTENTIAL:
REPORTED INFECTION:
INFORMATION EXPOSURE:
Threat Type: Trojan
Destructiveness: No
Encrypted: Yes
In the wild: Yes
OVERVIEW
This Trojan arrives on a system as a file dropped by other malware or as a file downloaded unknowingly by users when visiting malicious sites.
Once a malware successfully exploits the said vulnerability, it causes certain actions to be done on the system. It takes advantage of certain vulnerabilities.
TECHNICAL DETAILS
File Size:
23,040 bytes
File Type:
EXE
Memory Resident:
No
Initial Samples Received Date:
24 Apr 2015
Arrival Details
This Trojan arrives on a system as a file dropped by other malware or as a file downloaded unknowingly by users when visiting malicious sites.
Other Details
Once a malware successfully exploits the said vulnerability, it causes the following actions to be done on the system:
- Executes commands using elevated privileges on vulnerable systems
It takes advantage of the following vulnerabilities:
- (MS14-058) Vulnerabilities in Kernel-Mode Driver Could Allow Remote Code Execution (3000061)