Author: Sammy Chua   

 

W97M/Downloader.abb (McAfee); Trojan-Downloader.VBA.Agent (IKARUS); WM/Agent!tr (Fortinet)

 PLATFORM:

Windows

 OVER ALL RISK RATING:
 DAMAGE POTENTIAL::
 DISTRIBUTION POTENTIAL::
 REPORTED INFECTION:
 INFORMATION EXPOSURE:
Low
Medium
High
Critical

  • Threat Type:
    Trojan

  • Destructiveness:
    No

  • Encrypted:
     

  • In the wild::
    Yes

  OVERVIEW


  TECHNICAL DETAILS

File size: 166,736 bytes
File type: DOCX
INITIAL SAMPLES RECEIVED DATE: 05 de stycznia de 2015

Rutina de infiltración

Infiltra los archivos siguientes:

  • c:\Windows\Temp\adobeacd-update.bat - hardcoded directory for Windows XP and below
  • c:\Windows\Temp\adobeacd-updatexp.vbs - hardcoded directory for Windows XP and below
  • c:\Windows\Temp\444.exe - hardcoded directory
  • c:\Users\{username}\AppData\Local\Temp\adobeacd-update.ps1 - hardcoded directory for Windows Vista and above
  • c:\Users\{username}\AppData\Local\Temp\adobeacd-update.bat - hardcoded directory for Windows Vista and above
  • c:\Users\{username}\AppData\Local\Temp\adobeacd-update.vbs - hardcoded directory for Windows Vista and above