TROJ_DLOADR.EW
a variant of Win32/Kryptik.BZHQ trojan(NOD32); Troj/Zbot-IAZ(Sophos-Lite)
Windows 2000, Windows Server 2003, Windows XP (32-bit, 64-bit), Windows Vista (32-bit, 64-bit), Windows 7 (32-bit, 64-bit)
Threat Type: Trojan
Destructiveness: No
Encrypted:
In the wild: Yes
OVERVIEW
This Trojan arrives on a system as a file dropped by other malware or as a file downloaded unknowingly by users when visiting malicious sites.
TECHNICAL DETAILS
130,560 bytes
EXE
09 Apr 2014
Arrival Details
This Trojan arrives on a system as a file dropped by other malware or as a file downloaded unknowingly by users when visiting malicious sites.
Download Routine
This Trojan saves the files it downloads using the following names:
- %User Temp%\mss{random characters}.exe
- %User Temp%\mss{random characters}.tmp
(Note: %User Temp% is the current user's Temp folder, which is usually C:\Documents and Settings\{user name}\Local Settings\Temp on Windows 2000, XP, and Server 2003, or C:\Users\{user name}\AppData\Local\Temp on Windows Vista and 7.)
Other Details
This Trojan connects to the following possibly malicious URL:
- http://{BLOCKED}ttoplay.co.uk/duffer/salutations
- http://{BLOCKED}ttoplay.co.uk/duffer/salutations
- http://{BLOCKED}temas.com.ar/ennobles/moment
- http://www.{BLOCKED}econtracts.co.uk/racked/pennis
- http://{BLOCKED}dcommercials.co.uk/transepts/your
- http://{BLOCKED}chanics.com/spengler/beatle
- http://{BLOCKED}stersandiego.com/impugning/felsitic
- http://{BLOCKED}.{BLOCKED}.161.78/mishapping/fleeceable
- http://www.{BLOCKED}s.net/dyslexia/horizonless
- http://{BLOCKED}60.co.uk/mervin/number
- http://{BLOCKED}ttoplay.co.uk/duffer/salutations
- http://{BLOCKED}.{BLOCKED}.41.251/goiters/wonderless
- http://{BLOCKED}etcollection.com/adverb/songless
- http://www.{BLOCKED}boutiquehotelsandvillas.com/qualm/onder
- http://{BLOCKED}n-flooring.org.uk/stern/just
- http://{BLOCKED}senta.co/mores/wait
- http://{BLOCKED}temas.com.ar/ennobles/moment
- http://{BLOCKED}o.com/carped/loose
- http://{BLOCKED}tours.ca/precluding/enlarge
- http://www.{BLOCKED}econtracts.co.uk/racked/pennis
- http://{BLOCKED}dcommercials.co.uk/transepts/your
- http://{BLOCKED}thofeck.de/gerardo/biggest
- http://{BLOCKED}a.com.tr/pennons/fan
- http://ftp.{BLOCKED}es.org/cajoling/make
- http://{BLOCKED}ps.co.za/willing/hill
- http://arik-{BLOCKED}euk.co.uk/habit/day