W97M_MOHODROP.B
VBS/Agent.0346!tr (Fortinet) ,TrojanDownloader:W97M/Mohodrop.A (Microsoft) ,Trojan.Mdropper (Symantec)
Windows 2000, Windows Server 2003, Windows XP (32-bit, 64-bit), Windows Vista (32-bit, 64-bit), Windows 7 (32-bit, 64-bit)
Threat Type: Trojan
Destructiveness: No
Encrypted:
In the wild: Yes
OVERVIEW
This Trojan arrives as an attachment to email messages spammed by other malware/grayware or malicious users. It arrives on a system as a file dropped by other malware or as a file downloaded unknowingly by users when visiting malicious sites.
TECHNICAL DETAILS
33,280 bytes
DOC
07 Mar 2014
Arrival Details
This Trojan arrives as an attachment to email messages spammed by other malware/grayware or malicious users.
It arrives on a system as a file dropped by other malware or as a file downloaded unknowingly by users when visiting malicious sites.
Installation
This Trojan creates the following folders:
- %Application Data%\OSNPGKNVXAJ
(Note: %Application Data% is the current user's Application Data folder, which is usually C:\Documents and Settings\{user name}\Application Data on Windows 2000, XP, and Server 2003, or C:\Users\{user name}\AppData\Roaming on Windows Vista and 7.)
Download Routine
This Trojan saves the files it downloads using the following names:
- %Application Data%\OSNPGKNVXAJ\JSDSRLXCSPU.com
Other Details
This Trojan attempts to access the following websites to download files, which are possibly malicious:
- http://{BLOCKED}a.co.in/v45.exe