Analysis by: Christopher Daniel So

 PLATFORM:

Windows 2000, Windows XP, Windows Server 2003

 OVERALL RISK RATING:
 DAMAGE POTENTIAL:
 DISTRIBUTION POTENTIAL:
 REPORTED INFECTION:

  • Threat Type: Trojan

  • Destructiveness: No

  • Encrypted:

  • In the wild: Yes

  OVERVIEW

This Trojan may arrive bundled with malware packages as a malware component.

It executes the downloaded files. As a result, malicious routines of the downloaded files are exhibited on the affected system. As of this writing, the said sites are inaccessible.

  TECHNICAL DETAILS

File Size: 15,315 bytes
File Type: Java Class
Initial Samples Received Date: 04 Apr 2012

Arrival Details

This Trojan may arrive bundled with malware packages as a malware component.

Download Routine

This Trojan accesses the following websites to download files:

  • http://{BLOCKED}box.com/u/68019757/a.gif

It saves the files it downloads using the following names:

  • {all user's profile}\{8 random characters}.exe

It then executes the downloaded files. As a result, malicious routines of the downloaded files are exhibited on the affected system.

As of this writing, the said sites are inaccessible.

NOTES:
It also downloads the file from the URL specified in the parameter l.