PLATFORM:

Windows 2000, Windows XP, Windows Server 2003

 OVERALL RISK RATING:
 DAMAGE POTENTIAL:
 DISTRIBUTION POTENTIAL:
 REPORTED INFECTION:

  • Threat Type: Trojan

  • Destructiveness: No

  • Encrypted:

  • In the wild: Yes

  OVERVIEW

This Trojan may arrive bundled with malware packages as a malware component. It may be hosted on a website and run when a user accesses the said website.

  TECHNICAL DETAILS

File Size: 3,722 bytes
File Type: Java
Memory Resident: No
Initial Samples Received Date: 12 Nov 2015

Arrival Details

This Trojan may arrive bundled with malware packages as a malware component.

It may be hosted on a website and run when a user accesses the said website.

NOTES:

This Trojan downloads a possibly malicious file from a certain URL. The URL where this malware downloads the file depends on the parameter passed on to it by its components.

In order to execute properly, this malware needs the whole .JAR file, where this file is bundled from. The downloaded file is saved as %User Temp%\{random file name}.EXE.

(Note: %User Temp% is the current user's Temp folder, which is usually C:\Documents and Settings\{user name}\Local Settings\Temp on Windows 2000, XP, and Server 2003.)