TROJ_MDROPPR.NG
Trojan-Downloader.MSWord.Agent.an (Kaspersky), TrojanDownloader:W97M/Orgen.A (Microsoft), Trojan.Gen.2 (Symmantec), [13.OLE]:W97M/Downloader.h (Mcafee), WM97/DwnLdr-LTS (Sophos), W97M/Bernie.B.25 (Antivir), W97M/Bernie.B (Authentium), W97M.Downloader.X (Bitdefender), W97M/Agent.NCI!tr (Fortinet), W97M/Bernie.B (exact) (Fprot), Trojan-Downloader.MSWord.Agent (Ikarus), W97M/TrojanDownloader.Agent.NCI trojan (Esset)
Windows 2000, Windows Server 2003, Windows XP (32-bit, 64-bit), Windows Vista (32-bit, 64-bit), Windows 7 (32-bit, 64-bit)
Threat Type: Trojan
Destructiveness: No
Encrypted:
In the wild: Yes
OVERVIEW
This Trojan arrives on a system as a file dropped by other malware or as a file downloaded unknowingly by users when visiting malicious sites.
It executes the downloaded files. As a result, malicious routines of the downloaded files are exhibited on the affected system.
TECHNICAL DETAILS
Arrival Details
This Trojan arrives on a system as a file dropped by other malware or as a file downloaded unknowingly by users when visiting malicious sites.
Download Routine
This Trojan accesses the following websites to download files:
- http://{BLOCKED}ernie1996.ru/u.exe
It then executes the downloaded files. As a result, malicious routines of the downloaded files are exhibited on the affected system.