Analysis by: Christopher Daniel So

 PLATFORM:

Windows 2000, XP, Server 2003

 OVERALL RISK RATING:
 DAMAGE POTENTIAL:
 DISTRIBUTION POTENTIAL:
 REPORTED INFECTION:
 SYSTEM IMPACT RATING:
 INFORMATION EXPOSURE:

  • Threat Type: Trojan

  • Destructiveness: No

  • Encrypted: No

  • In the wild: Yes

  OVERVIEW

This Trojan may be dropped by other malware.

It executes downloaded files whose malicious routines are exhibited by the affected system.

  TECHNICAL DETAILS

File Size: 22,622 bytes
File Type: DLL
Memory Resident: No
Initial Samples Received Date: 16 Jul 2010

Arrival Details

This Trojan may be dropped by the following malware:

  • TROJ_MONKIF.SMY

Download Routine

This Trojan accesses the following websites to download files:

  • http://media9s.com/photo/{RANDOM}.php?{RANDOM}
  • http://media9s.com/d/dl.php?{RANDOM}

It executes downloaded files :

    whose malicious routines are exhibited by the affected system.

    Other Details

    Based on analysis of the codes, it has the following capabilities:

    • It executes the downloaded file then deletes it.

      SOLUTION

    Minimum Scan Engine: 8.900
    VSAPI OPR PATTERN File: 7.352.06
    VSAPI OPR PATTERN Date: 31 Jul 2010

    Step 1

    Scan your computer with your Trend Micro product and note files detected as TROJ_MONKIF.SMZ

    Step 2

    Restart in Safe Mode

    [ Learn More ]


    Did this description help? Tell us how we did.