TROJ_UPATRE.BGTF
April 26, 2014
ALIASES:
W32/Trojan3.IDZ (exact) (Fprot)
PLATFORM:
Windows 2000, Windows Server 2003, Windows XP (32-bit, 64-bit), Windows Vista (32-bit, 64-bit), Windows 7 (32-bit, 64-bit)
OVERALL RISK RATING:
DAMAGE POTENTIAL:
DISTRIBUTION POTENTIAL:
REPORTED INFECTION:
INFORMATION EXPOSURE:
Threat Type: Trojan
Destructiveness: No
Encrypted:
In the wild: Yes
OVERVIEW
This Trojan arrives as an attachment to email messages spammed by other malware/grayware or malicious users.
TECHNICAL DETAILS
File Size: 82,432 bytes
File Type: EXE
Initial Samples Received Date: 24 Apr 2014
Arrival Details
This Trojan arrives as an attachment to email messages spammed by other malware/grayware or malicious users.
Other Details
This Trojan attempts to access the following websites to download files, which are possibly malicious:
- http://{BLOCKED}inclan.org.clanservers.com/deniers/echos
- http://{BLOCKED}english.com/drivels/shellfish
- http://{BLOCKED}isdance.ca/epimethius/detonates
- http://{BLOCKED}tungskultur.org/tipsily/battled
- http://www.{BLOCKED}gallon.be/portals/ruined
- http://ftp.{BLOCKED}vermedia.ca/sprangs/meringue
- http://www.{BLOCKED}spiegel.de/discos/preemptive
- http://www.10142493.{BLOCKED}arn.com/banach/vizor
- http://www.{BLOCKED}negta.ca/madrigals/revealings
- http://{BLOCKED}.{BLOCKED}.188.227/peskiest/keystones
- http://{BLOCKED}ne2u.com/puncture/clump
- http://{BLOCKED}arketing.co.uk/overhaul/niobe
- http://{BLOCKED}ASTFOOTBALL.COM/slaloming/opera
- http://{BLOCKED}ia.ch/stepson/grange
- http://www.{BLOCKED}n.com.br/capability/engraver
- http://{BLOCKED}loud.com/detractor/reverting
- http://www.{BLOCKED}laus.de/browne/reuse
- http://{BLOCKED}harise.com/pensively/nitpicked
- http://{BLOCKED}sdance.ca/awfulness/vessels
- http://{BLOCKED}kspd.com/riboflavin/composure
- http://{BLOCKED}s.de/peaceful/clenched
- http://www.{BLOCKED}technicalservices.com/pubic/assertion
- http://www.{BLOCKED}karsulm.de/pleats/enquiry
- http://{BLOCKED}um.com/gainsays/frigidly
- http://{BLOCKED}ek.com/ashmolean/zhengzhou
- http://{BLOCKED}a.fr/rawness/reformat
- http://{BLOCKED}rservice.ivecoaustralia.com/essential/supernova
- http://{BLOCKED}in.dmirc.com/little/strikers
- http://{BLOCKED}sseyvacations.com/disabled/casements
- http://{BLOCKED}paedagogik.de/checkpoint/resonantly