W97M_DLOAD.OVE
Windows
Threat Type: Trojan
Destructiveness: No
Encrypted:
In the wild: Yes
OVERVIEW
This Trojan arrives as an attachment to email messages spammed by other malware/grayware or malicious users.
It executes the downloaded files. As a result, malicious routines of the downloaded files are exhibited on the affected system.
TECHNICAL DETAILS
Arrival Details
This Trojan arrives as an attachment to email messages spammed by other malware/grayware or malicious users.
Installation
This Trojan drops the following files:
- %Temp%\adobeacd-update.bat
- %Temp%\adobeacd-update.vbs
- %Temp%\adobeacd-update.ps1
(Note: %Temp% is the Windows temporary folder, where it usually is C:\Windows\Temp on all Windows operating system versions.)
Download Routine
This Trojan saves the files it downloads using the following names:
- %Temp%\444.exe
(Note: %Temp% is the Windows temporary folder, where it usually is C:\Windows\Temp on all Windows operating system versions.)
It then executes the downloaded files. As a result, malicious routines of the downloaded files are exhibited on the affected system.
Other Details
This Trojan connects to the following possibly malicious URL:
- www.{BLOCKED}ch.com.hk/images/tn.exe
NOTES:
The dropped files are deleted afterwards.