TROJ_AGENT_000042b.TOMA
October 09, 2012
PLATFORM:
Windows 2000, Windows XP, Windows Server 2003
OVERALL RISK RATING:
DAMAGE POTENTIAL:
DISTRIBUTION POTENTIAL:
REPORTED INFECTION:
Threat Type: Trojan
Destructiveness: No
Encrypted:
In the wild: Yes
OVERVIEW
This Trojan arrives on a system as a file dropped by other malware or as a file downloaded unknowingly by users when visiting malicious sites.
It attempts to access certain websites.
TECHNICAL DETAILS
File Size:
28672 bytes
File Type:
EXE
Memory Resident:
Yes
Initial Samples Received Date:
10 Mar 2011
Arrival Details
This Trojan arrives on a system as a file dropped by other malware or as a file downloaded unknowingly by users when visiting malicious sites.
Other Details
This Trojan attempts to access certain websites.
NOTES:
This is Trend Micro's Automated Smart Pattern Proactive Detection for files that manifest similar behavior and characteristics as the following malware:
- TROJ_AGENT
Upon execution, this Trojan attempts to access the following possible malicious websites:
- http://www.{BLOCKED}34xing.w239.dns911.cn/kills.txt?t3=125424
- http://www.{BLOCKED}sp.web194.dns911.cn/kills.txt?t4=125429
- http://www.{BLOCKED}3.com/kills.txt?t5=125431
- http://www.{BLOCKED}.{BLOCKED}.9.151/kills.txt?t1=125433