TSPY_SOBIT
June 22, 2016
PLATFORM:
Windows
OVERALL RISK RATING:
DAMAGE POTENTIAL:
DISTRIBUTION POTENTIAL:
REPORTED INFECTION:
INFORMATION EXPOSURE:
Threat Type: Trojan
Destructiveness: No
Encrypted:
In the wild: Yes
OVERVIEW
This Trojan arrives on a system as a file dropped by other malware or as a file downloaded unknowingly by users when visiting malicious sites.
TECHNICAL DETAILS
File Size:
(varies) bytes
File Type:
EXE
Memory Resident:
Yes
Initial Samples Received Date:
12 Oct 2015
Arrival Details
This Trojan arrives on a system as a file dropped by other malware or as a file downloaded unknowingly by users when visiting malicious sites.
Other Details
This Trojan connects to the following possibly malicious URL:
- http://download.{BLOCKED}ems.com/d4.fcgi?v=4.000&act=clist&aid=124462&skid=tte&langid=
- http://www.{BLOCKED}admin.com/cgi-bin/err4.cgi?prog=ldr&ver=4.000&code=9&info=&aid=124462&skid=tte&langid=&winver=Windows+NT+6.1;7601;8.0.7601.17514&ci=1-56