Infection Channel: Downloaded from the Internet
This Trojan may be downloaded unknowingly by a user when visiting malicious website(s).
File size: 16,759 bytes
File type: JS
Initial samples received date: 10 Jan 2013
Payload: Downloads files
Arrival Details
This Trojan may be downloaded unknowingly by a user when visiting the following malicious website(s):
- {BLOCKED}enhaupdad.bounceme.net/read/offer-canvas.jsp
Download Routine
This Trojan connects to the following URL(s) to download its component file(s):
- http://{BLOCKED}enhaupdad.bounceme.net/read/UTTER-OFFEND.EXE - detected as TROJ_REVETON.RG
- http://{BLOCKED}enhaupdad.bounceme.net/read/UTTER-OFFEND.JAR - detected as JAVA_EXPLOIT.RG
- http://{BLOCKED}enhaupdad.bounceme.net/read/Office_Grass2.pdf
- http://{BLOCKED}enhaupdad.bounceme.net/read/Apple_Solemn1.pdf
- http://{BLOCKED}enhaupdad.bounceme.net/read/strengthen1.swf
- http://{BLOCKED}enhaupdad.bounceme.net/read/PREMISE2.swf
- http://{BLOCKED}enhaupdad.bounceme.net/read/SHALLOW3.swf
NOTES:
This malware checks for vulnerable software (such as Java, Adobe Reader, and Adobe Flash) to download and execute a malicious file.
Connect with us on
| | | |