Infection Channel: Downloaded from the Internet
This Trojan executes when a user accesses certain websites where it is hosted.
File size: Varies
File type: HTML, HTM
Memory resident: No
Initial samples received date: 27 Oct 2012
Payload: Displays message/message boxes, Downloads files
Arrival Details
This Trojan executes when a user accesses certain websites where it is hosted.
Rogue Antivirus Routine
This Trojan displays the following fake alerts:
It displays the following window and pretends to scan the system:
NOTES:
Upon closing the browser, this Trojan displays the following message box:
It attempts to access the URL http://{hosted site}/?c=RaEdMCsEyD9o2pcO17KNED++ne2mVXnHy4mjwXhRf8nAluVQznWWinHO1wFBiRpfsWVOwr9LK5bkhQ==. It accesses the URL to download a possibly malicious file.
Connect with us on
| | | |