This Trojan may be dropped by other malware. It may be unknowingly downloaded by a user while visiting malicious websites. It executes when a user accesses certain websites where it is hosted.
File size: Varies
File type: HTA
Initial samples received date: 15 Mar 2011
Arrival Details
This Trojan may be dropped by other malware.
It may be unknowingly downloaded by a user while visiting malicious websites.
It executes when a user accesses certain websites where it is hosted.
NOTES:
This Trojan connects to the following websites that contain pornographic content:
- http://{BLOCKED}poo.net/user/h_check.php
- http://{BLOCKED}poo.net/user/h_info_ajax.php
- http://www.{BLOCKED}vies.com/regist1.php?s=1&d=04&f=01&p=43066139
- http://www.{BLOCKED}vies.com/css/regist2.css
- http://www.{BLOCKED}vies.com/css/regist2/close_button.jpg
- http://www.{BLOCKED}vies.com/css/regist2/harituki.jpg
- http://{BLOCKED}1.camel-movies.com/04/01.wmv
- http://www.{BLOCKED}vies.com/regist1.php?s=1&d=04&f=01&p=43066139 http://{BLOCKED}1.sloughi-morocco.info/movie54/27.wmv
- http://www.{BLOCKED}i-morocco.info/Scripts/AC_RunActiveContent.js
- http://www.{BLOCKED}i-morocco.info/css/regist1.css
- http://www.{BLOCKED}i-morocco.info/img/regist123/Xbt.jpg
- http://www.{BLOCKED}i-morocco.info/img/regist123/title_bar.jpg
- http://www.{BLOCKED}i-morocco.info/regist1.php?s=1&d=54&f=27&p=43722105
- http://{BLOCKED}fest.galhimawarimove.net
- http://{BLOCKED}fest.galhimawarimove.net
- http://{BLOCKED}n.galhimawarimove.net
- http://{BLOCKED}pper.galhimawarimove.net
- http://www.{BLOCKED}01host.com
- http://{BLOCKED}kix.com/member/delete.php
This description is based on a compiled analysis of several variants of HTML_HTAPORN. Note that specific data such as file names and registry values may vary for each variant.
Connect with us on
| | | |