Infection Channel: Downloaded from the Internet
This Trojan executes when a user accesses certain websites where it is hosted.
File size: 3,853 bytes
File type: Java Class
Initial samples received date: 26 Jul 2012
Payload: Drops files
Arrival Details
This Trojan executes when a user accesses certain websites where it is hosted.
NOTES:
It determines the operating system where it is executing.
If the operating system is Windows, it drops and executes the following file:
- %User Temp%\~spawn{random number}.tmp.dir\payload.exe - detected by Trend Micro as WORM_MORCUT.A
If the malware is running in Mac OS X, it drops and executes the following file:- $TMPDIR/~spawn{random number}.tmp.dir/payload.exe - detected by Trend Micro as OSX_MORCUT.A
Where $TMPDIR is usually /var/folders/cr/{random characters}/T.
Connect with us on
| | | |