Infection Channel: Downloaded from the Internet
This malware is loaded by HTML_EXPDROP.II. It attempts to connect to a site to download a backdoor detected as BKDR_POISON.BMN.
The backdoor is executed on the affected computer. As a result, all malicious routines of the executed backdoor are exhibited on the affected system.
This Trojan may be hosted on a website and run when a user accesses the said website.
File size: 13,631 bytes
File type: SWF
Initial samples received date: 17 Sep 2012
Payload: Downloads files
Arrival Details
This Trojan may be hosted on a website and run when a user accesses the said website.
NOTES:
Once this malware is loaded by EXPLOIT.HTML, which is detected as HTML_EXPDROP.II, it attempts to connect to the following site to download a malicious file:
- http://{BLOCKED}.{BLOCKED}.104.149/public/help/111.exe
It executes the downloaded file. As a result, malicious behavior of the downloaded file is exhibited on the affected system. Trend Micro detects the downloaded file as BKDR_POISON.BMN.
Connect with us on
| | | |