Infection Channel: Dropped by other malware, Downloaded from the Internet
This Trojan may be downloaded by other malware/grayware from remote sites.
File size: 8,002 bytes
File type: SWF
Initial samples received date: 07 May 2012
Payload: Drops files
Arrival Details
This Trojan may be downloaded by the following malware/grayware from remote sites:
It may be downloaded from the following remote sites:
- http://www.{BLOCKED}ups.com/update/top.swf
Dropping Routine
This Trojan takes advantage of the following software vulnerabilities to drop malicious files:
NOTES:
It is a SWF component of a dropper document malware that is detected by Trend Micro as TROJ_SCRIPBRID.A.
It aids in extracting, decrypting and executing an embedded malicious executable file in TROJ_SCRIPBRID.A's body. As a result, malicious routines of the extracted malicious file are also exhibited on the affected system.
Trend Micro detects the extracted executable as BKDR_INJECT.EVL.
Connect with us on
| | | |