This Trojan arrives as an attachment to email messages spammed by other malware/grayware or malicious users. It arrives on a system as a file dropped by other malware or as a file downloaded unknowingly by users when visiting malicious sites.
It executes the downloaded files. As a result, malicious routines of the downloaded files are exhibited on the affected system. As of this writing, the said sites are inaccessible.
File size: 1,473,344 bytes
File type: EXE
Memory resident: No
Initial samples received date: 06 Feb 2013
Payload: Connects to URLs/IPs
Arrival Details
This Trojan arrives as an attachment to email messages spammed by other malware/grayware or malicious users.
It arrives on a system as a file dropped by other malware or as a file downloaded unknowingly by users when visiting malicious sites.
Installation
This Trojan drops the following non-malicious file:
(Note: %Windows% is the Windows folder, which is usually C:\Windows.)
Download Routine
This Trojan accesses the following websites to download files:
- https://som.{BLOCKED}e.com/h-s-internal/20130128/f3487f359b38436f
- https://som.{BLOCKED}e.com/h-s-internal/20130128/d3669545621045d9
It saves the files it downloads using the following names:
- %Windows%\WIDEAWAKE1.zip
- %Windows%\WIDEAWAKE3.zip
(Note: %Windows% is the Windows folder, which is usually C:\Windows.)
It then executes the downloaded files. As a result, malicious routines of the downloaded files are exhibited on the affected system.
As of this writing, the said sites are inaccessible.
NOTES:
This Trojan is signed with a real and valid digital certificate issued by DigiCert to trick users into thinking that it is legitimate.
Connect with us on
| | | |