Infection Channel: Downloaded from the Internet
This malware downloads a supposedly Windows 8 application from a certain link once the affected users clicked 'OK' or close buttons on the displayed image.
File size: 181,024 bytes
File type: EXE
Memory resident: No
Initial samples received date: 27 Nov 2012
Payload: Displays image
Arrival Details
This Trojan may be downloaded from the following remote sites:
- http://{BLOCKED}en2eqqh2.cloudfront.net/2.2.43/5069717/windows%208%20win%208.exe
Installation
This Trojan displays the following fake error messages:

NOTES:
It downloads a supposedly Windows 8 application from the following link once the affected users clicked on the 'OK' or close buttons on the image above:
- http://api.{BLOCKED}admr.com/installer/5062d47f-b8cc-411a-9555-12ab5bc06f2f/5069717/open?ie=6&net=4.0F&sp=0
Connect with us on
| | | |