Infection Channel: Spammed via email
This Trojan arrives as an attachment in a spammed email that uses Tibet and the 2012 Olympics as lure.
To get a one-glance comprehensive view of the behavior of this Trojan, refer to the Threat Diagram shown below.

This Trojan arrives as an attachment to email messages spammed by other malware/grayware or malicious users. It arrives on a system as a file dropped by other malware or as a file downloaded unknowingly by users when visiting malicious sites. It may be manually installed by a user.
It uses common file icons to trick a user into thinking that the files are legitimate.
It executes the dropped file(s). As a result, malicious routines of the dropped files are exhibited on the affected system.
It deletes itself after execution.
File size: 196,608 bytes
File type: EXE
Memory resident: No
Initial samples received date: 06 Aug 2012
Payload: Drops files, Displays images
Arrival Details
This Trojan arrives as an attachment to email messages spammed by other malware/grayware or malicious users.
It arrives on a system as a file dropped by other malware or as a file downloaded unknowingly by users when visiting malicious sites.
It may be manually installed by a user.
Installation
This Trojan drops the following component file(s):
- %System%\systimer.exe - detected as TROJ_RUGENT.A
(Note: %System% is the Windows system folder, which is usually C:\Windows\System on Windows 98 and ME, C:\WINNT\System32 on Windows NT and 2000, or C:\Windows\System32 on Windows XP and Server 2003.)
It uses common file icons to trick a user into thinking that the files are legitimate.
Dropping Routine
This Trojan executes the dropped file(s). As a result, malicious routines of the dropped files are exhibited on the affected system.
Other Details
This Trojan displays the following images:
It deletes itself after execution.
Connect with us on
| | | |