Infection Channel: Downloaded from the Internet, Dropped by other malware
This Trojan arrives on a system as a file dropped by other malware or as a file downloaded unknowingly by users when visiting malicious sites.
File size: 247,307 bytes
File type: DLL
Memory resident: No
Initial samples received date: 08 Feb 2013
Payload: Drops files
Arrival Details
This Trojan arrives on a system as a file dropped by other malware or as a file downloaded unknowingly by users when visiting malicious sites.
Installation
This Trojan drops and executes the following files:
- %User Temp%\seccenter.xxx - Detected as BKDR_PLUGAX.A
(Note: %User Temp% is the current user's Temp folder, which is usually C:\Documents and Settings\{user name}\Local Settings\Temp on Windows 2000, XP, and Server 2003, or C:\Users\{user name}\AppData\Local\Temp on Windows Vista and 7.)
NOTES:
TROJ_DROPPER.YWO is a .DLL file embedded in SWF_EXPLOIT.MC.
Connect with us on
| | | |