It saves the downloaded file, which is detected as TROJ_FAKEAV.GXX in a specific folder.
This Trojan may be dropped by other malware. It may be unknowingly downloaded by a user while visiting malicious websites.
It executes the downloaded files. As a result, malicious routines of the downloaded files are exhibited on the affected system.
It deletes itself after execution.
File size: Varies
File type: PE
Memory resident: No
Initial samples received date: 10 Nov 2010
Payload: Downloads files
Arrival Details
This Trojan may be dropped by other malware.
It may be unknowingly downloaded by a user while visiting malicious websites.
Download Routine
This Trojan accesses the following websites to download files:
- http://{string1}.{string2}{random number}.com/index.php?{parameters}
- http://{string1}.{string2}{random number}.com/?{parameters}
- http://{string1}.{string2}{random number}.net/index.php?{parameters}
- http://{string1}.{string2}{random number}.net/?{parameters}
It then executes the downloaded files. As a result, malicious routines of the downloaded files are exhibited on the affected system.
Other Details
This Trojan does the following:
- It saves the downloaded file which is detected as TROJ_FAKEAV.GXX in the %User Temp% folder.
- It uses any of the following for String 1 when connecting to websites:
- report
- report1
- report2
- update
- update1
- update2
- It uses a combination of any of the following for String 2:
- disgan
- domain
- dostum
- estwood
- frost
- grover
- istorg
- klapton
- liwnar
- mining
- nalbin
- nartiv
- peren
- plerk
- query
- quzonk
- report
- revcon
- spectr
- statistic
- storage
- traden
- tyscon
- update
- usting
- veter
- wlentor
- yanka
- zulet
(Note: %User Temp% is the current user's Temp folder, which is usually C:\Documents and Settings\{user name}\Local Settings\Temp on Windows 2000, XP, and Server 2003.)
It deletes itself after execution.
Connect with us on
| | | |