This Trojan may be downloaded from several remote sites. It may also be downloaded from links in email messages sent out by WORM_KELIHOS.SM.
It connects to website to download and execute a malicious file detected by Trend Micro as WORM_KELIHOS.SM.
This Trojan executes the downloaded files. As a result, malicious routines of the downloaded files are exhibited on the affected system.
File size: 19,968 bytes
Memory resident: No
Initial samples received date: 05 Jan 2011
Payload: Downloads files
Arrival Details
This Trojan may be downloaded from the following remote site(s):
- http://{BLOCKED}i.com/install_flash_player.exe
- http://{BLOCKED}p.com/install_flash_player.exe
- http://{BLOCKED}cu.com/install_flash_player.exe
- http://{BLOCKED}r.com/install_flash_player.exe
- http://{BLOCKED}de.com/install_flash_player.exe
Download Routine
This Trojan connects to the following website(s) to download and execute a malicious file:
- http://{BLOCKED}.{BLOCKED}.240.36/flash2.exe
It saves the files it downloads using the following names:
- %Windows%\Temp\_ex-{random numbers}.exe
(Note: %Windows% is the Windows folder, which is usually C:\Windows or C:\WINNT.)
Trend Micro detects the dowloaded file as:
It then executes the downloaded files. As a result, malicious routines of the downloaded files are exhibited on the affected system.
NOTES:
This malware may be downloaded from links in email messages sent out by WORM_KELIHOS.SM
Connect with us on
| | | |