HTML_PHISH.DRL
October 28, 2014
ALIASES:
Mal/Phish-A (Sophos)
PLATFORM:
Windows 2000, Windows Server 2003, Windows XP (32-bit, 64-bit), Windows Vista (32-bit, 64-bit), Windows 7 (32-bit, 64-bit)
OVERALL RISK RATING:
DAMAGE POTENTIAL:
DISTRIBUTION POTENTIAL:
REPORTED INFECTION:
INFORMATION EXPOSURE:

Threat Type: Trojan
Destructiveness: No
Encrypted:
In the wild: Yes
OVERVIEW
This Trojan may be hosted on a website and run when a user accesses the said website.
TECHNICAL DETAILS
File Size:
5,706 bytes
File Type:
HTML, HTM
Initial Samples Received Date:
07 May 2014
Arrival Details
This Trojan may be hosted on a website and run when a user accesses the said website.
Other Details
This Trojan connects to the following possibly malicious URL:
- http://{BLOCKED}nk9.cwsurf.de/login31.php