Analysis by: RonJay Kristoffer Caragay

ALIASES:

TrojanDownloader:Java/Toniper (Microsoft); Trojan-Downloader.Java.Agent.op (Kaspersky); Trojan.Maljava (Symantec); Trojan-Downloader.Java.Agent (Ikarus)

 PLATFORM:

Windows

 OVERALL RISK RATING:
 DAMAGE POTENTIAL:
 DISTRIBUTION POTENTIAL:
 REPORTED INFECTION:
 INFORMATION EXPOSURE:

  • Threat Type: Trojan

  • Destructiveness: No

  • Encrypted:

  • In the wild: Yes

  OVERVIEW

This Trojan arrives on a system as a file dropped by other malware or as a file downloaded unknowingly by users when visiting malicious sites. It may be hosted on a website and run when a user accesses the said website.

  TECHNICAL DETAILS

Tamaño del archivo 2,941 bytes
Tipo de archivo Java
Fecha de recepción de las muestras iniciales 04 Oct 2013

Arrival Details

This Trojan arrives on a system as a file dropped by other malware or as a file downloaded unknowingly by users when visiting malicious sites.

It may be hosted on a website and run when a user accesses the said website.

Download Routine

This Trojan saves the files it downloads using the following names:

  • %All Users Profile%\rundll32.exe

(Note: %All Users Profile% is the All Users or Common profile folder, which is C:\Documents and Settings\All Users in Windows 2000, XP, and Server 2003, and C:\ProgramData in Windows Vista and 7.)

It downloads a possibly malicious file from a certain URL. The URL where this malware downloads the said file depends on the following parameter(s) passed on to it by its components:

  • url