TROJ_PHISHER.JDRB
March 18, 2015
PLATFORM:
Windows
OVERALL RISK RATING:
DAMAGE POTENTIAL:
DISTRIBUTION POTENTIAL:
REPORTED INFECTION:
INFORMATION EXPOSURE:

Threat Type: Trojan
Destructiveness: No
Encrypted:
In the wild: Yes
OVERVIEW
This Trojan arrives as an attachment to email messages spammed by other malware/grayware or malicious users. It arrives on a system as a file dropped by other malware or as a file downloaded unknowingly by users when visiting malicious sites.
TECHNICAL DETAILS
Tamaño del archivo 83,845 bytes
Tipo de archivo PDF
Residente en memoria No
Fecha de recepción de las muestras iniciales 18 Mar 2015
Arrival Details
This Trojan arrives as an attachment to email messages spammed by other malware/grayware or malicious users.
It arrives on a system as a file dropped by other malware or as a file downloaded unknowingly by users when visiting malicious sites.
Other Details
This Trojan connects to the following possibly malicious URL:
- http://{BLOCKED}f.{BLOCKED}e.com/manifest/50/win/reader8rdr-en_US.upd
- http://{BLOCKED}f.{BLOCKED}e.com/manifest/50/win/AdobeUpdater.upd
- http://{BLOCKED}f.{BLOCKED}e.com/manifest/50/win/reader8rdr-en_US.upd
- http://{BLOCKED}f.{BLOCKED}e.com/manifest/50/win/AdobeUpdater.upd
NOTES:
The document itself tricks users into accessing a possibly malicious URL:
- http://{BLOCKED}tlook.{BLOCKED}o.com