W2KM_BARTALEX.SMO
TrojanDownloader:W97M/Adnel (Microsoft), W97M.Downloader (Symantec), W97M/Bartallex.n (McAfee)
Windows

Threat Type: Trojan
Destructiveness: No
Encrypted:
In the wild: Yes
OVERVIEW
This Trojan arrives on a system as a file dropped by other malware or as a file downloaded unknowingly by users when visiting malicious sites.
TECHNICAL DETAILS
78,336 bytes
DOC
18 Jul 2015
Arrival Details
This Trojan arrives on a system as a file dropped by other malware or as a file downloaded unknowingly by users when visiting malicious sites.
Other Details
This Trojan connects to the following possibly malicious URL:
- http://{BLOCKED}nneton-quebec.com/components/com_sexycontactform/fileupload/files/78672738612836.txt
- http://{BLOCKED}ions.com/wp-includes/js/tinymce/themes/advanced/skins/highcontrast/78672738612836.txt
It drops the following file(s)/component(s):
- %User Temp%\dikopirt.exe
(Note: %User Temp% is the user's temporary folder, where it usually is C:\Documents and Settings\{user name}\Local Settings\Temp on Windows 2000, Windows Server 2003, and Windows XP (32- and 64-bit); C:\Users\{user name}\AppData\Local\Temp on Windows Vista (32- and 64-bit), Windows 7 (32- and 64-bit), Windows 8 (32- and 64-bit), Windows 8.1 (32- and 64-bit), Windows Server 2008, and Windows Server 2012.)