Analysis by: JessaD

 PLATFORM:

Windows 2000, XP, Server 2003

 OVERALL RISK RATING:
 DAMAGE POTENTIAL:
 DISTRIBUTION POTENTIAL:
 REPORTED INFECTION:

  • Threat Type: Trojan

  • Destructiveness: No

  • Encrypted:

  • In the wild: Yes

  OVERVIEW

This Trojan may be downloaded by other malware/grayware/spyware from remote sites. It may be dropped by other malware.

It requires its main component to successfully perform its intended routine.

  TECHNICAL DETAILS

File Size: 6,144 bytes
File Type: Other
Memory Resident: No
Initial Samples Received Date: 16 Aug 2010

Arrival Details

This Trojan may be downloaded by other malware/grayware/spyware from remote sites.

It may be dropped by other malware.

Other Details

Based on analysis of the codes, it has the following capabilities:

  • It is a .CAB file that contains an .EXE file. The embedded .EXE file then attempts to execute a file named SETUP.CMD via cmd.exe using the paramaters, open cmd.exe /C setup.cmd.
  • However, it requires the presence of setup.cmd in order to run properly.

It requires its main component to successfully perform its intended routine.