Analysis by: Mark Joseph Manahan

ALIASES:

W32/Trojan3.IDZ (exact) (Fprot)

 PLATFORM:

Windows 2000, Windows Server 2003, Windows XP (32-bit, 64-bit), Windows Vista (32-bit, 64-bit), Windows 7 (32-bit, 64-bit)

 OVERALL RISK RATING:
 DAMAGE POTENTIAL:
 DISTRIBUTION POTENTIAL:
 REPORTED INFECTION:
 INFORMATION EXPOSURE:

  • Threat Type: Trojan

  • Destructiveness: No

  • Encrypted:

  • In the wild: Yes

  OVERVIEW

This Trojan arrives as an attachment to email messages spammed by other malware/grayware or malicious users.

  TECHNICAL DETAILS

File Size: 82,432 bytes
File Type: EXE
Initial Samples Received Date: 24 Apr 2014

Arrival Details

This Trojan arrives as an attachment to email messages spammed by other malware/grayware or malicious users.

Other Details

This Trojan attempts to access the following websites to download files, which are possibly malicious:

  • http://{BLOCKED}inclan.org.clanservers.com/deniers/echos
  • http://{BLOCKED}english.com/drivels/shellfish
  • http://{BLOCKED}isdance.ca/epimethius/detonates
  • http://{BLOCKED}tungskultur.org/tipsily/battled
  • http://www.{BLOCKED}gallon.be/portals/ruined
  • http://ftp.{BLOCKED}vermedia.ca/sprangs/meringue
  • http://www.{BLOCKED}spiegel.de/discos/preemptive
  • http://www.10142493.{BLOCKED}arn.com/banach/vizor
  • http://www.{BLOCKED}negta.ca/madrigals/revealings
  • http://{BLOCKED}.{BLOCKED}.188.227/peskiest/keystones
  • http://{BLOCKED}ne2u.com/puncture/clump
  • http://{BLOCKED}arketing.co.uk/overhaul/niobe
  • http://{BLOCKED}ASTFOOTBALL.COM/slaloming/opera
  • http://{BLOCKED}ia.ch/stepson/grange
  • http://www.{BLOCKED}n.com.br/capability/engraver
  • http://{BLOCKED}loud.com/detractor/reverting
  • http://www.{BLOCKED}laus.de/browne/reuse
  • http://{BLOCKED}harise.com/pensively/nitpicked
  • http://{BLOCKED}sdance.ca/awfulness/vessels
  • http://{BLOCKED}kspd.com/riboflavin/composure
  • http://{BLOCKED}s.de/peaceful/clenched
  • http://www.{BLOCKED}technicalservices.com/pubic/assertion
  • http://www.{BLOCKED}karsulm.de/pleats/enquiry
  • http://{BLOCKED}um.com/gainsays/frigidly
  • http://{BLOCKED}ek.com/ashmolean/zhengzhou
  • http://{BLOCKED}a.fr/rawness/reformat
  • http://{BLOCKED}rservice.ivecoaustralia.com/essential/supernova
  • http://{BLOCKED}in.dmirc.com/little/strikers
  • http://{BLOCKED}sseyvacations.com/disabled/casements
  • http://{BLOCKED}paedagogik.de/checkpoint/resonantly