Analysis by: John Anthony Banes

 PLATFORM:

Windows

 OVERALL RISK RATING:
 DAMAGE POTENTIAL:
 DISTRIBUTION POTENTIAL:
 REPORTED INFECTION:
 SYSTEM IMPACT RATING:
 INFORMATION EXPOSURE:

  • Threat Type: Trojan

  • Destructiveness: No

  • Encrypted:

  • In the wild: Yes

  OVERVIEW

This Trojan arrives on a system as a file dropped by other malware or as a file downloaded unknowingly by users when visiting malicious sites. It may be hosted on a website and run when a user accesses the said website.

  TECHNICAL DETAILS

File Size: 2,668 bytes
File Type: HTML, HTM
Initial Samples Received Date: 04 Dec 2018

Arrival Details

This Trojan arrives on a system as a file dropped by other malware or as a file downloaded unknowingly by users when visiting malicious sites.

It may be hosted on a website and run when a user accesses the said website.

Other Details

This Trojan connects to the following possibly malicious URL:

  • http://{BLOCKED}o.{BLOCKED}8.cc/nubia.html
  • http://www.{BLOCKED}8.cc/hlct.html
  • http://www.{BLOCKED}8.cc/huatu.html
  • http://{BLOCKED}o.{BLOCKED}8.cc/yhzc.html
  • http://{BLOCKED}2.{BLOCKED}8.cc/xiechengql.html
  • http://{BLOCKED}o.{BLOCKED}8.cc/zhe800.html
  • http://{BLOCKED}2.{BLOCKED}8.cc/suningdm.html
  • http://{BLOCKED}2.{BLOCKED}8.cc/lvmama.html
  • http://{BLOCKED}2.{BLOCKED}8.cc/qunaerdm.html
  • http://www.{BLOCKED}8.cc/west.html
  • http://www.{BLOCKED}8.cc/txy.html
  • http://{BLOCKED}o.{BLOCKED}8.cc/juanpi.html
  • http://{BLOCKED}o.{BLOCKED}8.cc/tebu.html
  • http://{BLOCKED}o.{BLOCKED}8.cc/banggou.html
  • http://{BLOCKED}o.{BLOCKED}8.cc/5173.html
  • http://{BLOCKED}o.{BLOCKED}8.cc/jdxxwlkt.html
  • http://{BLOCKED}o.{BLOCKED}8.cc/zhkjwxdm.html
  • http://{BLOCKED}p.{BLOCKED}tatic.com/js/os.js
  • http://www.{BLOCKED}8.cc/appleurl.html
  • http://www.{BLOCKED}4.com/weiruanlink.html
  • http://{BLOCKED}8.cc/1688go.html
  • http://www.{BLOCKED}h.com/lu.html