| Malware name | Trojan.Dldr.Agent.73728 | | Type | Trojan | | Affected platform | Win32 | | Media-Type | application/executable | | MD5 checksum | CBE0FF45745324FCA399A7CA53820C9F | | Static file | no | | Filesize | 73,728 Bytes | Alias names (also known as) | | Sophos | Mal/Behav-063 | | McAfee | Downloader-BDX | | CA ETrust | Win32/Livuto!generic |
| | Side effects | Downloads malicious files | | Propagation | No own spreading routine |
|
Description:
Files
It tries to download some files:
– The location is the following:
• http://78.157.143.251/hvhakrb/*****.exe
It is saved on the local hard drive under: %tempdir%\vistasp1.exe Furthermore this file gets executed after it was fully downloaded. Further investigation pointed out that this file is malware, too. Detected as: Trojan.Drop.Agen.130048
– The location is the following:
• http://viacodecright1.com/s1265/*****.exe
It is saved on the local hard drive under: %tempdir%\s1265.php Furthermore this file gets executed after it was fully downloaded. Further investigation pointed out that this file is malware, too. Detected as: Trojan.Vapsup.kcw
– The location is the following:
• http://193.33.61.169/*****
It is saved on the local hard drive under: %tempdir%\bindsrv2.exe Furthermore this file gets executed after it was fully downloaded. Further investigation pointed out that this file is malware, too. Detected as: Trojan.Monder.fdd
– The location is the following:
• http://91.203.92.13/files/42/v2test3/*****.exe
It is saved on the local hard drive under: %tempdir%\atmadm2.exe Furthermore this file gets executed after it was fully downloaded. Further investigation pointed out that this file is malware, too. Detected as: Trojan.UPD.61440