| Malware name | Trojan.Agent.ahze | | Type | Trojan | | Affected platform | Win32 | | Media-Type | application/executable | | MD5 checksum | A2BE925AA32F2430CDDADEA9619650BB | | Static file | yes | | Filesize | 37,019 Bytes | Alias names (also known as) | | Sophos | Troj/Dloadr-BWB | | McAfee | Generic BackDoor | | CA ETrust | Win32/Thrap.R |
| | Side effects | Downloads a malicious file | | Propagation | No own spreading routine |
|
Description:
Files
It copies itself to the following locations:
• %WINDIR%\svchost.exe
• %SYSDIR%\..\svchost.exe
It tries to download a file:
– The location is the following:
• http://kino.to/**********/stat.php
At the time of writing this file was not online for further investigation.
File details
Programming language:
The malware program was written in MS Visual C++.