Home / malwarePDF  

TrojanDownloader:Win32/Beebone.AY


First posted on 19 May 2012.
Source: Microsoft

Aliases :

TrojanDownloader:Win32/Beebone.AY is also known as Trojan-Downloader.Win32.VB.aret (Kaspersky), Trojan.DL.VB!mF27OYT0HA0 (VirusBuster), Trojan.DownLoad3.5758 (Dr.Web), Win32/TrojanDownloader.VB.PSN trojan (ESET), Trojan.Win32.VB (Ikarus), Downloader.a!bs3 (McAfee), TROJ_SPNR.0BE212 (Trend Micro).

Explanation :



TrojanDownloader:Win32/Beebone.AY is is a trojan that downloads files from a certain server.



Installation

TrojanDownloader:Win32/Beebone.AY is reported to spread through Skype. You may receive messages on Skype containing a link to "video.yourfun.us/video/<removed>002ak2350u". This link leads to a copy of the trojan.

The trojan may pose as a fake update for the Adobe Flash Player.



Payload

Downloads other files

TrojanDownloader:Win32/Beebone.AY tries to connect to "update7754.wow64.net" via TCP port 60077 to download other files. The server is unavailable as of this writing.



Analysis by Lena Lin

Last update 19 May 2012

 

TOP