Home / malwarePDF  

Trojan.BAT.AACL


First posted on 21 November 2011.
Source: BitDefender

Aliases :

There are no other names known for Trojan.BAT.AACL.

Explanation :

The trojan is a Windows batch file which comes packed alongside a known application for iPhone jailbreaking. The bundle can be downloaded from an illegitimate site which claims to offer a new version of the application, http://[REMOVED]/blackra1n.exeOnce the user executes the downloaded file, the trojan is deployed and executed without the user's knowledge. It attempts to change the preferred DNS server address for several possible internet connections on the user's computer to 188.210.[REMOVED]The names of the connections affected by the trojan are:
Local Area Connectionwireles network connectionLocal Area Connection 2Local Area Connection 1wireles network connection 1wireles network connection 2LANLAN 1LAN 2WANWAN 1WAN 2
After the trojan is executed, the aforementioned application starts so that the user will not realise the computer has been compromised.

Last update 21 November 2011

 

TOP