Home / malwarePDF  

TrojanDownloader:Java/Toniper


First posted on 24 January 2013.
Source: Microsoft

Aliases :

There are no other names known for TrojanDownloader:Java/Toniper.

Explanation :



TrojanDownloader:Java/Toniper is a Java trojan that downloads other malware onto your computer.



Installation

TrojanDownloader:Java/Toniper may arrive on your computer when you visit a compromised website that hosts the trojan.



Payload

Downloads other malware

In the wild, we have observed TrojanDownloader:Java/Toniper connecting to specified URLs in order to download malware; for example, we have observed it connecting to "dl.dropbox.com" to download the following file:

JAVAAPPLET.exe - detected as Backdoor:Win32/Fynloski.A

Below are some other files we have observed the trojan attempting to download:

  • 110920002211.jpg
  • a.gif
  • bot.exe
  • cafsdf.dat
  • checker.exe
  • cortex.exe
  • crypted.exe
  • data.exe
  • executeit.exe
  • flashpk.exe
  • GamersChat.exe
  • JavaWebb.exe
  • productsamples.exe




Analysis by Marian Radu

Last update 24 January 2013

 

TOP