Home / malwarePDF  

Trojan-Downloader:W32/Wimad.gen!A


First posted on 12 March 2010.
Source: SecurityHome

Aliases :

Trojan-Downloader:W32/Wimad.gen!A is also known as Trojan.Wimad (Symantec).

Explanation :

A trojan that secretly downloads malicious files from a remote server, then installs and executes the files.

Additional DetailsThis is the detection for malicious files that are executed using Windows Media Player (WMP). The files may use any extension that can be recognized and executed by WMP, such as MP3 or WMA.

When executing with Windows Media Player, the malicious file will attempt to make a connection to a URL in the web browser. Some URLs the malware attempt to open are:
€ http://www.fastmp3player.com/affiliates/[...]/2/?embedded=false - down € http://www.fastmp3player.com/affiliates/[...]/1/?embedded=false - down € http://isvbr.net/[...]=false - down
These URLs lead to webpages hosting malicious files, which may be downloaded and executed by an unsuspecting user.

Last update 12 March 2010

 

TOP

Malware :