Thursday, June 14, 2007

TROJ_STRAT.GI

TROJ_STRAT.GI
Malware type: Trojan
Aliases: No Alias Found
In the wild: Yes
Destructive: No
Language: English

File type: PE

Memory resident: Yes

Size of malware: 20,576 Bytes (compressed)

Initial samples received on: Jun 11, 2007

Payload 1: Downloads files



Details:


This Trojan arrives as an attachment to email messages spammed by another malware or a malicious user.

It accesses the following Web site to download and execute a file:
http://{BLOCKED}esunhaxazedesa.com/getw.exe- detected by Trend Micro as WORM_STRAT.GI

As a result, routines of the downloaded worm are also exhibited on the affected system.

It comes with its own compression and runs on Windows 98, ME, NT, 2000, XP, and Server 2003.


Analysis By: Luis Antonio P. Magisa

Copyright (c) 1989-2007 Trend Micro Incorporated. All rights reserved.

Labels: ,