Home / malwarePDF  

Trojan-Downloader:W32/Agent.FDA


First posted on 02 November 2007.
Source: SecurityHome

Aliases :

Trojan-Downloader:W32/Agent.FDA is also known as Trojan.Win32.Pakes.bmp, Win32/TrojanDownloader.Injecter.NAC.

Explanation :

F-Secure has received multiple reports regarding a new trojan downloader that is being sent via e-mail to a large number of recipients.

The trojan downloader is attached to a message claiming to be a critical security update from Microsoft.

Trojan-Download:W32/Agent.FDA arrives via e-mail messages claiming to be a critical security update from Microsoft.

The messages have an attachment named update.zip and inside the attachment there is a trojan file named update.exe. The spammed messages contain the following text:


At the bottom of spammed messages there usually is a piece of random text, an attempt to bypass spam filters. Here is a screenshot of one of the spammed messages:



When extracted and run by a user, the trojan-downloader connects to a website and downloads more malicious components.

Last update 02 November 2007

 

TOP

Malware :

Family: