Home / malware TrojanDownloader:Win32/Beebone.AY
First posted on 19 May 2012.
Source: MicrosoftAliases :
TrojanDownloader:Win32/Beebone.AY is also known as Trojan-Downloader.Win32.VB.aret (Kaspersky), Trojan.DL.VB!mF27OYT0HA0 (VirusBuster), Trojan.DownLoad3.5758 (Dr.Web), Win32/TrojanDownloader.VB.PSN trojan (ESET), Trojan.Win32.VB (Ikarus), Downloader.a!bs3 (McAfee), TROJ_SPNR.0BE212 (Trend Micro).
Explanation :
TrojanDownloader:Win32/Beebone.AY is is a trojan that downloads files from a certain server.
Installation
TrojanDownloader:Win32/Beebone.AY is reported to spread through Skype. You may receive messages on Skype containing a link to "video.yourfun.us/video/<removed>002ak2350u". This link leads to a copy of the trojan.
The trojan may pose as a fake update for the Adobe Flash Player.
Payload
Downloads other files
TrojanDownloader:Win32/Beebone.AY tries to connect to "update7754.wow64.net" via TCP port 60077 to download other files. The server is unavailable as of this writing.
Analysis by Lena Lin
Last update 19 May 2012