Home / malwarePDF  

TrojanDownloader:Win32/Taleret.A


First posted on 27 July 2010.
Source: SecurityHome

Aliases :

TrojanDownloader:Win32/Taleret.A is also known as Win32/Tnega.BOK (CA), Trojan-Downloader.Win32.Agent.dmzb (Kaspersky).

Explanation :

TrojanDownloader:Win32/Taleret.A is a trojan that attempts to download arbitrary files from predefined websites.
Top

TrojanDownloader:Win32/Taleret.A is a trojan that attempts to download arbitrary files from predefined websites. InstallationThis trojan may be present as a DLL file and is installed by other malicious software. Payload Downloads arbitrary filesTrojanDownloader:Win32/Taleret.A attempts to connect to a predefined website via port 443 to download other malware files. In the wild, this trojan has been observed to attempt connections to the following sites: trade.terelation.com 211.234.117.8 As of this writing, both sites are already inaccessible. The downloaded file is then saved and executed in the %TEMP% folder. It may also send system information via POST, such as the IP and MAC address of the infected computer to a remote site.

Analysis by Elda Dimakiling

Last update 27 July 2010

 

TOP