Home / malwarePDF  

Trojan:W32/Waledac.gen


First posted on 30 January 2009.
Source: SecurityHome

Aliases :

There are no other names known for Trojan:W32/Waledac.gen.

Explanation :

Trojan:W32/Waledac.gen is generic detection of the Waledac trojan.

right]Trojan:W32/Waledac.gen is generic detection of the Waledac trojan.

Waledac is a spammed trojan that is capable of harvesting and forwarding password information.

Social engineering tricks are used to tempt the victim. Fake Barack Obama websites have been used as bait during the US elections. Obama spam was also used during the US Presidential Inauguration. Waledac spam frequently uses holidays and news headlines.

Waledac is capable of receiving commands from a remote server. Commands include instructions on functions to perform (for example, update malware components or send information from the infected computer).

Samples analyzed in the lab downloaded Rogue antispyware applications.

Detections

Examples of generic detection names include:

  • Trojan:W32/Waledac.gen!A
  • Trojan:W32/Waledac.gen!B

Waledac variants use lists of hardcoded IP addresses to determine where it sends harvested data. More recent variants can also update their lists from the remote command server.

Packers

The packers used by Waledac are different depending on the variant. Cryptor is being used as of January, 2009.

Example

For a representative example, please see:

  • Trojan:W32/Waledac.A

Last update 30 January 2009

 

TOP