Content

Downloader-GN

Type
Trojan
SubType
Downloader
Discovery Date
01/14/2004
Length
2,592 bytes
Minimum DAT
4315 (01/16/2004)
Updated DAT
4315 (01/16/2004)
Minimum Engine
5.1.00
Description Added
01/15/2004
Description Modified
01/15/2004 10:09 AM (PT)
Risk Assessment
Corporate User
Low-Profiled
Home User
Low-Profiled

Tab Navigation

Characteristics

This malware is known to have been spammed on the 14th Jan 2004 via Email with the following characteristics:

From: do_not_reply@paypal.com
Subject: PAYPAL.COM NEW YEAR OFFER
Body:

** GREAT NEW YEAR OFFER FROM PAYPAL.COM **

Dear PayPal.com Member,

We here at PayPal.com are pleased to announce that we have a special New Year offer for you! If you currently have an account with PayPal then you will be eligible to receive a terrific prize from PayPal.com for the New Year. For a limited time only PayPal is offering to add 10 percent of the total balance in your PayPal account to your account and all you have to do is register yourself within the next five business days with our application (see attachment)!

If at this time you do not have a PayPal account of your own you can also register yourself with our secure application and get this great New Year bonus! If you fill out the secure form we have provided PayPal will create an account for you (it's free) and you will receive a confirmation e-mail that your account has been created.

That's not all! If you resend this letter (with its attachment) to all of your friends you may be eligible to receive another New Year bonus because the 1000 PayPal members that send the most of these to their friends will get the bonus. If you are one of these 1000 lucky members then PayPal will add 17 percent of your total balance to your account!

Registration is simple. Just unpack the attachment with WinZip, run the application, and follow the instructions we have provided. If you have problems opening the application then you may want to try downloading a free version of WinZip from http://www.winzip.com

Do not miss your chance at this fantastic opportunity! Thousands of our current customers have already received their prizes and now it's your turn; so hurry up and take advantage of this special offer!

Best of luck in the New Year,
PayPal.com Team


Attachment: PAYPAL.ZIP ( containing PAYPAL.EXE)

When run, the downloader retrieves a file from http://www.aquarium-fish.ru, saves it as "c:\tmp.exe", and executes it.

At the time of writing, the executable on the mentioned Web site was the W32/Mimail.p@MM virus (detected with the current DAT files, version 4313).

The downloader is written in MSVC and packed with UPX.

Symptoms

  • Presence of c:\tmp.exe
  • Detection of W32/Mimail.p@MM by on-access scanner
  • Unexpected outgoing connection to mentioned Web site

Method of Infection

Trojans do not self-replicate. This downloader only serves a purpose of retrieving and executing other malware.

Removal

All Users:
Use current engine and DAT files for detection and removal.

Modifications made to the system Registry and/or INI files for the purposes of hooking system startup, will be successfully removed if cleaning with the recommended engine and DAT combination (or higher).

Additional Windows ME/XP removal considerations

Variants

Variants

    N/A

All Information

Overview -

This is a trojan detection. Unlike viruses, trojans do not self-replicate. They are spread manually, often under the premise that they are beneficial or wanted. The most common installation methods involve system or security exploitation, and unsuspecting users manually executing unknown programs. Distribution channels include email, malicious or hacked web pages, Internet Relay Chat (IRC), peer-to-peer networks, etc.

Aliases

  • Download.Trojan (NAV)
  • TrojanDownloader.Win32.Small.cz (AVP)

Characteristics

Characteristics -

This malware is known to have been spammed on the 14th Jan 2004 via Email with the following characteristics:

From: do_not_reply@paypal.com
Subject: PAYPAL.COM NEW YEAR OFFER
Body:

** GREAT NEW YEAR OFFER FROM PAYPAL.COM **

Dear PayPal.com Member,

We here at PayPal.com are pleased to announce that we have a special New Year offer for you! If you currently have an account with PayPal then you will be eligible to receive a terrific prize from PayPal.com for the New Year. For a limited time only PayPal is offering to add 10 percent of the total balance in your PayPal account to your account and all you have to do is register yourself within the next five business days with our application (see attachment)!

If at this time you do not have a PayPal account of your own you can also register yourself with our secure application and get this great New Year bonus! If you fill out the secure form we have provided PayPal will create an account for you (it's free) and you will receive a confirmation e-mail that your account has been created.

That's not all! If you resend this letter (with its attachment) to all of your friends you may be eligible to receive another New Year bonus because the 1000 PayPal members that send the most of these to their friends will get the bonus. If you are one of these 1000 lucky members then PayPal will add 17 percent of your total balance to your account!

Registration is simple. Just unpack the attachment with WinZip, run the application, and follow the instructions we have provided. If you have problems opening the application then you may want to try downloading a free version of WinZip from http://www.winzip.com

Do not miss your chance at this fantastic opportunity! Thousands of our current customers have already received their prizes and now it's your turn; so hurry up and take advantage of this special offer!

Best of luck in the New Year,
PayPal.com Team


Attachment: PAYPAL.ZIP ( containing PAYPAL.EXE)

When run, the downloader retrieves a file from http://www.aquarium-fish.ru, saves it as "c:\tmp.exe", and executes it.

At the time of writing, the executable on the mentioned Web site was the W32/Mimail.p@MM virus (detected with the current DAT files, version 4313).

The downloader is written in MSVC and packed with UPX.

Symptoms

Symptoms -

  • Presence of c:\tmp.exe
  • Detection of W32/Mimail.p@MM by on-access scanner
  • Unexpected outgoing connection to mentioned Web site

Method of Infection

Method of Infection -

Trojans do not self-replicate. This downloader only serves a purpose of retrieving and executing other malware.

Removal -

Removal -

All Users:
Use current engine and DAT files for detection and removal.

Modifications made to the system Registry and/or INI files for the purposes of hooking system startup, will be successfully removed if cleaning with the recommended engine and DAT combination (or higher).

Additional Windows ME/XP removal considerations

Variants

Variants -

    N/A