Content
Downloader-AXM
- Type
- Trojan
- SubType
- Downloader
- Discovery Date
- 07/25/2006
- Length
- Varies
- Minimum DAT
- 4814 (07/25/2006)
- Updated DAT
- 4956 (02/05/2007)
- Minimum Engine
- 5.1.00
- Description Added
- 07/25/2006
- Description Modified
- 04/03/2007 1:28 PM (PT)
Risk Assessment
- Corporate User
- Low-Profiled
- Home User
- Low-Profiled
Tab Navigation
Characteristics
-- Update September 24, 2006 --
A new series of spam containing hyperlinks and file attachments that installs Downloader-AXM was discovered recently. These Downloader-AXM variants can be proactively detected as New Win32.g2. These spam may appear as one of the following e-mail(s):
|
From: (random)<RANDOM> Kylie Minogue is dead. File Attachment: lastwords.zip |
|
From: "VISA TechSupport" <TECHSUPPORT@VISA.COM.AU>
This message has been sent to you by Visa Security Program. You've specified this e-mail as reachable with your credit card online transaction (your credit card details are not shown here for security reasons). If you believe there was a mistake please report this to Verified by Visa. Regards File Attachment: TT_2846583.zip |
-- Update July 25, 2006 --
The risk assessment of this threat has been updated to Low-Profiled due to media attention at:
http://www.techweb.com/wire/security/191101268;jsessionid=ZSIPNB4RIMFWUQSNDLOSKH0CJUNN2JVN
Though we consider this a low threat, An EXTRA.DAT file may be downloaded via the McAfee AVERT Extra.dat Request Page: <https://www.webimmune.net/extra/getextra.aspx>
Additionally, a repackaged version of this trojan was mass-spammed on July 25, 2006. Message content is the same as the initial spamming. Detection for this version is included in the 4815 DAT files (release date July 26, 2006).
--
This trojan was mass-spammed on July 24, 2006 in a message as follows:
|
From: billing support [mailto:info@walmart.com] Dear Sir/Madam, Attachment: wc2905036.exe |
When executed, the trojan creates and executes a thread in the Windows Explorer (explorer.exe) process, and terminates. The trojan executes in the memory space of Windows Explorer from there on.
Connections are made to to a web server hosted at IP address 81.95.xx.xx to download other malware. At the time of writing, FormSpy was downloaded and installed into the victim's machine.
Symptoms
HTTP connections made from the Windows Explorer process to the following IP address(es):
- 81.95.xx.xx
Method of Infection
Downloaders are not viruses, and as such do not themselves contain any method to replicate. However they may themselves be downloaded by other viruses and/or Trojans to be installed on the user's system.
Many of these additionally are mass spammed by the author to entice people into double-clicking on them.
Alternatively they may be installed by visiting a malicious web page (either by clicking on a link, or by the website hosting a scripted exploit which installs the Downloader onto the user's system with no user interaction.
Removal
AVERT recommends to always use latest DATs and engine. This threat will be cleaned if you have this combination.
Variants
Variants
N/A
All Information
Overview -
This initial spamming of this trojan was proactively detected from the wild as New Malware.ag with email scanning products.
Downloader serves as a downloading/updating component for other malicious files. Generally it makes Internet connectons without user's knowledge and downloads malicious contents.
Aliases
- Trj/Spyforms.H (Panda)
- Trojan-PSW.Win32.Small.bs (Kaspersky)
- TSPY_SMALL.EEW (Trend)
- W32/Gozi.A (Normal)
- Win32/Ursnif.AG (CA)
Characteristics
Characteristics -
-- Update September 24, 2006 --
A new series of spam containing hyperlinks and file attachments that installs Downloader-AXM was discovered recently. These Downloader-AXM variants can be proactively detected as New Win32.g2. These spam may appear as one of the following e-mail(s):
|
From: (random)<RANDOM> Kylie Minogue is dead. File Attachment: lastwords.zip |
|
From: "VISA TechSupport" <TECHSUPPORT@VISA.COM.AU>
This message has been sent to you by Visa Security Program. You've specified this e-mail as reachable with your credit card online transaction (your credit card details are not shown here for security reasons). If you believe there was a mistake please report this to Verified by Visa. Regards File Attachment: TT_2846583.zip |
-- Update July 25, 2006 --
The risk assessment of this threat has been updated to Low-Profiled due to media attention at:
http://www.techweb.com/wire/security/191101268;jsessionid=ZSIPNB4RIMFWUQSNDLOSKH0CJUNN2JVN
Though we consider this a low threat, An EXTRA.DAT file may be downloaded via the McAfee AVERT Extra.dat Request Page: <https://www.webimmune.net/extra/getextra.aspx>
Additionally, a repackaged version of this trojan was mass-spammed on July 25, 2006. Message content is the same as the initial spamming. Detection for this version is included in the 4815 DAT files (release date July 26, 2006).
--
This trojan was mass-spammed on July 24, 2006 in a message as follows:
|
From: billing support [mailto:info@walmart.com] Dear Sir/Madam, Attachment: wc2905036.exe |
When executed, the trojan creates and executes a thread in the Windows Explorer (explorer.exe) process, and terminates. The trojan executes in the memory space of Windows Explorer from there on.
Connections are made to to a web server hosted at IP address 81.95.xx.xx to download other malware. At the time of writing, FormSpy was downloaded and installed into the victim's machine.
Symptoms
Symptoms -
HTTP connections made from the Windows Explorer process to the following IP address(es):
- 81.95.xx.xx
Method of Infection
Method of Infection -
Downloaders are not viruses, and as such do not themselves contain any method to replicate. However they may themselves be downloaded by other viruses and/or Trojans to be installed on the user's system.
Many of these additionally are mass spammed by the author to entice people into double-clicking on them.
Alternatively they may be installed by visiting a malicious web page (either by clicking on a link, or by the website hosting a scripted exploit which installs the Downloader onto the user's system with no user interaction.
Removal -
Removal -
AVERT recommends to always use latest DATs and engine. This threat will be cleaned if you have this combination.
Additional Windows ME/XP removal considerations
Variants
Variants -
N/A