Trojan-Downloader.Win32.Stubby.d

tag:Trojan   Downloaders  

0 0

This Trojan program will download other malicious programs via the Internet without the user's knowledge or consent.

The Trojan itself is a Windows PE EXE file 26624 bytes in size, packed using ASPack. The unpacked file is approximately 46KB in size.

Once launched, the Trojan registers itself in the system registry, ensuring that the Trojan will be launched each time Windows is rebooted on the victim machine:

[HKLM\Software\Microsoft\Windows\CurrentVersion\Run]
"satmat" = "≶path to Trojan>"

The Trojan will download another Trojan program from the following address:

http://download.abet*********et.com/download/stmtreco/

It saves this program on the victim machine and launches it for execution.

©Virus-Encyclopedia.com All Rights Reserved.