Additional Details
This malware uses an Icon of an Image file.
Upon execution, this malware connects, downloads, and executes a file from the follwing websites:
- http://bedtrader.com/tmp/fotos/[REMOVED]/verao1.scr
Detected as Trojan-Spy.Win32.Banker.axc.
- http://snwn.lss.gov.cn/img/fotos/[REMOVED]/verao1.scr
Detected as Trojan-Spy.Win32.Banker.av.