Skip to main content

Goldun.CW

Classification

Category:

Malware

Type:

Trojan-spy

Aliases:

  • Goldun.CW
  • Trojan-Spy.Win32.Goldun.cw

Summary

Goldun.CW is a trojan downloader that attempts to secretly download and execute a file from a malicious website.

See the Details section for more information.

Removal

Technical Details

Goldun.CW comes as an FSG packed EXE file. It creates and opens the following Bitmap file to hide its original intent:

Note: This image is saved in the default Temporary folder as screen.bmp.

Goldun.CW drops the following UPX-compressed DLL file on Windows System folder:

  • %systemdir%\mscods.dll

Note: %systemdir% by default is C:\Windows\system32.

The DLL file is installed as a Browser Helper Object (BHO) so that when ever an Internet Explorer session is started, the DLL will also execute. It does this by creating the following Registry keys:

  • [HKCR\CLSID\{45357971-2534-8760-3685-423479197575}]
  • [HKLM\SOFTWARE\Classes\CLSID\{45357971-2534-8760-3685-423479197575}]

The DLL will connect, download, and execute the file from the following URL:

  • https://everythingdiscounted.biz/store/images/extras/[REMOVED].jpg

The said URL is ecncrypted on the malware's body using a simple XOR routine.

It then drops a file named vbrs.bat into the default Temporary folder in order to delete the EXE file and the BAT file itself. This is done just to clean up some of the disorder created.

Protect your devices from malware with F‑Secure Total

Protecting your devices from malicious software is essential for maintaining online security. F‑Secure Total makes this easy, helping you to secure your devices in a brilliantly simple way.

  • Award‑winning antivirus and malware protection

  • Online browsing, banking, and shopping protection

  • 24/7 online identity and data breach monitoring

  • Unlimited VPN service to safe­guard your privacy

  • Password manager with private data protection

Choose how many devices you want to protect to get started.

  • Free customer support

  • Cancel anytime

  • The trial does not obligate you to buy the product

After 30 days your subscription will renew automatically for one year at €69.99.

More Support

Community

Ask questions in our Community.

User guides

Check the user guide for instructions.

Contact Support

Chat with with or call an agent.

Submit a Sample

Submit a file or URL for analysis.