Skip to main content

Trojan-Downloader:W32/Oficla

Classification

Category:

Malware

Type:

Trojan-downloader

Aliases:

  • Oficla
  • Trojan.Sasfis (Symantec)
  • w32_sasfis.e259!tr (Other)

Summary

This type of trojan secretly downloads malicious files from a remote server, then installs and executes the files.

Removal

Technical Details

Trojan-Downloader:W32/Oficla identifies a family of malware that are distributed as attachments to fake email messages.

On installation, the trojan-downloader connects to a remote server and downloads additional files (which are mostly malicious) onto the system. The specific files downloaded will vary depending on the variant.

A representative example of Oficla variant is:

Distribution

Oficla variants are distributed as executable or zipped files attached to misleading email messages. Some of the most common messages used to deliver this trojan involve fake offers for iTunes Gift certificates or for Amazon.com orders, UPS invoice other attachments are disguised as resumes.

The text in the email message entices the unsuspecting user to open the attached executable; Oficla's actual malicious code is packed (using a custome packer) in a DLL file secretly embedded in the executable file.

Installation

Once the attached executable file is launched by the user, it will extract the DLL file into the Windows temporary folder.

The DLL file is saved, usually with the 1.tmp filename:

  • %Temp%\1.tmp

During installation, the 1.tmp file will be executed and injected to a normal process. Subsequently, when running under the normal process it will create a file in the Windows system folder.

The created file uses a somewhat non-standrd extension file, for example:

  • %windir%\system32\fjof.sto

Note: The filename and extension name may change from variant to variant.

Registry Changes

In order for it to automatically start on restart, it modifies the registry:

  • HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon Shell = Explorer.exe

to

  • HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon Shell = Explorer.exe rundll32.exe [Oficla_dll file] ["parameter"]

Example of a modified registry entry:

  • HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon Shell = Explorer.exe rundll32.exe fjof.sto vffwd

Protect your devices from malware with F‑Secure Total

Protecting your devices from malicious software is essential for maintaining online security. F‑Secure Total makes this easy, helping you to secure your devices in a brilliantly simple way.

  • Award‑winning antivirus and malware protection

  • Online browsing, banking, and shopping protection

  • 24/7 online identity and data breach monitoring

  • Unlimited VPN service to safe­guard your privacy

  • Password manager with private data protection

Choose how many devices you want to protect to get started.

  • Free customer support

  • Cancel anytime

  • The trial does not obligate you to buy the product

After 30 days your subscription will renew automatically for one year at €69.99.

More Support

Community

Ask questions in our Community.

User guides

Check the user guide for instructions.

Contact Support

Chat with with or call an agent.

Submit a Sample

Submit a file or URL for analysis.