Threat Description

Trojan-Downloader: W32/Mebroot.gen!B

Details

Category: Malware
Type: Trojan-Downloader
Platform: W32
Aliases: Trojan-Downloader:W32/Mebroot.gen!B

Summary


Trojan-Downloader:W32/Mebroot.gen!B is a Generic Detection that identifies the downloader program responsible for fetching the installer for the Mebroot rootkit.



Removal


Automatic action

Once detected, the F-Secure security product will automatically disinfect the suspect file by either deleting it or renaming it.

More scanning & removal options

More information on scanning or removal options is available in the documentation for your F-Secure security product on the Downloads section of our Home - Global site.

You may also refer to the Knowledge Base on the F-Secure Community site for more information.

Contact Support

For further assistance, F-Secure customers can request support online via the Request support or the Chat forms on our Home - Global site.



Technical Details


This malware is discussed in further detail in the following Labs Weblog posts:

The downloader is known to be distributed to users via a malicious website (driveby download) or via an exploit.

Activity

When active, the downloader downloads an encrypted file on port 443 or 80 from:

  • http://bcoxgcgxes.com (encrypted file)

where (encrypted file) is a defined string. This string is unique in every sample.

Once downloaded, the encrypted file is first saved in an allocated memory where it will be decrypted, then saved to a file in a temporary folder. The file will then be executed.

The encrypted file is encrypted with an RC2 encryption algorithm. The Cipher Hash that is used in the decryption is based on a defined string that is also unique in every sample.






SUBMIT A SAMPLE

Suspect a file or URL was wrongly detected? Submit a sample to our Labs for analysis

Submit Now

Give And Get Advice

Give advice. Get advice. Share the knowledge on our free discussion forum.

Learn More