Trojan-Downloader:W32/Small.EJK

Threat description

Details

Category: Malware
Type: Trojan-Downloader
Platform: W32

Summary

Small.EJK is a trojan-downloader that is included in a spam run in Germany.



Removal

Automatic action

Depending on the settings of your F-Secure security product, it will either automatically delete, quarantine or rename the suspect file, or ask you for a desired action.

More scanning & removal options

More information on the scanning and removal options available in your F-Secure product can be found in the Help Center.

You may also refer to the Knowledge Base on the F-Secure Community site for more information.

Contact Support

F-Secure customers can request support online via the Request support or the Chat forms on our Home - Global site.



Technical Details

Small.EJK is a trojan-downloader that is included in a spam run in Germany.A sample mail is as follows:

Upon execution, it downloads a trojan-spy from a remote addresses on the web using the following script:

  • http://81.95.147.138/[REMOVED]/get_exe.php
  • http://marketing-know-how.com/[REMOVED]/get_exe.php
  • http://tncmhg.com/images/[REMOVED]/get_exe.php
  • http://www.eurowing.us/[REMOVED]/get_exe.php
  • http://www.thaitradeshow.com/images/[REMOVED]/get_exe.php

An earlier version of the downloaded trojan was detected as Trojan-Spy.Win32.BZub.IJ. This was later changed/modified most probably by the author(s). The updated copy is now detected as Trojan-Spy:W32/BZub.IK.






SUBMIT A SAMPLE

Suspect a file or URL was wrongly detected? Submit a sample to our Labs for analysis

Submit Sample

Give And Get Advice

Give advice. Get advice. Share the knowledge on our free discussion forum.

Learn More