Threat Description

Trojan-Downloader:W32/Small.EJK

Details

Aliases: Trojan-Downloader:W32/Small.EJK
Category: Malware
Type: Trojan-Downloader
Platform: W32

Summary


Small.EJK is a trojan-downloader that is included in a spam run in Germany.



Removal


Automatic action

Once detected, the F-Secure security product will automatically disinfect the suspect file by either deleting it or renaming it.

More

Detailed instructions for F-Secure security products are available in the documentation found in the Downloads section of our Home - Global site.

You may also refer to the Knowledge Base on the F-Secure Community site for further assistance.



Technical Details


Small.EJK is a trojan-downloader that is included in a spam run in Germany.A sample mail is as follows:

Upon execution, it downloads a trojan-spy from a remote addresses on the web using the following script:

  • http://81.95.147.138/[REMOVED]/get_exe.php
  • http://marketing-know-how.com/[REMOVED]/get_exe.php
  • http://tncmhg.com/images/[REMOVED]/get_exe.php
  • http://www.eurowing.us/[REMOVED]/get_exe.php
  • http://www.thaitradeshow.com/images/[REMOVED]/get_exe.php

An earlier version of the downloaded trojan was detected as Trojan-Spy.Win32.BZub.IJ. This was later changed/modified most probably by the author(s). The updated copy is now detected as Trojan-Spy:W32/BZub.IK.






SUBMIT A SAMPLE

Suspect a file or URL was wrongly detected? Submit a sample to our Labs for analysis

Submit Now

Give And Get Advice

Give advice. Get advice. Share the knowledge on our free discussion forum.

Learn More