1. Skip to navigation
  2. Skip to content
  3. Skip to secondary-content




Trojan-Downloader:W32/Wimad.gen!A

Name : Trojan-Downloader:W32/Wimad.gen!A
Detection Names : Trojan.Downloader.WMA.Wimad
Aliases : Trojan.Wimad (Symantec)
Category:Malware
Type:Trojan-Downloader
Platform:W32

Summary

A trojan that secretly downloads malicious files from a remote server, then installs and executes the files.

Additional Details

Trojan-Downloader:W32/Wimad.gen!A is a Generic Detection for malicious files that are executed using Windows Media Player (WMP). The files may use any extension that can be recognized and executed by WMP, such as MP3 or WMA.

When executing with Windows Media Player, the malicious file will attempt to make a connection to a URL in the web browser. Some  URLs the malware attempt to open are:

  •  http://www.fastmp3player.com/affiliates/[...]/2/?embedded=false  - down
  •  http://www.fastmp3player.com/affiliates/[...]/1/?embedded=false  - down
  •  http://isvbr.net/[...]=false   - down

These URLs lead to webpages hosting malicious files, which may be downloaded and executed by an unsuspecting user.


About Generic Detections

Unlike signature or single-file detections, a Generic Detection does not identify a unique or individual malicious program. Instead, a Generic Detection looks for broadly applicable code or behavior characteristics that indicate a file as potentially malicious, so that a single Generic Detection can efficiently identify dozens, or even hundreds of malware.

For more information about Generic Detections, see the Generic Detection description.