Win32/Oficla [Threat Name] go to Threat

Win32/Oficla.GN [Threat Variant Name]

Category trojan
Size 34304 B
Aliases Trojan-Downloader.Win32.Piker.cgd (Kaspersky)
  Win32:MalOb-AR (Avast)
  TrojanDropper:Win32/Oficla.G (Microsoft)
Short description

Win32/Oficla.GN is a trojan which tries to download other malware from the Internet.

Installation

When executed, the trojan creates the following files:

  • %system%\­thxr.wgo (19968 B)
  • %temp%\­%variable1%.tmp (19968 B)

A string with variable content is used instead of %variable1% .


In order to be executed on every system start, the trojan sets the following Registry entry:

  • [HKEY_LOCAL_MACHINE\­SOFTWARE\­Microsoft\­Windows NT\­CurrentVersion\­Winlogon]
    • "Shell" = "* rundll32.exe thxr.wgo nwfdtx"

The following Registry entries are set:

  • [HKEY_CLASSES_ROOT\­idid]
    • "op" = %variable2%
    • "url%variable3%" = %variable4%

A string with variable content is used instead of *, %variable2-4% .

Other information

The trojan acquires data and commands from a remote computer or the Internet.


The trojan contains a list of (1) URLs. The HTTP protocol is used.


It can execute the following operations:

  • download files from a remote computer and/or the Internet
  • run executable files

The trojan may create the following files:

  • %temp%\­%variable5%.tmp

A string with variable content is used instead of %variable5% .


Please enable Javascript to ensure correct displaying of this content and refresh this page.