Threat Database Worms W32.Phopifas

W32.Phopifas

By Sumo3000 in Worms

Threat Scorecard

Ranking: 14,342
Threat Level: 50 % (Medium)
Infected Computers: 14
First Seen: October 10, 2012
Last Seen: August 4, 2023
OS(es) Affected: Windows

W32.Phopifas Image

W32.Phopifas is a worm that proliferates through Skype and Windows Live Messenger. When run, W32.Phopifas sends one of the numerous messages, which depends on the locale setting on the corrupted computer, to all contacts in Skype and Windows Live Messenger. The message also carries the link [http://]goo.gl/[REMOVED]sx?img=[USER ID], where [USER ID] is the Skype/Windows Live Messenger user ID. The link drops either a copy of W32.Phopifas or W32.IRCBot.NG

Aliases

15 security vendors flagged this file as malicious.

Anti-Virus Software Detection
Panda Trj/OCJ.A
AVG Dropper.Generic6.CFUF
AhnLab-V3 Win-Trojan/Agent.26624.TW
Microsoft Worm:Win32/Floppier.A
Sophos W32/Rodpicom-B
AntiVir TR/Buzus.IF
DrWeb Trojan.Spamlink.1
Kaspersky Trojan.Win32.Yakes.bgjm
eSafe Win32.Trojan
Avast Win32:Injector-AVB [Trj]
K7AntiVirus Riskware
CAT-QuickHeal Worm.Floppier
Panda Trj/CI.A
Fortinet W32/Rodpicom.A
Ikarus Win32.SuspectCrc

URLs

W32.Phopifas may call the following URLs:

search.rktz9.com

Trending

Most Viewed

Loading...