Threat Database Trojan Downloader Gen:Variant.Downloader.167

Gen:Variant.Downloader.167

By GoldSparrow in Trojan Downloader

Threat Scorecard

Popularity Rank: 12,897
Threat Level: 90 % (High)
Infected Computers: 102
First Seen: May 29, 2014
Last Seen: August 7, 2026
OS(es) Affected: Windows

The Gen:Variant.Downloader.167 Trojan has caught the attention of PC security analysts, not least because Gen:Variant.Downloader.167 includes a bible quote in its attack. Gen:Variant.Downloader.167 is distributed using IM (Instant Messaging) platforms such as Yahoo and the Facebook chat. Malware analysts have detected Gen:Variant.Downloader.167 attacks throughout Europe in the last few weeks and, more recently, in the United States and Canada. Gen:Variant.Downloader.167 is disguised as an instant message from an online contact inviting the computer user to download an application to view certain pictures. This supposed application contains threatening code that compromises the victim's computer and attempts to spread to the victim's online contacts. Gen:Variant.Downloader.167 affects computers using the Windows operating system and uses instant messaging platforms to spread from one victim to another.

The Unique Characteristics of Gen:Variant.Downloader.167

One particularly unusual feature of Gen:Variant.Downloader.167 is that Gen:Variant.Downloader.167 uses verses from the bible as the decryption keys for Gen:Variant.Downloader.167's data. So far, Gen:Variant.Downloader.167 uses verses from the first epistle of Paul to the Corinthians, hiding its data between Bible verses and using an encryption algorithm. This is a curious feature that does not seem to be present in other threats, although it may not mean anything. PC security analysts believe that Gen:Variant.Downloader.167 is used to generating money from collected information and distribution of other threats.

How Third Parties may Profit from Gen:Variant.Downloader.167

The main goal of a Gen:Variant.Downloader.167 infection is to profit by gathering information that may be sold to a third party. Gen:Variant.Downloader.167 or threats associated with Gen:Variant.Downloader.167 may gather information such as online banking data or online passwords. This data is transmitted to a third party and then may be sold to ill-minded persons for use in online hoaxes and identity theft. These types of tactics pop up regularly on Facebook. In 2013, there was a widely distributed threat infection that also spread through Facebook using instant messages promising naked pictures to the victim's Facebook contacts. Computer users should be educated to spot these types of obvious deceiving tactics to avoid infecting their computers through threatening links spread using social engineering.

Analysis Report

General information

Family Name: Trojan.Upatre.WV
Signature status: No Signature

Known Samples

MD5: ab1f626c7cf7f99b33db2185b945a7c2
SHA1: 34457f997b70181fe327b4be771d9eb902dbaf20
SHA256: 37CBD035036BDA1F1372EAFE73FC14AE244F124C4F389A51368F93298D186193
File Size: 17.99 KB, 17994 bytes

Windows Portable Executable Attributes

  • File doesn't have "Rich" header
  • File doesn't have debug information
  • File doesn't have exports table
  • File doesn't have resources
  • File doesn't have security information
  • File is 32-bit executable
  • File is either console or GUI application
  • File is GUI application (IMAGE_SUBSYSTEM_WINDOWS_GUI)
  • File is Native application (NOT .NET application)
  • File is not packed
Show More
  • IMAGE_FILE_DLL is not set inside PE header (Executable)
  • IMAGE_FILE_EXECUTABLE_IMAGE is set inside PE header (Executable Image)

File Traits

  • 2+ executable sections
  • No Version Info
  • x86

Block Information

Total Blocks: 3
Potentially Malicious Blocks: 1
Whitelisted Blocks: 1
Unknown Blocks: 1

Visual Map

x 2 ?
0 - Probable Safe Block
? - Unknown Block
x - Potentially Malicious Block