Jump to content

Dropper (malware)

From Wikipedia, the free encyclopedia

This is an old revision of this page, as edited by 138.162.5.12 (talk) at 13:59, 8 January 2007. The present address (URL) is a permanent link to this revision, which may differ significantly from the current revision.

A Dropper is a program that has been designed or modified to "install" some sort of malware (virus, backdoor, etc) onto the target system. The malware code can be contained within the Dropper (single stage) in such a way as to avoid detection by virus scanners or the Dropper may download the malware to the target machine once activated (two stage).

There are two major types of Droppers, Those that do not require user interaction which perform through the exploitation of a system by some vulnerability and those that require user interaction by convincing the user that it is some legitimate or benign program. A Dropper which installs a malware program to memory only is sometimes called an "injector".


Examples

  • YAB: Yet Another Binder

So far, all that people can find on Dropper's is a "Malware" signature on the dropper itself. Finding where the virus it has planted is another thing.