Associated Malware Groups
The filename is associated with the malware group:
File Behavior
GOLDENTIGER[n].EXE has been seen to perform the following behavior:
- This process creates other processes on disk
- This Process is a file infector which modifies program files to include a copy of the infection
- Reads email address and phone book details
- Visits web sites on your PC without you knowing
- Can communicate with other computer systems using HTTP protocols
- This Process Deletes Other Processes From Disk
- Executes a Process
- Writes to another Process's Virtual Memory (Process Hijacking)
- Executes Processes stored in Temporary Folders
- Adds products to the system registry
- Enables an In Process Object/Server - Common with DLL Injections
- Deletes an ActiveX component
- Adds an ActiveX component changing or modifying the function of your browser
- The process hooks code into all running processes which could allow it to take control of the system or record keyboard input, mouse activity and screen contents
- Found on infected systems and resists interrogation by security products
GOLDENTIGER[n].EXE has been the subject of the following behavior:
- Executed as a Process
- Registered as a Dynamic Link Library File
- Created as a process on disk
- Executed by Internet Explorer
- Has code inserted into its Virtual Memory space by other programs
- Executed from Temporary Folders
- Deleted as a process from disk
Country Of Origin
The filename GOLDENTIGER[n].EXE was first seen on Aug 5 2008 in the following geographical regions of the Prevx community:
- Europe on Aug 5 2008
- France on Aug 5 2008
- Italy on Aug 14 2008
- Netherlands on Jul 14 2009
- Canada on Jul 14 2009
File Name Aliases
GOLDENTIGER[n].EXE can also use the following file names:
- INSTALL.EXE
- GOL267.TMP
- GOL29D.TMP
- GOLDENTIGER.EXE
- GOLDENTIGER(n).EXE
- DOWNLOAD[n].EXE
- TOMB RAIDER - MULTIPLE COIN VIDEO SLOT.EXE
- VIDEO BONUS SLOTS.EXE
- ROULETTE GAMES (AMERICAN, EUROPEAN AND FRENCH).EXE
- BLACKJACK - SINGLE AND MULTI-HAND.EXE
- PARLOUR AND TABLE GAMES.EXE
- PROGRESSIVE JACKPOT GAMES.EXE
- Z GAMBLING GAMES.EXE
- GOLEA74.TMP
- GOLDENTIGER[1].EXE
- DI5.EXE
- DI7.EXE
- DI9.EXE
- DI11.EXE
- DI8.EXE
- DD1.EXE
- DD2.EXE
- DD3.EXE
- DD4.EXE
- DE6.EXE
- DE7.EXE
- DE8.EXE
- DE9.EXE
- DE10.EXE
- DI1.EXE
- DI2.EXE
- DI3.EXE
- DI4.EXE
- DI6.EXE
- DD5.EXE
- DD6.EXE
- DD7.EXE
- DE1.EXE
- DE2.EXE
- DE3.EXE
- DE4.EXE
- DE5.EXE
- DI10.EXE
- DI12.EXE
- DI13.EXE
Filesizes
The following file size has been seen:
- 416,112 bytes
- 462,064 bytes
- 462,480 bytes
- 416,976 bytes
File Type
The filename GOLDENTIGER[n].EXE refers to many versions of an executable program.
Website Activity
One or more files with the name GOLDENTIGER[n].EXE interacts with the following web sites and pages. Web addresses have been deliberately modified to prevent unintentional use.
- Remote server connection to goldentiger .mgsmup .co
- TCP:127.0.0.1:1084 Port:21
- TCP:66.212.246.111:443 Port:19
- Port 80 IP:91.206.144.32
- Port 80 IP:66.212.236.118
PCMag.com Editors' Choice Award Logo is a trademark of Ziff Davis Publishing Holdings Inc. Used under license.