Trojan.X97M.QAKBOT.HAKI
October 22, 2021
TrojanDownloader:O97M/Qakbot.STC!MTB (MICROSOFT)
Plate-forme:
Windows
Overall Risk:
Dommages potentiels: :
Distribution potentielle: :
reportedInfection:
Information Exposure Rating::
Faible
Medium
Élevé
Critique
Type de grayware:
Trojan
Destructif:
Non
Chiffrement:
In the wild::
Oui
Overview
It arrives on a system as a file dropped by other malware or as a file downloaded unknowingly by users when visiting malicious sites.
Détails techniques
File size: 555,520 bytes
File type: XLS
Memory resident: Non
Date de réception des premiers échantillons: 21 octobre 2021
Übertragungsdetails
It arrives on a system as a file dropped by other malware or as a file downloaded unknowingly by users when visiting malicious sites.
Installation
Fügt die folgenden Prozesse hinzu:
- regsvr32 -silent ..\Celod.wac
- regsvr32 -silent ..\Celod.wac1
- regsvr32 -silent ..\Celod.wac2
Andere Details
It connects to the following possibly malicious URL:
- http://{BLOCKED}.{BLOCKED}.37.236/44490.{Random Numbers}.dat
- http://{BLOCKED}.{BLOCKED}.90.73/44490.{Random Numbers}.dat
- http://{BLOCKED}.{BLOCKED}.191.16/44490.{Random Numbers}.dat