Trojan.XF.FORMULOAD.UFUT
December 09, 2021
TrojanDownloader:O97M/Dridex.PMSK!MTB (MICROSOFT)
Plate-forme:
Windows
Overall Risk:
Dommages potentiels: :
Distribution potentielle: :
reportedInfection:
Information Exposure Rating::
Faible
Medium
Élevé
Critique
Type de grayware:
Trojan
Destructif:
Non
Chiffrement:
In the wild::
Oui
Overview
It arrives on a system as a file dropped by other malware or as a file downloaded unknowingly by users when visiting malicious sites.
Détails techniques
File size: 76,561 bytes
File type: XLS, Other
Memory resident: Oui
Date de réception des premiers échantillons: 18 novembre 2021
Übertragungsdetails
It arrives on a system as a file dropped by other malware or as a file downloaded unknowingly by users when visiting malicious sites.
Installation
Schleust die folgenden Dateien ein:
- %ProgramData%\fjkdgjknfdgfjkdgjknfdg.rtf
- %ProgramData%\api-ms-win-crt-stdio-l1-1-0.mp4
Fügt die folgenden Prozesse hinzu:
- wmic.exe process call create 'mshta %ProgramData%\fjkdgjknfdgfjkdgjknfdg.rtf'
- wmic process call create "rundll32.exe %ProgramData%\api-ms-win-crt-stdio-l1-1-0.mp4 LZDone"
Andere Details
It connects to the following possibly malicious URL:
- https://cdn.{BLOCKED}app.com/attachments/910212171147915317/910550967668310016/WxDPscgHItkfTniggerjewhitler.mp4
- https://cdn.{BLOCKED}app.com/attachments/910212171147915317/910550751456149534/JvqwnnQpTQVAyniggerjewhitler.mp4
- https://cdn.{BLOCKED}app.com/attachments/910212171147915317/910550529279655966/qcAWeDaQPniggerjewhitler.mp4