VBS_POWLOAD.QBH
December 29, 2017
ALIASES:
TrojanDropper:PowerShell/Ploty.C (Microsoft), PowerShell/Rozena.AJ trojan (Norton)
PLATFORM:
Windows
OVERALL RISK RATING:
DAMAGE POTENTIAL:
REPORTED INFECTION:
SYSTEM IMPACT RATING:

Threat Type: Trojan
Destructiveness: No
Encrypted:
In the wild: Yes
OVERVIEW
This Trojan arrives on a system as a file dropped by other malware or as a file downloaded unknowingly by users when visiting malicious sites. It may be hosted on a website and run when a user accesses the said website.
TECHNICAL DETAILS
File Size:
6544 bytes
File Type:
HTA
Initial Samples Received Date:
26 Dec 2017
Arrival Details
This Trojan arrives on a system as a file dropped by other malware or as a file downloaded unknowingly by users when visiting malicious sites.
It may be hosted on a website and run when a user accesses the said website.
Download Routine
This Trojan saves the files it downloads using the following names:
- {Malware Path}\svchost.exe
- {Malware Path}\svhost.exe
- {Malware Path}\svthost.exe
Other Details
This Trojan connects to the following possibly malicious URL:
- http://dazqc4{BLOCKED}l.clou{BLOCKED}ront.net/p9kH
- http://block{BLOCKED}oin.com/s/ref=nb_sb_noss_1/167-329{BLOCKED}49/field-keywords=books