TROJ_SOCELARS.A
W32/Socelars.K!tr.spy (Fortinet); Trojan:Win32/Occamy.C (Microsoft)
Windows


Threat Type: Trojan
Destructiveness: No
Encrypted:
In the wild: Yes
OVERVIEW
This Trojan arrives on a system as a file dropped by other malware or as a file downloaded unknowingly by users when visiting malicious sites.
TECHNICAL DETAILS
Arrival Details
This Trojan arrives on a system as a file dropped by other malware or as a file downloaded unknowingly by users when visiting malicious sites.
Other System Modifications
This Trojan adds the following registry entries:
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\
Windows NT\CurrentVersion\Svchost
MicroServiceGroup = MicroService
HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\
services\MicroService
Description = MicroService
HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\
services\MicroService\Parameters
ServiceDll = {malware path}\{malware name}.dll
