TROJ_CRYPLOD.SVG
Trojan-Downloader.JS.Agent.hfh (Kaspersky); JS/Redirector.by (McAfee); JS/Agent.HFH!tr.dldr (Fortinet); TrojanDownloader:JS/Tgouex.A (Microsoft)
Windows

Threat Type: Trojan
Destructiveness: No
Encrypted:
In the wild: Yes
OVERVIEW
This Trojan arrives as attachment to mass-mailed email messages. It arrives on a system as a file dropped by other malware or as a file downloaded unknowingly by users when visiting malicious sites.
However, as of this writing, the said sites are inaccessible.
TECHNICAL DETAILS
Arrival Details
This Trojan arrives as attachment to mass-mailed email messages.
It arrives on a system as a file dropped by other malware or as a file downloaded unknowingly by users when visiting malicious sites.
Other Details
This Trojan connects to the following possibly malicious URL:
- http://www.{BLOCKED}nnovationshow.com/wp-conf/123.zip
However, as of this writing, the said sites are inaccessible.