TROJ_DORV.BZZH
October 07, 2016
ALIASES:
Trojan.Win32.Inject.abjtm (Kaspersky), W32.Hinired (Symantec)
PLATFORM:
Windows
OVERALL RISK RATING:
REPORTED INFECTION:

Threat Type: Trojan
Destructiveness: No
Encrypted:
In the wild: Yes
OVERVIEW
Infection Channel: Dropped by other malware
This Trojan may be dropped by other malware.
However, as of this writing, the said sites are inaccessible.
TECHNICAL DETAILS
File Size: 34,816 bytes
File Type: EXE
Memory Resident: No
Initial Samples Received Date: 07 Oct 2016
Payload: Connects to URLs/IPs
Arrival Details
This Trojan may be dropped by the following malware:
- W2KM_FAREIT.YYSVX
Installation
This Trojan injects codes into the following process(es):
- svchost.exe
- explorer.exe
Other Details
This Trojan connects to the following possibly malicious URL:
- http://{BLOCKED}nfortfa.com:80/h/gate.php
- http://{BLOCKED}moof.ru:80/h/gate.php
- http://{BLOCKED}entinve.ru:80/h/gate.php
However, as of this writing, the said sites are inaccessible.