W2KM_POWLOAD.ASULBV
November 16, 2017
ALIASES:
TrojanDownloader:O97M/Donoff (Microsoft); W97M.Downloader (Symantec)
PLATFORM:
Windows
OVERALL RISK RATING:
DAMAGE POTENTIAL:
DISTRIBUTION POTENTIAL:
REPORTED INFECTION:
INFORMATION EXPOSURE:

Threat Type: Trojan
Destructiveness: No
Encrypted:
In the wild: Yes
OVERVIEW
This Trojan arrives as an attachment to email messages spammed by other malware/grayware or malicious users.
However, as of this writing, the said sites are inaccessible.
TECHNICAL DETAILS
File Size: 92,672 bytes
Initial Samples Received Date: 09 Nov 2017
Arrival Details
This Trojan arrives as an attachment to email messages spammed by other malware/grayware or malicious users.
Download Routine
This Trojan saves the files it downloads using the following names:
- C:\Users\Public\{6 Random Numbers}.exe
Other Details
This Trojan connects to the following possibly malicious URL:
- http://{BLOCKED}t-britv.ru/UamuKMpu
It does the following:
- It executes the downloaded code from the URL using powershell.
However, as of this writing, the said sites are inaccessible.