VBS_DLOADR.UASE
November 09, 2016
ALIASES:
(Microsoft) Trojan:VBS/Donvibs
PLATFORM:
Windows
OVERALL RISK RATING:
DAMAGE POTENTIAL:
DISTRIBUTION POTENTIAL:
REPORTED INFECTION:
INFORMATION EXPOSURE:
Threat Type: Trojan
Destructiveness: No
Encrypted: Yes
In the wild: Yes
OVERVIEW
This Trojan arrives on a system as a file dropped by other malware or as a file downloaded unknowingly by users when visiting malicious sites.
TECHNICAL DETAILS
File Size:
4,280 bytes
File Type:
VBS
Memory Resident:
Yes
Initial Samples Received Date:
13 Oct 2016
Arrival Details
This Trojan arrives on a system as a file dropped by other malware or as a file downloaded unknowingly by users when visiting malicious sites.
Backdoor Routine
As of this writing, the said sites are inaccessible.
Other Details
This Trojan connects to the following possibly malicious URL:
- http://{BLOCKED}ouri.fr/data.dpg
- http://www.{BLOCKED}-partners.fr/data.dpg