SONBOKLI


 PLATFORM:

Windows

 OVERALL RISK RATING:
 REPORTED INFECTION:

  • Threat Type: Trojan

  • Destructiveness: No

  • Encrypted:

  • In the wild: Yes

  OVERVIEW

SONBOKLI is malware that is used to detect malicious attachments such as archive or .iso files that are used for phishing and other cyberattacks. It is a Trojan that pretends to be a normal file but can silently invade a computer and worsen the system performance.

Its current malicious spam campaign targets its victims with fake invoices, remittances and price list requests. It can also spread through porn or torrent websites, suspicious links, via peer-to-peer file sharing, and by being bundled with free programs, cracked software, fake software updates and online games.

It is capable of the following:

  • Steals personal and financial information such as bank account number, credit card credentials, login identification, passwords and Internet protocol (IP) address by using keylogger techniques

  • Opens backdoor on victim's system for other threats and cybercriminals

  • Disables antivirus and firewall security of system to stay hidden

  • Connects to remote server automatically and download harmful threats on your machine

      It typically follows the infection chain below: