Trojan.Win32.NOON.AU
February 14, 2020
ALIASES:
Trojan:Win32/Detplock(MICROSOFT); Win32.Outbreak(IKARUS);
PLATFORM:
Windows
OVERALL RISK RATING:
DAMAGE POTENTIAL:
DISTRIBUTION POTENTIAL:
REPORTED INFECTION:
INFORMATION EXPOSURE:


Threat Type: Trojan
Destructiveness: No
Encrypted:
In the wild: Yes
TECHNICAL DETAILS
File Size: 1,245,184 bytes
File Type: ISO
Memory Resident: Yes
Initial Samples Received Date: 14 Feb 2020
Installation
This Trojan drops the following files:
- %Cookies%\{username}@google[1].txt
(Note: %Cookies% is the Internet Explorer browser cookies folder, which is usually C:\Documents and Settings\{user name}\Cookies on Windows 2000(32-bit), XP, and Server 2003(32-bit), or C:\Users\{user name}\AppData\Roaming\Microsoft\Windows\Cookies on Windows Vista and 7, or C:\Users\{user name}\AppData\Local\Microsoft\Windows\INetCookies on Windows 8, 8.1, 2008(64-bit), 2012(64-bit) and 10(64-bit).)
It adds the following processes:
- {malware file path}\C1.exe
Other Details
This Trojan connects to the following possibly malicious URL:
- http://{BLOCKED}p.{BLOCKED}i.goog/gsr2/ME4wTDBKMEgwRjAJBgUrDgMCGgUABBTgXIsxbvr2lBkPpoIEVRE6gHlCnAQUm%2BIHV2ccHsBqBt5ZtJot39wZhi4CDQHjtJqhjYqpgSVpULg%3D
- http://{BLOCKED}p.{BLOCKED}i.goog/gts1o1/MFEwTzBNMEswSTAJBgUrDgMCGgUABBRCRjDCJxnb3nDwj%2Fxz5aZfZjgXvAQUmNH4bhDrz5vsYJ8YkBug630J%2FSsCEGbFlJeGAf%2B1AgAAAABXm8I%3D

