Author: Mohammed Malubay   

 

Trojan:Win32/Detplock(MICROSOFT); Win32.Outbreak(IKARUS);

 PLATFORM:

Windows

 OVER ALL RISK RATING:
 DAMAGE POTENTIAL::
 DISTRIBUTION POTENTIAL::
 REPORTED INFECTION:
 INFORMATION EXPOSURE:
Low
Medium
High
Critical

  • Threat Type:
    Trojan

  • Destructiveness:
    No

  • Encrypted:
     

  • In the wild::
    Yes


  TECHNICAL DETAILS

File size: 1,245,184 bytes
File type: ISO
Memory resident: Yes
INITIAL SAMPLES RECEIVED DATE: 14 lutego 2020

Instalación

Infiltra los archivos siguientes:

  • %Cookies%\{username}@google[1].txt

Agrega los procesos siguientes:

  • {malware file path}\C1.exe

Otros detalles

It connects to the following possibly malicious URL:

  • http://{BLOCKED}p.{BLOCKED}i.goog/gsr2/ME4wTDBKMEgwRjAJBgUrDgMCGgUABBTgXIsxbvr2lBkPpoIEVRE6gHlCnAQUm%2BIHV2ccHsBqBt5ZtJot39wZhi4CDQHjtJqhjYqpgSVpULg%3D
  • http://{BLOCKED}p.{BLOCKED}i.goog/gts1o1/MFEwTzBNMEswSTAJBgUrDgMCGgUABBRCRjDCJxnb3nDwj%2Fxz5aZfZjgXvAQUmNH4bhDrz5vsYJ8YkBug630J%2FSsCEGbFlJeGAf%2B1AgAAAABXm8I%3D