Search
Keyword: chopper.ac!mtb
system. Trojan:Win32/PonyStealer.VB!MTB (Microsoft); Fareit-FRL!B03891F299D7 (McAfee)
the Windows system folder, where it usually is C:\Windows\System32 on all Windows operating system versions.) This report is generated via an automated analysis system. Trojan:Win32/AutoitInject.BH!MTB
system. Trojan:Win32/FormBook.AW!MTB (Microsoft); RDN/Generic PWS.y (McAfee); Trojan.Win32.Generic!BT (Sunbelt)
Trojan:Win32/PonyStealer.AE!MTB (Microsoft); Fareit-FRL!5165C37BD434 (McAfee); Trojan.Win32.Generic!BT (Sunbelt)
Trojan:MSIL/AgentTesla.GAP!MTB (MICROSOFT); UDS:Trojan-Spy.MSIL.Noon.gen (KASPERSKY) Downloaded from the Internet, Dropped by other malware Connects to URLs/IPs
http://b{BLOCKED}glu.com.tr/wp-admin/317Sz3wZsYmAAmmL6/ TrojanDownloader:O97M/Emotet.PKCU!MTB (MICROSOFT)
inaccessible. TrojanDownloader:O97M/EncDoc.KFVU!MTB (MICROSOFT)
interface Hostname Other Details This Trojan does the following: It runs itself as a daemon Trojan:Linux/Vermilionstrike.A!MTB (MICROSOFT)
encrypted files: .locked It drops the following file(s) as ransom note: /home/{Username}/Desktop/__$$RECOVERY_README$$__.html {Encrypted Directory}/__$$RECOVERY_README$$__.html Ransom:Linux/Cerbercrypt.B!MTB
}sroomtime.com/mongery/ZlPsROtQiXIujmJmAA/ TrojanDownloader:O97M/Emotet.SS!MTB (MICROSOFT)
TrojanDownloader:O97M/EncDoc.KFVU!MTB (MICROSOFT)
TrojanDownloader:O97M/EncDoc.LSM!MTB (MICROSOFT)
}ct.org/wp-admin/E6Z5DApRJ/ TrojanDownloader:O97M/Encdoc.ADAC!MTB (MICROSOFT)
TrojanDownloader:O97M/Emotet.PDWB!MTB (MICROSOFT)
}dianarab.com/wp-content/VJ/ TrojanDownloader:O97M/EncDoc.LSM!MTB (MICROSOFT)
}es.my.id/cgi-bin/uFqdwCqAP7mro/ TrojanDownloader:O97M/Emotet.PKCU!MTB (MICROSOFT)
proceed with its intended routine. Trojan:MSIL/AgentTesla.MBFC!MTB (MICROSOFT) Downloaded from the Internet, Dropped by other malware Connects to URLs/IPs
following file extensions: .biotech Ransom:Linux/Biotech.A!MTB (MICROSOFT) Downloaded from the Internet, Dropped by other malware Encrypts files, Displays windows
following possibly malicious URL: {BLOCKED}175.221 This report is generated via an automated analysis system. TrojanDownloader:O97M/Obfuse.KQ!MTB [non_writable_container], TrojanDownloader:O97M/Obfuse.KQ!MTB
possibly malicious URL: {BLOCKED}171.194 This report is generated via an automated analysis system. TrojanDownloader:O97M/Obfuse.OR!MTB [non_writable_container], TrojanDownloader:O97M/Obfuse.OR!MTB [n