Trojan.W97M.POWLOAD.TIOIBEHR
November 21, 2019
ALIASES:
Trojan-Downloader.VBA.Emotet (Ikarus); W97M/Dropper.cu (NAI)
PLATFORM:
Windows
OVERALL RISK RATING:
DAMAGE POTENTIAL:
DISTRIBUTION POTENTIAL:
REPORTED INFECTION:
INFORMATION EXPOSURE:
Threat Type: Trojan
Destructiveness: No
Encrypted:
In the wild: Yes
OVERVIEW
This Trojan arrives on a system as a file dropped by other malware or as a file downloaded unknowingly by users when visiting malicious sites.
TECHNICAL DETAILS
File Size: 214,799 bytes
File Type: DOC
Memory Resident: No
Initial Samples Received Date: 21 Nov 2019
Arrival Details
This Trojan arrives on a system as a file dropped by other malware or as a file downloaded unknowingly by users when visiting malicious sites.
Installation
This Trojan drops the following files:
- %User Profile\849.exe
Other Details
This Trojan connects to the following possibly malicious URL:
- http://{BLOCKED}forfairygodmothers.com/yjlsdsd/k3/
- http://{BLOCKED}ox.uk/wp-admin/7Q/
- https://{BLOCKED}99.com/cgi-bin/g1oi/
- https://{BLOCKED}od.com/pytosj2jd/pazg/
- https://www.{BLOCKED}consulting.it/cgi-bin/9q6ty/