Home / malwarePDF  

TrojanDropper:JS/Zlader.B


First posted on 18 November 2015.
Source: Microsoft

Aliases :

There are no other names known for TrojanDropper:JS/Zlader.B.

Explanation :

Threat behavior

Installation

This threat might arrive on your PC as an email attachment. We have seen it use the following names:

  • ætÑGá-Sá¬Gpad_130-2_132-9_߫ú½Ã¡ÃŸ«Ã³Ã¡¡«_ß_¡Ã¡tá½8¡¿¬«¼_«Gñѽá_»a«Ã±Ã¡ª__Scanned_by_Dr.WÑ£_Çntivirus_163-10_13f850b43c8.tst_.js
  • ǬG_ßóÑa¬¿_«G_10.11.2015_ú«Ã±Ã¡___«G»aáó½Ã‘¡«_¬«¡GaáúÑ¡Gp_-_æ«Ãº½Ã¡ÃŸ«Ã³Ã¡¡«_ñ¿aѬG«a«¼_-_ÄíTÑßGó«_ß_«Ãºaá¡¿tÑ¡¡«¬_«GóÑGßGóÑ¡¡«ÃŸG8e_ÉÑípß___2bd55b51050.tst_.js


We have seen this threat create the following file your your PC:



  • %TEMP% \09093.exe - detected as Ransom:Win32/Zlader.A



Payload

Downloads malware or unwanted software

This threat can download other malware and unwanted software onto your PC. We have seen it install malware from the Trojan:Win32/Zlader family.





Analysis by Donna Sibangan

Symptoms

The following can indicate that you have this threat on your PC:

  • You have these files

    %TEMP%\09093.exe
    ætÑGá-Sá¬Gpad_130-2_132-9_߫ú½Ã¡ÃŸ«Ã³Ã¡¡«_ß_¡Ã¡tá½8¡¿¬«¼_«Gñѽá_»a«Ã±Ã¡ª__Scanned_by_Dr.WÑ£_Çntivirus_163-10_13f850b43c8.tst_.js
    ǬG_ßóÑa¬¿_«G_10.11.2015_ú«Ã±Ã¡___«G»aáó½Ã‘¡«_¬«¡GaáúÑ¡Gp_-_æ«Ãº½Ã¡ÃŸ«Ã³Ã¡¡«_ñ¿aѬG«a«¼_-_ÄíTÑßGó«_ß_«Ãºaá¡¿tÑ¡¡«¬_«GóÑGßGóÑ¡¡«ÃŸG8e_ÉÑípß___2bd55b51050.tst_.js

Last update 18 November 2015

 

TOP