Home / malware TrojanDownloader:Win32/Dropdrans.A
First posted on 04 February 2015.
Source: MicrosoftAliases :
There are no other names known for TrojanDownloader:Win32/Dropdrans.A.
Explanation :
Threat behavior
Installation
This threat is usually downloaded by other malware.
It is installed to a random folder with a random file name. For example, we have seen it use the following file name:
- intel.exe
Payload
Downloads other malware
This threat can download files, including other malware, from a hardcoded Dropbox account. This account is now offline.
The downloaded files are saved to the root directory using the following file names:
- comine.exe
- data.bin
- ~tmp.dat
Analysis by Zarestel Ferrer
Symptoms
The following can indicate that you have this threat on your PC:
- You have these files:
comine.exe
data.bin
~tmp.datLast update 04 February 2015