Home / malwarePDF  

TrojanDownloader:Win32/Dropdrans.A


First posted on 04 February 2015.
Source: Microsoft

Aliases :

There are no other names known for TrojanDownloader:Win32/Dropdrans.A.

Explanation :

Threat behavior

Installation

This threat is usually downloaded by other malware.

It is installed to a random folder with a random file name. For example, we have seen it use the following file name:

  • intel.exe


Payload

Downloads other malware

This threat can download files, including other malware, from a hardcoded Dropbox account. This account is now offline.

The downloaded files are saved to the root directory using the following file names:

  • comine.exe
  • data.bin
  • ~tmp.dat




Analysis by Zarestel Ferrer

Symptoms

The following can indicate that you have this threat on your PC:

  • You have these files:

    comine.exe
    data.bin
    ~tmp.dat

Last update 04 February 2015

 

TOP