Home / malware TrojanDownloader:Win32/Lerspeng.B
First posted on 20 July 2019.
Source: MicrosoftAliases :
TrojanDownloader:Win32/Lerspeng.B is also known as Trojan/Win32.Ransomlock, W32/Downloader.PUYB-2856, Trojan.Win32.Inject.mpuu, win32/Agent.BCBLJ, Trojan horse SHeur4.BUEA, TR/Dldr.Small.PSD, Trojan.GenericKD.1651739, Trojan.Packed.26550, W32/Inject.MPUU!tr, Troj/Zbot-IEL, TROJ_UPATRE.JH.
Explanation :
Installation
TrojanDownloader:Win32/Lerspeng.B can arrive on your PC attached to a spam email, or downloaded by other malware family, such as TrojanDownloader:Win32/Upatre and TrojanDownloader:Win32/Kuluoz.
The spam email might follow the following template:
Subject: Payment notification #
Email body:
!
.
Sum: $
===Detailed notification is in the attached ZIP-archive===
Unfortunately, this email is an automated notification, which is unable to receive replies.
We're happy to help you with any questions or concerns you may have.
Please contact us directly 24/7 via our site.
Nofound in this message. Checked by .
When run, TrojanDownloader:Win32/Lerspeng.B downloads a file and saves this file on your PC as %TEMP%mss.exe. for example, %TEMP%mss11.exe.
Payload
Downloads other malware
We have seen TrojanDownloader:Win32/Lerspeng.B connect to the following URLs to download other malware:
76.12.188.227/pesk/keystones allee-a.fr/rawness ormat bestattungskultur. tipsily/battled blueodysseyvacatio om/disabled/casements cajuncloud.com/det or/reverting customerservice.iv ustralia.com/essential/supernova dboulaisdance.ca/a ness/vessels dboulaisdance.ca/e thius/detonates dislexia.ch/stepso ange ftp.bluerivermedia sprangs/meringue griffinclan.org.cl rvers.com/deniers/echos handhtek.com/ashmo /zhengzhou LEFTCOASTFOOTBALL. slaloming/opera mccubbin.dmirc.com tle/strikers mytimeenglish.com/ els/shellfish peas.de/peaceful/c hed pflegepaedagogik.d eckpoint/resonantly redrockspd.com/rib vin/composure spraymarketing.co. verhaul/niobe studiosharise.com/ ively/nitpicked torrealum.com/gain /frigidly walkzone2u.com/pun e/clump www.10142493.wavel .com/banach/vizor www.efg-neckarsulm pleats/enquiry www.furairgallon.b rtals/ruined www.genienspiegel. iscos/preemptive www.limousinegta.c drigals/revealings www.stoltztechnica vices.com/pubic/assertion www.teutoklaus.de/ ne/reuse www.zeton.com.br/c ility/engraver
We have seen it download the following malware families:
PWS:Win32/Zbot Trojan:Win32/Kuluoz TrojanDownloader:Win32/Upatre Worm:Win32/Gamarue
Analysis by Zarestel FerrerLast update 20 July 2019