Home / malware TrojanDropper:JS/Xibow.A
First posted on 02 April 2015.
Source: MicrosoftAliases :
There are no other names known for TrojanDropper:JS/Xibow.A.
Explanation :
Threat behavior
Installation
This threat can create files on your PC, including:
- %TEMP%\vlt.bat - detected as Ransom:BAT/Xibow.H
It may arrive in the system as attachment inside emails. We have seen it use the following names for the attachments:
- ÐÂкÑ‚ ÑÂвеÑ€ки за март 2015 годакÑ‚_ÑÂвеÑ€ки_(март)_2015_год_по_иÑ‚огам_пеÑ€вого_квартала_ÑÂоглаÑÂовано_бухгалÑ‚еÑ€ией_-_аttаÑÂhmеnt_Dr.Wеb_SÑÂаnnеd_--_OK.dоÑÂx_.js
- а_ ÑÂоÑÂÑ‚авлено зам главного бухгалÑ‚еÑ€а ÑÂоглаÑÂовано руководиÑ‚елем пÑ€едпÑ€_СÐÂЛЬДО на 24.03.2015 doÑÂx.js
Payload
Installs malware or unwanted software
This trojan can install other malware or unwanted software onto your PC. The dropped malware is usually a member of the Ransom:BAT/Xibow family.
Additional information
This malware description was published using automated analysis of file SHA1 2f4d245b368e13946c214e7693622918e27a019b.
Symptoms
The following can indicate that you have this threat on your PC:
- You see a file similar to:
- %TEMP%\vlt.bat
Last update 02 April 2015