Home / malware Trojan:Win32/Logedrut.A
First posted on 04 February 2015.
Source: MicrosoftAliases :
There are no other names known for Trojan:Win32/Logedrut.A.
Explanation :
Threat behavior
Installation
This threat is installed to a random folder on your PC using a random file name. For example, we have seen it installed to %TEMP%\Adobe\f18.exe.
Payload
Downloads and runs malware on connected systems
This threat collects a list of systems connected via remote desktop to the infected PC.
It tries to run the following files in any connected systems:
- mstask.bat - used to run TrojanSpy:Win32/Logedrut.A
- mstask.exe - can contain other malware, including components used to hash files in an infected system
Analysis by Zarestel Ferrer
Symptoms
Alerts from your security software might be the only symptom.
Last update 04 February 2015