Home / malwarePDF  

Trojan:Win32/Logedrut.A


First posted on 04 February 2015.
Source: Microsoft

Aliases :

There are no other names known for Trojan:Win32/Logedrut.A.

Explanation :

Threat behavior

Installation

This threat is installed to a random folder on your PC using a random file name. For example, we have seen it installed to %TEMP%\Adobe\f18.exe.

Payload

Downloads and runs malware on connected systems

This threat collects a list of systems connected via remote desktop to the infected PC.

It tries to run the following files in any connected systems:

  • mstask.bat - used to run TrojanSpy:Win32/Logedrut.A
  • mstask.exe - can contain other malware, including components used to hash files in an infected system




Analysis by Zarestel Ferrer

Symptoms

Alerts from your security software might be the only symptom.

Last update 04 February 2015

 

TOP