Home / malwarePDF  

Downloader.Sapaviro


First posted on 01 October 2015.
Source: Symantec

Aliases :

There are no other names known for Downloader.Sapaviro.

Explanation :

The Trojan may arrive on the compromised computer as an email attachment.

When the Trojan is executed, it attempts to connect to the following location:
197.149.90.166
The Trojan may download potentially malicious files to the following location:
%Temp%\[RANDOM FILE NAME].exe
The Trojan may execute downloaded files.

The Trojan may send the following information back to the remote location to inform it that the compromised computer has been infected:
Computer nameOperating System information

Last update 01 October 2015

 

TOP