Home / malwarePDF  

TrojanDropper:JS/Xibow.A


First posted on 02 April 2015.
Source: Microsoft

Aliases :

There are no other names known for TrojanDropper:JS/Xibow.A.

Explanation :

Threat behavior

Installation
This threat can create files on your PC, including:

  • %TEMP%\vlt.bat - detected as Ransom:BAT/Xibow.H


It may arrive in the system as attachment inside emails. We have seen it use the following names for the attachments:

  • АкÑ‚ свеÑ€ки за март 2015 годакÑ‚_свеÑ€ки_(март)_2015_год_по_иÑ‚огам_пеÑ€вого_квартала_согласовано_бухгалÑ‚еÑ€ией_-_аttасhmеnt_Dr.Wеb_Sсаnnеd_--_OK.dосx_.js
  • а_ составлено зам главного бухгалÑ‚еÑ€а согласовано руководиÑ‚елем пÑ€едпÑ€_САЛЬДО на 24.03.2015 doсx.js


Payload


Installs malware or unwanted software

This trojan can install other malware or unwanted software onto your PC. The dropped malware is usually a member of the Ransom:BAT/Xibow family.



Additional information


This malware description was published using automated analysis of file SHA1 2f4d245b368e13946c214e7693622918e27a019b.

Symptoms

The following can indicate that you have this threat on your PC:

  • You see a file similar to:
    • %TEMP%\vlt.bat

Last update 02 April 2015

 

TOP