VBA/TrojanDownloader.Agent.BVO [Threat Name] go to Threat

VBA/TrojanDownloader.Agent.BVO [Threat Variant Name]

Category trojan
Size 35339 B
Detection created Oct 06, 2016
Detection database version 14234
Aliases Trojan.VBS.Agent.aef (Kaspersky)
  TrojanDownloader:O97M/Donoff (Microsoft)
  W97M.Downloader (Symantec)
  W97M.DownLoader.1195 (Dr.Web)
Short description

VBA/TrojanDownloader.Agent.BVO is a trojan which tries to download other malware from the Internet.

Installation

The trojan does not create any copies of itself.

Other information

The trojan contains a list of (3) URLs.


It tries to download a file from the addresses.


The file is stored in the following location:

  • %temp%\­rufiad%variable%

A string with variable content is used instead of %variable% .


The files contain encrypted executables.


After decryption the data is saved in the following files:

  • %temp%/vuchbots%variable%.dll

The file is then executed.


A string with variable content is used instead of %variable% .


Trojan requires the Microsoft Word to run.

Please enable Javascript to ensure correct displaying of this content and refresh this page.