VBA/TrojanDropper.Agent.FY [Threat Name] go to Threat

VBA/TrojanDropper.Agent.FY [Threat Variant Name]

Category trojan
Detection created Mar 02, 2016
Detection database version 13116
Short description

VBA/TrojanDropper.Agent.FY is a trojan which tries to download other malware from the Internet.

Installation

The trojan does not create any copies of itself.


The trojan contains the program code of the following malware:

  • BAT/TrojanDownloader.Agent.NHT
  • VBS/TrojanDownloader.Agent.NZE

The trojan creates the following files:

  • %temp%\­tdfvhjdsf.bat (BAT/TrojanDownloader.Agent.NHT)
  • %temp%\­ytredasdf.vbs (VBS/TrojanDownloader.Agent.NZE)

The files are then executed.

Other information

The trojan contains a URL address.


It tries to download a file from the address.


The file is stored in the following location:

  • %temp%\­dsdsfvvb.exe

The file is then executed. The HTTP protocol is used in the communication.


The trojan then deletes following files:

  • %temp%\­tdfvhjdsf.bat
  • %temp%\­ytredasdf.vbs

Please enable Javascript to ensure correct displaying of this content and refresh this page.