Win32/TrojanDownloader.Siromost [Threat Name] go to Threat

Win32/TrojanDownloader.Siromost.A [Threat Variant Name]

Category trojan
Size 1048650 B
Detection created Feb 06, 2014
Detection database version 9389
Aliases Trojan-Downloader.Win32.Agent.hdzh (Kaspersky)
Short description

Win32/TrojanDownloader.Siromost.A is a trojan which tries to download other malware from the Internet.

Installation

The trojan does not create any copies of itself.

Information stealing

Win32/TrojanDownloader.Siromost.A is a trojan that steals sensitive information.


The trojan collects the following information:

  • computer name
  • operating system version
  • MAC address
  • installed antivirus software
  • files

The trojan attempts to send gathered information to a remote machine.

Other information

The trojan contains a URL address.


It tries to download several files from the address. The HTTP protocol is used.


The downloaded files contain encrypted executables.


These are stored in the following locations:

  • smdhost.exe
  • nlbhost.exe

The files are stored in the current folder.


After decryption, the trojan runs these files.


The trojan checks for Internet connectivity by trying to connect to the following addresses:

  • www.baidu.com
  • update.microsoft.com

Please enable Javascript to ensure correct displaying of this content and refresh this page.