Win32/TrojanDownloader.Siromost [Threat Name] go to Threat

Win32/TrojanDownloader.Siromost.A [Threat Variant Name]

Category trojan
Size 1048650 B
Detection created Feb 06, 2014
Detection database version 9389
Aliases Trojan-Downloader.Win32.Agent.hdzh (Kaspersky)
Short description

Win32/TrojanDownloader.Siromost.A is a trojan which tries to download other malware from the Internet.


The trojan does not create any copies of itself.

Information stealing

Win32/TrojanDownloader.Siromost.A is a trojan that steals sensitive information.

The trojan collects the following information:

  • computer name
  • operating system version
  • MAC address
  • installed antivirus software
  • files

The trojan attempts to send gathered information to a remote machine.

Other information

The trojan contains a URL address.

It tries to download several files from the address. The HTTP protocol is used.

The downloaded files contain encrypted executables.

These are stored in the following locations:

  • smdhost.exe
  • nlbhost.exe

The files are stored in the current folder.

After decryption, the trojan runs these files.

The trojan checks for Internet connectivity by trying to connect to the following addresses:


Please enable Javascript to ensure correct displaying of this content and refresh this page.