Tranwos

By Domesticus in Trojans

Tranwos, also known as Backdoor.Tranwos, is a backdoor Trojan that uses encrypting file system to block forensic analysis. the malware known as Backdoor.Tranwos uses the EFS to prevent researchers from accessing the contents of the malicious files. Once Tranwos affects a vulnerable computer, it opens a back door to enable attackers to download more malware threats on the compromised PC. Tranwos creates a temporary folder, after which it calls the EncryptFileW API to encrypt all its files and folders. This makes it impossible not only to retrieve the malicious files from another operating system, such as Linux, but also to use forensic tools to analyze it.

Trending

Most Viewed

Loading...