Threat Database Trojans Trojan-SkyHook

Trojan-SkyHook

By GoldSparrow in Trojans

Threat Scorecard

Threat Level: 90 % (High)
Infected Computers: 3
First Seen: April 9, 2013
Last Seen: April 15, 2023
OS(es) Affected: Windows

Trojan-SkyHook is a Trojan that sets UTF-8 BOM in ZIP Signature to bypass the detection by anti-virus programs. Trojan-SkyHook uses a simple phishing attack by making modifications to the hosts file on Windows systems. Trojan-SkyHook is packaged in a ZIP file together with a 0-byte 'readme.txt' file. Commonly, ZIP files that affect hacked PCs with Trojan-SkyHook are started with the ZIP signature 0x04034B50, or 'PK', 03, 04, but in this case, the makers chose to add the UTF-8 Byte Order Mark (BOM), introduced as 0xEFBBBF, before the ZIP header. Because the ZIP file is prefixed with the UTF-8 BOM, it tricks many software into supposing that the file is a UTF-8-encoded text file. For instance, when such a file is opened by Windows 7, the operating system regrets that such a ZIP file is invalid. Some third-party archive software, such as 7-Zip, WinRAR, and some others ignore the BOM and read the ZIP file appropriately.

File System Details

Trojan-SkyHook may create the following file(s):
# File Name Detections
1. readme.txt

Trending

Most Viewed

Loading...