Threat Database Trojans TrojanDropper:O97M/Poshkod.gen!A

TrojanDropper:O97M/Poshkod.gen!A

By GoldSparrow in Trojans

Threat Scorecard

Threat Level: 90 % (High)
Infected Computers: 12
First Seen: May 6, 2014
Last Seen: May 22, 2023
OS(es) Affected: Windows

TrojanDropper:O97M/Poshkod.gen!A is a Trojan that can be executed automatically when a PC user opens a Microsoft Word document or Microsoft Excel workbook. TrojanDropper:O97M/Poshkod.gen!A can drop other malware threats onto an affected computer system, incorporating ransomware. TrojanDropper:O97M/Poshkod.gen!A is distributed via spam emails carrying malicious attachments including .doc or .xlsx files. TrojanDropper:O97M/Poshkod.gen!A is executed when a Microsoft Word document or Microsoft Excel spreadsheet is opened and Visual Basic for Applications (VBA) macros are enabled on the infected computer. TrojanDropper:O97M/Poshkod.gen!A drops and runs an infected PowerShell script from a specific web address. The infected script is evoked and might not be written to disk. TrojanDropper:O97M/Poshkod.gen!A can perform a variety of actions selected by an attacker and can change at any time. TrojanDropper:O97M/Poshkod.gen!A can be used by cybercriminals to distribute ransomware.

File System Details

TrojanDropper:O97M/Poshkod.gen!A may create the following file(s):
# File Name Detections
1. 2014 - Doc_10 - AJAX - Template - Match Report (example).doc
2. Round 1 match report.docm
3. U11 Comets Round 1.docm
4. 2014 - Doc#10 - AJAX - U11 Commets Round 1 Match Report.docm
5. Um-Hazaa List.xls
6. 2014 U11 AJAX Commets Sign in Sheet.xls

URLs

TrojanDropper:O97M/Poshkod.gen!A may call the following URLs:

Powerwormjqj42hu.onion/get.php?s=setup&mom=4C4C4544-0050-3010-804C-B4C04F4C5131&uid=[Infected PC UUID]

Trending

Most Viewed

Loading...