Threat Database Trojans TrojanDropper:Win32/Lisfel.A

TrojanDropper:Win32/Lisfel.A

By Domesticus in Trojans

Threat Scorecard

Ranking: 14,344
Threat Level: 90 % (High)
Infected Computers: 138
First Seen: October 16, 2012
Last Seen: September 18, 2023
OS(es) Affected: Windows

TrojanDropper:Win32/Lisfel.A is a Trojan that distributes other Lisfel components on the compromised machine. When installed on the targeted computer system, TrojanDropper:Win32/Lisfel.A makes system changes by adding malevolent files and registry entries. TrojanDropper:Win32/Lisfel.A modifies the specific registry entry so that it can load its downloaded component every time you boot up Windows. TrojanDropper:Win32/Lisfel.A may invade the compromises PC via security threats that exploit the vulnerability described in CVE-2012-4969. TrojanDropper:Win32/Lisfel.A contacts an external server. TrojanDropper:Win32/Lisfel.A starts a disguised Internet browser window to access the server 'receo.konkuk.ac.kr', most likely to divert traffic to this server.

File System Details

TrojanDropper:Win32/Lisfel.A may create the following file(s):
# File Name Detections
1. user.dll
2. wlupdate.exe
3. lisfl.dll
4. tmp

Messages

The following messages associated with TrojanDropper:Win32/Lisfel.A were found:

HKEY_LOCAL_MACHINESoftwareMicrosoftWindowsCurrentVersionRun = "Kris" = " wlupdate.exe"

Trending

Most Viewed

Loading...