Threat Database Trojans Trojan.JackServn

Trojan.JackServn

By CagedTech in Trojans

Threat Scorecard

Threat Level: 80 % (High)
Infected Computers: 16
First Seen: May 8, 2018
Last Seen: August 1, 2018
OS(es) Affected: Windows

Trojan.JackServn is a detection name that AV developers have assigned to a generic Trojan, which is suspected to be made by a Korean team of programmers. Analysis of samples that are attributed to the Trojan.JackServn showed that the threat is coded on systems with a primary Korean keyboard layout. Also, many of the distribution campaigns associated with Trojan.JackServn appears to be restricted to computers on the peninsula. According to some statistics, the Trojan.JackServn has been active at least since July 2017. The Trojan.JackServn is reported to work on 32-bit and 64-bit Windows installations, but it is aimed at 32-bit systems primarily. Researchers note that the Trojan.JackServn may run as 'fbzqaaaa.exe' from the Temp folder under the AppData directory and feature the following attributes:

SHA-256: 4f04782130e8f73adba59e431c5775fc57573719f241da776eacd403751e956b
File name fbzqaaaa.exe
File size 1.2 MB
File version 6.1.7600.16385

The 'fbzqaaaa.exe' malware should not be removed manually as it may trigger some sort of a failsafe mechanism and cause damages to the host PC. Many AV vendors categorize Trojan.JackServn as a severe threat to regular PC users as it boasts the following capabilities:

  • Downloading and uploading files
  • Recording the keyboard input
  • Take screenshots

As far as the network capabilities of the Trojan.JackServn goes, it may be used for Denial-of-Service (DoS) attacks, as well as hide the Web traffic of an attacker. Trojan.JackServn might invade Windows-powered devices through emails, links to corrupted pages, peer-to-peer networks and fake updates to software you may be using on your system. Perhaps the most harmful aspect of Trojan.JackServn is that it can download other malware onto the compromised machine and allow for privilege escalation attacks. It may be hard even for advanced PC users to notice that the Trojan.JackServn is running in the background. We recommend users perform system scans with a reliable anti-malware service regularly as a way to minimize potential damages from the Trojan and remove it as quickly as possible. AV engines support detection rules for Trojan.JackServn and employ the following detection names:

  • TR/Patched.Gen3
  • Trojan.Generic.cbphp
  • Trojan.PasswordStealer
  • Trojan.Win32.Jackservn
  • Win32:Dh-A [Heur]
  • malicious (high confidence)

SpyHunter Detects & Remove Trojan.JackServn

File System Details

Trojan.JackServn may create the following file(s):
# File Name MD5 Detections
1. file.exe 7742cdc394221678af8b488c0857a05e 8
2. file.exe 30210ac7bbce1e5e0c1b9c5a38e7e02b 0

Registry Details

Trojan.JackServn may create the following registry entry or registry entries:
Regexp file mask
%WINDIR%\System32\zzzxxx.exe
%WINDIR%\SysWOW64\zzzxxx.exe

Trending

Most Viewed

Loading...