Threat Database Trojans Trojan.Jorik.Androm.pqr

Trojan.Jorik.Androm.pqr

By Domesticus in Trojans

Threat Scorecard

Threat Level: 90 % (High)
Infected Computers: 4
First Seen: May 17, 2013
Last Seen: February 18, 2022
OS(es) Affected: Windows

Trojan.Jorik.Androm.pqr is a Trojan that is distributed via spam emails, which carry falsified invoices from Zalando and Deutsche Bahn. The fake email dupes attacked computer users into running a malevolent file, found as Trojan.Jorik.Androm.pqr. Cybercriminals send personalized email messages in the German language supposedly coming from the well-known website Zalando.de (shoes and women accessories) and from the Deutsche Bahn (German Railways). The text is addressed to the target recipient directly, and it threatens the victimized PC user so that he/she opens the ZIP archive and runs the harmful file. If the affected PC user opens and executes the damaging file, his/her PC will get contaminated with

Trojan.Jorik.Androm.pqr.

File System Details

Trojan.Jorik.Androm.pqr may create the following file(s):
# File Name Detections
1. btc[1].exe
2. adobe_restart[1].exe
3. www2d.gif
4. image19.jpg.pif
5. 296291521.gif
6. yif81909.png

Registry Details

Trojan.Jorik.Androm.pqr may create the following registry entry or registry entries:
HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Run mService = [file name and location of the trojan]
HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Run WINSXS32 = [file name and location of the trojan]

Trending

Most Viewed

Loading...