Threat Database Trojans Trojan.Shylock.B

Trojan.Shylock.B

By Sumo3000 in Trojans

Trojan.Shylock.B is a Trojan that opens a back door on the compromised PC and attempts to steal confidential information. Trojan.Shylock.B propagates by exploiting the Oracle Java SE Rhino Script Engine Remote Code Execution Vulnerability (CVE-2011-3544) and Oracle Java SE Remote Java Runtime Environment Code Execution Vulnerability (CVE-2012-0507). When Trojan.Shylock.B is executed, it creates the potentially malicious file. Trojan.Shylock.B may also proliferate by substituting the certain file types on removable drives and network shares. Trojan.Shylock.B then opens a back door and contacts the command-and-control (C&C) server in order to download more infected files.Trojan.Shylock.B gathers information about the corrupted machine and transfers it to the C&C server. Trojan.Shylock.B also sets up itself into a process called 'svchost.exe' in order to obtain instructions from the C&C server.

SpyHunter Detects & Remove Trojan.Shylock.B

File System Details

Trojan.Shylock.B may create the following file(s):
# File Name MD5 Detections
1. %Temp%\[ONE LETTER].tmp.exe
2. Copy of [ORIGINAL FILE NAME].[EXTENSION]
3. [ORIGINAL FILE NAME].lnk
4. ddeshare.exe 52edfd92c348938f1410eac1dc024717 0
5. lokker.zip 939a971cfc3d777d47432a2084f30aa5 0
6. file.exe 6955abf8e938bfa0f40780554e17810f 0

Trending

Most Viewed

Loading...