Threat Database Trojans Trojan.Smackup


By Domesticus in Trojans

Threat Scorecard

Ranking: 13,065
Threat Level: 90 % (High)
Infected Computers: 367
First Seen: May 21, 2013
Last Seen: August 5, 2023
OS(es) Affected: Windows

Trojan.Smackup is a Trojan that steals information from the corrupted PC. Once run, Trojan.Smackup creates the malevolent files on the affected computer system. Trojan.Smackup makes modifications to the attributes of the files in order to conceal them from the computer user. Trojan.Smackup creates the registry entries so that it can load automatically whenever you start Windows. Trojan.Smackup grabs system information and stores it in the specific file. Trojan.Smackup also grabs files with the file extensions such as .docx, .doc, .xlsx, .pptx, .ppt and .pdf. Trojan.Smackup saves the gathered files in the particular file. Trojan.Smackup also logs keystrokes and opens window titles, and saves the information in the particular file. Trojan.Smackup then uploads the stolen information to the certain locations.

File System Details

Trojan.Smackup may create the following file(s):
# File Name Detections
1. %SystemDrive%\MSOCache\Hen.exe
2. %SystemDrive%\MSOCache\start.bat
3. %SystemDrive%\MSOCache\start1.bat
4. %SystemDrive%\MSOCache\Ron.exe
5. %SystemDrive%\MSOCache\test.vbs
6. %SystemDrive%\MSOCache\Info-[DATE].log
7. %SystemDrive%\MSOCache\MS[THREE DIGITS].log
8. %SystemDrive%\MSOCache\MB145.log
9. %SystemDrive%\MSOCache\1.pdf
10. %SystemDrive%\MSOCache\csb.log

Registry Details

Trojan.Smackup may create the following registry entry or registry entries:
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run\"GlitchInstrumentation" = "%SystemDrive%\MSOCache\Ron.exe\"
HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Run\"GlitchInstrumentation" = "%SystemDrive%\MSOCache\Ron.exe\"


Most Viewed
