Threat Database Trojans Win32/TrojanDownloader.Carberp.AM

Win32/TrojanDownloader.Carberp.AM

By Domesticus in Trojans

Threat Scorecard

Ranking: 16,560
Threat Level: 20 % (Normal)
Infected Computers: 11,544
First Seen: March 25, 2013
Last Seen: August 28, 2023
OS(es) Affected: Windows

Win32/TrojanDownloader.Carberp.AM is a Trojan downloader, which affects remote banking systems and fraud operations of major Russian and Ukrainian banks. Win32/TrojanDownloader.Carberp.AM uses the code injection technique to insert a code into a genuine process characteristic of Power Loader. While being run, Win32/TrojanDownloader.Carberp.AM strives to open one of the shared section objects and attaches shellcode to the end of the section. Win32/TrojanDownloader.Carberp.AM inserts a code into the genuine system process 'explorer.exe' in order to evade detection of anti-virus programs and run the specific infective steps from authentic process address space.

SpyHunter Detects & Remove Win32/TrojanDownloader.Carberp.AM

File System Details

Win32/TrojanDownloader.Carberp.AM may create the following file(s):
# File Name MD5 Detections
1. file.exe c6b9ebb31b18ac9a5cf1d4caf5b15e77 0
2. file.exe 15934689c6f627db53a7557eadc8bf71 0
3. file.exe eed989057d4566d7f83f5f24318067c9 0
4. file.exe 0c17886ce17951d499d589c8768e3484 0
5. file.exe 185ba4682d78a0da822cd3fc102daf3c 0

Trending

Most Viewed

Loading...