Wysotot

By GoldSparrow in Trojans

Threat Scorecard

Threat Level: 80 % (High)
Infected Computers: 9,603
First Seen: April 27, 2015
Last Seen: March 13, 2022
OS(es) Affected: Windows

The Trojan.Wysotot malware is a Trojan-Downloader that is considered to be a severe cyber threat. The Wysotot Trojan-Downloader can be used to change the browser settings of infected users and run a shadow instance of their default Internet client to download other threats over unencrypted HTTP channels. The Wysotot Trojan-Downloader may be deployed to users via spam mail and might be packed as a ZIP and RAR archive file that is an executable. Additionally, there are cases where the developers of the Wysotot malware deploy their application as a free car racing game and invite the user to run the Trojan with administrative privileges to ensure its infiltration. The Wysotot Trojan-Downloader is known to use DLL libraries to remain undetected by most security scanners, and you are not likely to see it listed in the 'Control Panel' and the Program Files directory.

The Wysotot Trojan may install its files in the AppData and Temp folders, and make modifications to your Registry to be executed as a system service on the next reboot. The Wysotot Trojan-Downloader may feature an obsolete digital certificate from a company called Banyan Tree Technology Limited to bypass the Windows Code Signing Verification. The Wysotot malware may use the eGdpSvc.exe process to host its activity and execute its operations. The Wysotot malware has many versions that may be detected as Trojan/Win32.Staser, Gen:Variant.Kazy.233728 and PUP.Optional.Wsys.A. The variants of the Wysotot Trojan-Downloader may make GET requests to remote servers at V9.com, 22find.com, 322apple.com and Portaldosites.com. Moreover, the Wysotot malware may utilize shell commands to add parameters to explorer.exe and hide its activity and installation folder. The Wysotot Trojan-Downloader is similar to Bartallex and Tordow, and you need a reliable anti-malware suite to remove it safely.

SpyHunter Detects & Remove Wysotot

File System Details

Wysotot may create the following file(s):
# File Name MD5 Detections
1. Laban.exe 30f5665844bc13279e002ddd9c9033c4 2,851
2. Laban.exe 7d813639a702b724d5c521178362cec3 670
3. Laban.exe 21d66d4fce05b0128a12d9ad45fb2be2 657
4. laban.exe bd8540918af4e328e06515239d5659f9 390
5. laban.exe 62166db3d2591720b951cc05eb72b4ba 309
6. laban.exe eaec3ccd110dd9708cfd5a95e7b6406c 192
7. laban.exe a38c80f052f0f542583fe3427ffb51cd 83
8. laban.exe 8e80876e49db9dc848419baa4305d5cc 77
9. laban.exe 26f13c877e28a75ac594089a07e1d2c0 42
10. Laban.exe 8add59b08989c08255b323de8dcfae1d 15
11. Laban.exe 1c0e00cc28a09c8dd0e0b78114879f2c 12
12. Laban.exe e2472786db1e1de332e709896ffc6e86 11
13. Laban.exe 2ae2146cd650022d1987ee0733e67499 10
14. laban.exe c9b898e6bcce28ec7627af0cd6bbcacf 6
15. laban.exe 8c253449030c214712a8dc102f01d4cc 5
16. Laban.exe 6219836a8a145a5ba6b07bea8c8954e1 5
17. laban.exe 757e869950723995a04135ee276bff30 4
18. laban.exe 05aac517985ecc278361a3cd7c4329c3 4
19. Laban.exe fc2280e245b1f015756d9ecee4e5b8f1 4
20. laban.exe 549a3101c6d33b99ec47f1be5dc82286 3
21. laban.exe 4ea7e72ccb876dec1f3da9e3eceb9fed 3
22. laban.exe 4fe3a865afdcd173f0c7f85ca80ec99c 3
23. laban.exe 2fd6017ca1296d6e57e2eb11034a7588 3
24. laban.exe 556f426beee1a2788a9fa51259d13cf1 3
25. laban.exe 6fb78de0fc5a3e2d63f479b17a4d792f 3
26. laban.exe 0e233a7172af66885beb37cfaa9f8b1a 2
27. laban.exe 977d1ca83d80c8fa22884e582da08045 2
28. Laban.exe 9aa1a5f645d4ed8027cc84f7b85e6698 2
More files

Related Posts

Trending

Most Viewed

Loading...