
SonicWALL UTM Research received reports of new backdoor Trojan being spammed in the wild. The trojan arrives via email as an attachment.
If the user downloads and executes the file attachment from the email then it performs the following activities on the victim machine:
It creates the following files
This file contains information about open windows and associated keystrokes which is uploaded to the domain. Sample of the file is as below:
SonicWALL Gateway AntiVirus provides protection against this Bandok Trojan with the following signatures
GAV: Bandok.WG (Trojan)
GAV: Bandok.WG_2 (Trojan)
Share This Article

An Article By
An Article By
Security News
Security News