NEW BLOG POST: Windows Defender AV’s behavior monitoring coupled with cloud-powered machine learning models uncovered and blocked a massive Dofoil (Smoke Loader) coin mining campaign. Read the post
Alert level: Severe Detected with Windows Defender Antivirus
Also detected as: VirTool:Win32/Injector.gen!BB (other) Trojan-Dropper.Win32.Dapato.bipz (Kaspersky) Mal/EncPk-AFA (Sophos) Mal/Kuluoz-C (Sophos)
Windows Defender Antivirus detects and removes this threat.
This trojan tries to connect your PC to a remote server to receive instructions from a malicious hacker. The hacker can then tell the trojan to perform any number of actions, including to download and run files. We have seen this trojan download variants of the rogue security scanner Rogue:Win32/Winwebsec.
There is more information in the Win32/Kuluoz family description.