Kategorie: Trojan-Dropper
Trojan-Dropper-Programme sind so konzipiert, dass bösartige Programme, die in ihren Code integriert sind, heimlich auf den Computer des Opfers installiert werden.Diese Art von bösartigem Programm speichert normalerweise eine Reihe von Dateien auf dem Laufwerk des Opfers (normalerweise im Windows-Verzeichnis, im Windows-Systemverzeichnis, temporären Verzeichnis usw.) und startet sie ohne jegliche Benachrichtigung (oder mit falscher Benachrichtigung über einen Archivfehler, ein veraltete Betriebssystemversion, etc.).
Solche Programme werden von Hackern verwendet, um:
Installiere heimlich Trojanische Programme und / oder Viren
Schutz bekannter Schadprogramme vor dem Aufspüren durch Antivirus-Lösungen; Nicht alle Antivirenprogramme können alle Komponenten in dieser Art von Trojanern durchsuchen.
Mehr Informationen
Plattform: Win32
Win32 ist eine API auf Windows NT-basierten Betriebssystemen (Windows XP, Windows 7 usw.), die die Ausführung von 32-Bit-Anwendungen unterstützt. Eine der am weitesten verbreiteten Programmierplattformen der Welt.Familie: Trojan-Dropper.Win32.Agent
No family descriptionExamples
12910D944159E76809661CC49B73073F62FDBA9CD3DD3D98F712C0F711DCFDCD
6D5ABE919711C196FF4B37304C7B0DC6
BF9563B9856F864055D4281DF53E1367
1467C27673540271C6DEDAF9A17953E3
Tactics and Techniques: Mitre*
TA0005
Defense Evasion
The adversary is trying to avoid being detected.
Defense Evasion consists of techniques that adversaries use to avoid detection throughout their compromise. Techniques used for defense evasion include uninstalling/disabling security software or obfuscating/encrypting data and scripts. Adversaries also leverage and abuse trusted processes to hide and masquerade their malware. Other tactics’ techniques are cross-listed here when those techniques include the added benefit of subverting defenses.
Defense Evasion consists of techniques that adversaries use to avoid detection throughout their compromise. Techniques used for defense evasion include uninstalling/disabling security software or obfuscating/encrypting data and scripts. Adversaries also leverage and abuse trusted processes to hide and masquerade their malware. Other tactics’ techniques are cross-listed here when those techniques include the added benefit of subverting defenses.
T1036.002
Masquerading: Right-to-Left Override
Adversaries may abuse the right-to-left override (RTLO or RLO) character (U+202E) to disguise a string and/or file name to make it appear benign. RTLO is a non-printing Unicode character that causes the text that follows it to be displayed in reverse. For example, a Windows screensaver executable named
Adversaries may abuse the RTLO character as a means of tricking a user into executing what they think is a benign file type. A common use of this technique is with Spearphishing Attachment/Malicious File since it can trick both end users and defenders if they are not aware of how their tools display and render the RTLO character. Use of the RTLO character has been seen in many targeted intrusion attempts and criminal activity.(Citation: Trend Micro PLEAD RTLO)(Citation: Kaspersky RTLO Cyber Crime) RTLO can be used in the Windows Registry as well, where regedit.exe displays the reversed characters but the command line tool reg.exe does not by default.
March 25 \u202Excod.scr will display as March 25 rcs.docx. A JavaScript file named photo_high_re\u202Egnp.js will be displayed as photo_high_resj.png.(Citation: Infosecinstitute RTLO Technique)Adversaries may abuse the RTLO character as a means of tricking a user into executing what they think is a benign file type. A common use of this technique is with Spearphishing Attachment/Malicious File since it can trick both end users and defenders if they are not aware of how their tools display and render the RTLO character. Use of the RTLO character has been seen in many targeted intrusion attempts and criminal activity.(Citation: Trend Micro PLEAD RTLO)(Citation: Kaspersky RTLO Cyber Crime) RTLO can be used in the Windows Registry as well, where regedit.exe displays the reversed characters but the command line tool reg.exe does not by default.
* © 2026 The MITRE Corporation. This work is reproduced and distributed with the permission of The MITRE Corporation.