Packer: WinLicense
Compilation date: 16.07.2017 06:09:50
SHA1:
- a77d43993ba690fda5c35ebe4ea2770e749de373 (spwinres.dll, x64)
Description
Trojan.Belonard.4 is an older part of the Belonard trojan. A more recent version of this module is Trojan.Belonard.6. The original file name: kernel.dll.
The main differences compared to the later version:
- An older algorithm is used for encrypting some of the code lines.
- Trojan.Belonard.4 contacts the C&C server less often than the later versions. It also doesn’t work with the wmcodecs.dll (Trojan.Belonard.8) and ssdp32.dll (Trojan.Belonard.8) files.
- It downloads only wmcodecs.dll (Trojan.Belonard.8) and spwinres.dll (Trojan.Belonard.8).