Home Malware Programs Trojans Trj/GdSda.A

Trj/GdSda.A

Posted: July 25, 2017

Threat Metric

Threat Level: 8/10
Infected PCs: 30
First Seen: July 25, 2017
Last Seen: February 18, 2022
OS(es) Affected: Windows

Trj/GdSda.A is a detection name used to label a Trojan, which may allow cyber crooks to collect data from the infected computer. This Trojan is unable to spread itself like a worm so that it relies on distribution campaigns launched by its operators primarily. The ways to spread Trj/GdSda.A are numerous, but it is likely that the cyber crooks operating this Trojan will rely on spam e-mails, infected game cracks, pirated software, and other illicit digital content. Users who end up executing this Trojan on their computers unknowingly are unlikely to notice anything suspicious at first, because this threat is meant to stay as quiet as possible while it exfiltrates data from the victim's machine.

According to an analysis performed by security researchers, Trj/GdSda.A is able to take screenshots from the user's computer, as well as to collect the login credentials used by various pieces of software automatically, which appear to be mostly FTP clients, online poker clients, and various messaging services such as the Yahoo! Messenger, MSN and others. Unfortunately, Trj/GdSda.A also is able to access the saved usernames and passwords in popular Web browsers like Mozilla Firefox, Google Chrome, and Internet Explorer, so that this gives this threat the ability to cause quite a lot of damage if it is not stopped on time.

The data is collected over a random period quietly, and it is then transmitted to a remote Command & Control server operated by the attacker. Since Trj/GdSda.A does not display any symptoms the only way to make sure you will not have to deal with the problems it can cause is to use a credible anti-virus software suite.

Loading...