Home Malware Programs Trojans Trojan.Sonso

Trojan.Sonso

Posted: March 1, 2013

Threat Metric

Threat Level: 8/10
Infected PCs: 23
First Seen: March 1, 2013
Last Seen: July 24, 2020
OS(es) Affected: Windows

Trojan.Sonso is a Trojan that opens a back door on the infected computer system. Trojan.Sonso is a Google Chrome browser extension that runs in the system background when Google Chrome is running. If 'chrome://extensions/' or 'chrome://extensions-frame' is opened, Trojan.Sonso diverts the affected web browser to a predefined URL. If Facebook is opened, Trojan.Sonso executes a script located at a predefined URL. Trojan.Sonso then performs a GET request to the specific URL. When the extension runs for the first time, Trojan.Sonso opens Facebook and get.adobe.com/tr/flashplayer in separate web browser windows. An alert box is displayed with the message in Turkish claiming that Flash Player has been updated. Trojan.Sonso attempts to connect to several URLs to execute other malicious scripts. Trojan.Sonso shares itself to the affected PC user's Facebook friends with an image attached from the specific URL.

Technical Details

Additional Information

The following messages's were detected:
# Message
1Adobe Flash Player G++ncellendi.

Loading...