Skip to main content

Trojan-Downloader:W32/Kavala

Classification

Category:

Malware

Type:

Trojan-downloader

Aliases:

  • Kavala.[variant]
  • Trojan-Downloader:W32/Kavala.[variant]
  • Trojan-Downloader:JS/Kavala.[variant]
  • Trojan:JS/Kavala.[variant]
  • Trojan:VBS/Kavala.[variant]
  • Trojan:W97M/Kavala.[variant]

Summary

This detection identifies a variant of the Kavala family of harmful programs, which can contact a remote server and download additional files onto the affected machine or device.

Removal

Technical Details

Users typically encounter Kavala variants as files that are attached to email messages.

The contents of the email message usually follow typical social engineering patterns - for example, claiming to be a delivery invoice, business-related document or urgent legal summons - to pressure or trick users into running the attached file. Some examples of the message titles used by these emails include:

  • RE: Payment Pending
  • RE:Attachment Shipping Document
  • Tax refund due
  • Statement of Account

The files attached to the email messages are usually deceptively named. Some examples of file names used include:

  • Case_[random_number].zip
  • Refund.doc.js
  • USPS - Missed package delivery.js

Note that some Kavala files use two or more file endings, such as .doc.js; this is a common trick used by malware authors to deceive users about the nature of a file. The actual filetype will vary depending on the specific Kavala variant, and can be any of the following:

  • A Windows executable file (EXE)
  • A JavaScript file (JS)
  • A Microsoft office document file (W97M)
  • A Visual Basic Script (VBS) file

The F-Secure detection which identified the file as a Kavala variant may also indicate its filetype - for example, the detection 'Trojan:JS/Kavala.D' indicates that it is a JavaScript file.

Protect your devices from malware with F‑Secure Total

Protecting your devices from malicious software is essential for maintaining online security. F‑Secure Total makes this easy, helping you to secure your devices in a brilliantly simple way.

  • Award‑winning antivirus and malware protection

  • Online browsing, banking, and shopping protection

  • 24/7 online identity and data breach monitoring

  • Unlimited VPN service to safe­guard your privacy

  • Password manager with private data protection

Choose how many devices you want to protect to get started.

  • Free customer support

  • Cancel anytime

  • The trial does not obligate you to buy the product

After 30 days your subscription will renew automatically for one year at €69.99.

More Support

Community

Ask questions in our Community.

User guides

Check the user guide for instructions.

Contact Support

Chat with with or call an agent.

Submit a Sample

Submit a file or URL for analysis.