This backdoor arrives on a system as a file dropped by other malware or as a file downloaded unknowingly by users when visiting malicious sites.
It deletes itself after execution.
File size: 128,871 bytes
File type: EXE
Memory resident: No
Initial samples received date: 22 Oct 2012
Arrival Details
This backdoor arrives on a system as a file dropped by other malware or as a file downloaded unknowingly by users when visiting malicious sites.
Other System Modifications
This backdoor adds the following registry keys:
HKEY_LOCAL_MACHINE\software\microsoft\
windows\currentversion\Policies\
Explorer\Run
It adds the following registry entries:
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\
Windows\CurrentVersion\policies\
Explorer\Run
4048 = "%User Temp%\msvakbw.com"
Dropping Routine
This backdoor drops the following files:
Other Details
This backdoor deletes itself after execution.
Connect with us on
| | | |