This backdoor may be dropped by TROJ_DROPPER.ADO.
When executed, it executes commands from a remote malicious user to start or stop services, list processes and services, get system information and download files.
It executes commands from a remote malicious user, effectively compromising the affected system.
It retrieves specific information from the affected system.
This backdoor may be dropped by other malware.
Ports used: TCP Port 443
File size: 14,792 bytes
File type: PE
File Compression: UPX
Initial samples received date: 14 Mar 2011
Payload: Steals information
Arrival Details
This backdoor may be dropped by the following malware:
Installation
This backdoor is injected into the following processes running in memory:
NOTES:
Backdoor Routine
This backdoor executes the following commands from a remote malicious user:
- Download files
- Get system information
- List processes and services
- Start or stop services
It connects to the following URL(s) to send and receive commands from a remote malicious user:
Information Theft
This backdoor retrieves the following information from the affected system:
- CPU
- Disk space
- Drive information
- File/Folder list
- Operating system
- Process/Service list
Connect with us on
| | | |