Infection Channel: Dropped by other malware
This backdoor may be dropped by other malware.
It executes commands from a remote malicious user, effectively compromising the affected system. It connects to a website to send and receive information.
File size: 126,422 bytes
File type: EXE
Memory resident: Yes
Initial samples received date: 21 Mar 2012
Payload: Compromises system security
Arrival Details
This backdoor may be dropped by the following malware:
Installation
This backdoor drops the following copies of itself into the affected system:
- %Windows%\Temp\{random}.dat
(Note: %Windows% is the Windows folder, which is usually C:\Windows or C:\WINNT.)
It drops the following files:
- %User Temp\print32.dll - also detected as BKDR_VISEL.FQ
Backdoor Routine
This backdoor executes the following commands from a remote malicious user:
- Perform shell command
- Download and execute files
- Send system information (IP address, user name, operating system)
It connects to the following websites to send and receive information:
Connect with us on
| | | |