Infection Channel: Downloaded from the Internet
This is a backdoor builder written in Java. It has been seen as a free download in underground forums. This opens a possibility that malicious users may use this tool to create a connect-back client .JAR file on the infected computer.
To get a one-glance comprehensive view of the behavior of this Backdoor, refer to the Threat Diagram shown below.

This is a backdoor remote access tool (RAT) builder written in Java. It is capable of creating a client .JAR file to allow attackers to control a system.
This backdoor arrives on a system as a file dropped by other malware or as a file downloaded unknowingly by users when visiting malicious sites.
File size: 1,832,132 bytes
File type: JAR
Initial samples received date: 14 Feb 2013
Payload: Terminates processes
Arrival Details
This backdoor arrives on a system as a file dropped by other malware or as a file downloaded unknowingly by users when visiting malicious sites.
NOTES:
This is a backdoor remote access tool (RAT) builder written in Java.
It is capable of creating a client .JAR file to allow attackers to control a system. It may execute the following commands to an infected system:
- Capture Screenshots
- Download and execute files
- Get passwords from browsers and messengers
- List and kill processes
- Manage files
- Open URL in a browser
- Perform DOS attack
- Reboot
- Send pop-up messages
- Stop Connection
- Uninstall
- Update copy
It contains an option to kill the following specific anti-malware related processes:
- AVG
- Avira Internet Security
- Kaspersky PURE
- Malwarebytes Anti-Malware
- McAfee
- MsConfig
- Nod32
- Norton
- Task Manager
- UAC
- Windows Defender
It also contains an option to encrypt its class files and install plug-ins. It has the option to set an autostart registry or scheduled task to enable automatic execution every system startup.
Connect with us on
| | | |