BKDR_CYCBOT.FD
Windows 2000, Windows XP, Windows Server 2003
Threat Type: Backdoor
Destructiveness: No
Encrypted:
In the wild: Yes
OVERVIEW
This backdoor may be unknowingly downloaded by a user while visiting malicious websites.
TECHNICAL DETAILS
286,720 bytes
EXE
Yes
28 Oct 2011
Arrival Details
This backdoor may be unknowingly downloaded by a user while visiting malicious websites.
Other System Modifications
This backdoor modifies the following registry key(s)/entry(ies) as part of its installation routine:
HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\
Services\wscsvc
Start = 4
(Note: The default value data of the said registry entry is 2.)
HKEY_CURRENT_CONFIG\Software\Microsoft\
windows\CurrentVersion\Internet Settings
ProxyEnable = 1
(Note: The default value data of the said registry entry is 0.)
Other Details
This backdoor connects to the following possibly malicious URL:
- http://{BLOCKED}xstored.com/logo.png?tq={values}