BKDR_RADMIN.P
January 15, 2015
ALIASES:
RemAdm-RemoteAdmin. (McAfee); Trojan.Win32.Generic!BT (Sunbelt); TR/Virtl.9946 (Avira); Riskware/RAdmin (Fortinet)
PLATFORM:
Windows
OVERALL RISK RATING:
DAMAGE POTENTIAL:
DISTRIBUTION POTENTIAL:
REPORTED INFECTION:
INFORMATION EXPOSURE:
Threat Type: Backdoor
Destructiveness: No
Encrypted:
In the wild: Yes
OVERVIEW
This backdoor arrives on a system as a file dropped by other malware or as a file downloaded unknowingly by users when visiting malicious sites.
It listens on ports.
TECHNICAL DETAILS
File Size:
287,232 bytes
File Type:
EXE
Initial Samples Received Date:
13 Jan 2015
Arrival Details
This backdoor arrives on a system as a file dropped by other malware or as a file downloaded unknowingly by users when visiting malicious sites.
Backdoor Routine
This backdoor listens on the following ports:
- 4899
NOTES:
It reads the following driver:
- \\.\raddrv
It reads the following registry:
- HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Msdtc\Parameters