BKDR_CYCBOT.FD

 Analysis by: Erika Bianca Mendoza

 PLATFORM:

Windows 2000, Windows XP, Windows Server 2003

 OVERALL RISK RATING:
 DAMAGE POTENTIAL:
 DISTRIBUTION POTENTIAL:
 REPORTED INFECTION:

  • Threat Type: Backdoor

  • Destructiveness: No

  • Encrypted:

  • In the wild: Yes

  OVERVIEW

This backdoor may be unknowingly downloaded by a user while visiting malicious websites.

  TECHNICAL DETAILS

File Size:

286,720 bytes

File Type:

EXE

Memory Resident:

Yes

Initial Samples Received Date:

28 Oct 2011

Arrival Details

This backdoor may be unknowingly downloaded by a user while visiting malicious websites.

Other System Modifications

This backdoor modifies the following registry key(s)/entry(ies) as part of its installation routine:

HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\
Services\wscsvc
Start = 4

(Note: The default value data of the said registry entry is 2.)

HKEY_CURRENT_CONFIG\Software\Microsoft\
windows\CurrentVersion\Internet Settings
ProxyEnable = 1

(Note: The default value data of the said registry entry is 0.)

Other Details

This backdoor connects to the following possibly malicious URL:

  • http://{BLOCKED}xstored.com/logo.png?tq={values}