BKDR_CYCBOT.FD
October 09, 2012
PLATFORM:
Windows 2000, Windows XP, Windows Server 2003
OVERALL RISK RATING:
DAMAGE POTENTIAL:
DISTRIBUTION POTENTIAL:
REPORTED INFECTION:
![](/vinfo/imgFiles/legend.jpg)
Threat Type: Backdoor
Destructiveness: No
Encrypted:
In the wild: Yes
OVERVIEW
This backdoor may be unknowingly downloaded by a user while visiting malicious websites.
TECHNICAL DETAILS
File Size: 286,720 bytes
File Type: EXE
Memory Resident: Yes
Initial Samples Received Date: 28 Oct 2011
Arrival Details
This backdoor may be unknowingly downloaded by a user while visiting malicious websites.
Other System Modifications
This backdoor modifies the following registry key(s)/entry(ies) as part of its installation routine:
HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\
Services\wscsvc
Start = 4
(Note: The default value data of the said registry entry is 2.)
HKEY_CURRENT_CONFIG\Software\Microsoft\
windows\CurrentVersion\Internet Settings
ProxyEnable = 1
(Note: The default value data of the said registry entry is 0.)
Other Details
This backdoor connects to the following possibly malicious URL:
- http://{BLOCKED}xstored.com/logo.png?tq={values}