BKDR_FUCOBHA.AB
September 05, 2013
ALIASES:
TrojanSpy:Win32/Fucobha.A(Microsoft), a variant of Win32/Fucobha.A trojan(Eset)
PLATFORM:
Windows 2000, Windows Server 2003, Windows XP (32-bit, 64-bit), Windows Vista (32-bit, 64-bit), Windows 7 (32-bit, 64-bit)
OVERALL RISK RATING:
DAMAGE POTENTIAL:
DISTRIBUTION POTENTIAL:
REPORTED INFECTION:
INFORMATION EXPOSURE:
Threat Type: Backdoor
Destructiveness: No
Encrypted:
In the wild: Yes
OVERVIEW
This backdoor may be dropped by other malware.
TECHNICAL DETAILS
File Size: 78,336 bytes
File Type: DLL
Memory Resident: Yes
Initial Samples Received Date: 02 Sep 2013
Arrival Details
This backdoor may be dropped by other malware.
Other Details
This backdoor connects to the following possibly malicious URL:
- http://{BLOCKED}v.com/jd/upload.aspx?filepath=info&filename={Host Name}_{Local IP Address}.jpg
- http://{BLOCKED}v.com/jd/order/{Host Name}_{Local IP Address}.jpg
- http://{BLOCKED}v.com/jd/upload.aspx?filepath=ok&filename={Host Name}_{Local IP Address}.jpg