BKDR_POSTBOT.AUSR
October 26, 2016
ALIASES:
Backdoor.Muirim (Norton)
PLATFORM:
Windows
OVERALL RISK RATING:
DAMAGE POTENTIAL:
DISTRIBUTION POTENTIAL:
REPORTED INFECTION:
INFORMATION EXPOSURE:
Threat Type: Backdoor
Destructiveness: No
Encrypted:
In the wild: Yes
OVERVIEW
This backdoor arrives on a system as a file dropped by other malware or as a file downloaded unknowingly by users when visiting malicious sites.
TECHNICAL DETAILS
File Size:
450,560 bytes
File Type:
EXE
Initial Samples Received Date:
21 Oct 2016
Arrival Details
This backdoor arrives on a system as a file dropped by other malware or as a file downloaded unknowingly by users when visiting malicious sites.
Other System Modifications
This backdoor adds the following registry entries:
HKEY_CURRENT_USER\Software\Microsoft\
Windows\CurrentVersion\Explorer
MMID = "{8 random characters}"
Other Details
This backdoor connects to the following possibly malicious URL:
- www.{BLOCKED}one1.com/admin/design/sign/admin.php
- {BLOCKED}one1.net/admin/design/sign/admin.php