Threat Database Trojans Troj/Agent-YDC

Troj/Agent-YDC

By Domesticus in Trojans

Threat Scorecard

Threat Level: 90 % (High)
Infected Computers: 16
First Seen: October 9, 2012
Last Seen: February 2, 2021
OS(es) Affected: Windows

Troj/Agent-YDC Image

There's a Skype-based scam that aims to integrate victims' computers to the Dorkbot botnet. Troj/Agent-YDC is an essential piece of this scam which involves a social engineering component, a malicious worm, a backdoor Trojan, and the Dorkbot botnet. Troj/Agent-YDC itself is the backdoor Trojan component of this dangerous attack. Computer users may become infected with the Troj/Agent-YDC Trojan after clicking on a link included in a suspicious Skype instant message that is sent by a computer infected with a worm. Once installed, Troj/Agent-YDC makes changes to the infected computer that allows criminals to gain access to the infected computer from a remote location. Using Troj/Agent-YDC, criminals can integrate the infected system into a vast botnet known as Dorkbot. This botnet is used to carry out illegal activities that range from DdoS and spam email to money laundering.

Most victims' first contact with Troj/Agent-YDC is through a malicious spam message on Skype. This message is sent out by computers that have been infected with a worm. This worm uses the infected computer's Skype account to send messages like 'lol is this your new profile pic?' which also includes a URL that, to trick the victim more effectively, includes the victim's Skype user name. Clicking on this link downloads a ZIP file that supposedly contains an image file. This ZIP file can be named skype_08102012_image.zip or with a similar name that follows the same pattern. Of course, this ZIP file does not contain an image. Rather, it contains the Troj/Agent-YDC Trojan's executable files which run instantly as soon as the malicious ZIP archive is retrieved.

Once installed, Troj/Agent-YDC makes changes to the Windows Registry to ensure that Troj/Agent-YDC is executed as soon as the infected computer starts up. Troj/Agent-YDC also installs a backdoor (an unauthorized opening in the infected computer's security). Using this backdoor, criminals can access the infected computer in order to install other malware, steal information or control the infected computer from a remote location. Troj/Agent-YDC is used to install a RAT that allows criminals to integrate the infected computer into the Dorkbot botnet. This infamous botnet is used to carry out numerous illegal activities, some of which include sending out malicious Skype spam messages to infect further computers with the Troj/Agent-YDC Trojan.

File System Details

Troj/Agent-YDC may create the following file(s):
# File Name Detections
1. %PROFILE%\Application Data\Jqfsfb.exe
2. skype_08102012_image.zip
3. skype_06102012_image.zip

Registry Details

Troj/Agent-YDC may create the following registry entry or registry entries:
HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Run "Skype " = "C:\Documents and Settings\support\Application Data\Jqfsfb.exe"

Trending

Most Viewed

Loading...