Threat Database Trojans TROJ_FYNLOSKI.BU

TROJ_FYNLOSKI.BU

By GoldSparrow in Trojans

Threat Scorecard

Threat Level: 90 % (High)
Infected Computers: 137
First Seen: May 7, 2013
Last Seen: May 9, 2023
OS(es) Affected: Windows

TROJ_FYNLOSKI.BU is a Trojan that is distributed via AutoIt, a flexible scripting language in Windows, through compromised websites such as Pastebin and Pastie. The websites include a malevolent AutoIt tool code, which is used by cybercriminals to corrupt PCs with TROJ_FYNLOSKI.BU. TROJ_FYNLOSKI.BU is a variation of the well-known DarkComet RAT written using AutoIt. TROJ_FYNLOSKI.BU runs a backdoor on the targeted computer and communicates outbound to a treacherous host. TROJ_FYNLOSKI.BU also makes changes to the local software firewall policies to disable them, in addition to installing itself at startup for persistence. Once executed, TROJ_FYNLOSKI.BU also adds the harmful file. After execution, TROJ_FYNLOSKI.BU immediately disables the Windows Firewall. After disabling the firewall, TROJ_FYNLOSKI.BU then disables the ability to get into the Windows Registry to view or undo the alterations made. In an effort to do so, TROJ_FYNLOSKI.BU shows the error message.

File System Details

TROJ_FYNLOSKI.BU may create the following file(s):
# File Name Detections
1. tb2323xt.exe

Messages

The following messages associated with TROJ_FYNLOSKI.BU were found:

Registry editing has been disabled by your administrator.

Trending

Most Viewed

Loading...