Threat Database Backdoors Backdoor.Betwem

Backdoor.Betwem

By GoldSparrow in Backdoors

Threat Scorecard

Popularity Rank: 14,121
Threat Level: 90 % (High)
Infected Computers: 41
First Seen: September 19, 2014
Last Seen: August 7, 2026
OS(es) Affected: Windows

Backdoor.Betwem is a deceptive backdoor Trojan horse that may end up on a vulnerable system that does not have many security protection measures in place. When loaded on a computer, Backdoor.Betwem is apt to running in the background where it could go undetected for a long time while it performs unknown malicious actions. The backdoor functions of Backdoor.Betwem may allow remote attackers to connect to an infected system. In doing so, remote hackers may be able to steal or gather data from the infected computer’s hard drive and use it in cases that lead to identity theft or other serious issues. Putting a rest to these potential issues is a situation that may require complete removal of Backdoor.Betwem, which can be done through use of an antimalware application.

Analysis Report

General information

Family Name: Trojan.Upatre.VD
Signature status: No Signature

Known Samples

MD5: 17d9d0304e1bcb610465ee8758e71135
SHA1: 1352b3b5eb71b979c0c1089acbe305e204cc0ce9
SHA256: 3BD44BEBA7B784EAA5967255800FE3707EA09C9A66DCAB13116E29857856121D
File Size: 51.50 KB, 51504 bytes

Windows Portable Executable Attributes

  • File doesn't have "Rich" header
  • File doesn't have debug information
  • File doesn't have exports table
  • File doesn't have relocations information
  • File doesn't have security information
  • File is 32-bit executable
  • File is either console or GUI application
  • File is GUI application (IMAGE_SUBSYSTEM_WINDOWS_GUI)
  • File is Native application (NOT .NET application)
  • File is not packed
Show More
  • IMAGE_FILE_DLL is not set inside PE header (Executable)
  • IMAGE_FILE_EXECUTABLE_IMAGE is set inside PE header (Executable Image)

File Icons

File Traits

  • No Version Info
  • x86

Block Information

Total Blocks: 15
Potentially Malicious Blocks: 6
Whitelisted Blocks: 4
Unknown Blocks: 5

Visual Map

x ? ? x 0 1 x ? ? x x x ? 0 0
0 - Probable Safe Block
? - Unknown Block
x - Potentially Malicious Block

Files Modified

File Attributes
c:\users\user\appdata\local\temp\ffengh.exe Generic Write,Read Attributes

Registry Modifications

Key::Value Data API Name
HKCU\software\microsoft\windows\currentversion\internet settings\zonemap::proxybypass  RegNtPreCreateKey
HKCU\software\microsoft\windows\currentversion\internet settings\zonemap::intranetname  RegNtPreCreateKey
HKCU\software\microsoft\windows\currentversion\internet settings\zonemap::uncasintranet  RegNtPreCreateKey
HKCU\software\microsoft\windows\currentversion\internet settings\zonemap::autodetect RegNtPreCreateKey
HKCU\software\microsoft\windows\currentversion\internet settings\zonemap::proxybypass  RegNtPreCreateKey
HKCU\software\microsoft\windows\currentversion\internet settings\zonemap::intranetname  RegNtPreCreateKey
HKCU\software\microsoft\windows\currentversion\internet settings\zonemap::uncasintranet  RegNtPreCreateKey
HKCU\software\microsoft\windows\currentversion\internet settings\zonemap::autodetect RegNtPreCreateKey
HKLM\software\microsoft\windows nt\currentversion\notifications\data::418a073aa3bc1c75 �n/ �v �Z����Bx#��(�1`1�1HO5�0<.:@V�A��H[uH�pN$b"hk`k�ql(�w�n{b��P���!�/����� ���3���������X�������.�m�Ù��gi�V����$�8წ���l��&MA�~�=�SB1_B��T�Vw���%���� RegNtPreCreateKey
HKLM\software\microsoft\windows nt\currentversion\notifications\data::418a073aa3bc1c75 �n0 �v �Z����Bx#��(�1`1�1HO5�0<.:@V�A��H[uH�pN$b"hk`k�ql(�w�n{b��P���!�/����� ���3���������X�������.���m�Ù��gi�V����$�8წ���l��&MA�~�=�SB1_B��T�Vw���%�� RegNtPreCreateKey
Show More
HKLM\software\microsoft\windows nt\currentversion\notifications\data::418a073aa3bc3475 鴵ȁ獖} RegNtPreCreateKey
HKLM\software\microsoft\windows nt\currentversion\notifications\data::418a073aa3bc1c75 �n5 �v �Z����Bx#��(�1`1�1HO5�0<.:@V�A��H[uH�pN$b"hk`k�ql(�w�n{b��P���!�/������7� ���3�M���������X�������.���m�Ù��IV�gi�V����$�8წ���l��&M�(!��jA�~��=� RegNtPreCreateKey

Windows API Usage

Category API
Process Manipulation Evasion
  • NtUnmapViewOfSection
Process Shell Execute
  • ShellExecute

Shell Command Execution

open C:\Users\Ayvuocvh\AppData\Local\Temp\ffengh.exe