Threat Database Backdoors BackDoor.Bulknet.739

BackDoor.Bulknet.739

By Domesticus in Backdoors

BackDoor.Bulknet.739 is a backdoor Trojan that is able to infect 100 hosts per hour. BackDoor.Bulknet.739 facilitates the sending of numerous spam emails from targeted PCs. BackDoor.Bulknet.739 mostly corrupts PCs located in Italy, France, Turkey, the USA, Mexico and Thailand. BackDoor.Bulknet.739 connects computer systems into botnets and permits attackers to send numerous spam emails. When the malevolent code is run on the infected computer, a Trojan downloader is extracted, after which another application, found as BackDoor.Bulknet.739, drops BackDoor.Bulknet.847. The application uses its hardcoded encrypted list of domain names to select an address to drop the spam module. In response, BackDoor.Bulknet.739 gets the main web page of the website and parses the HTML code in search for the image tag. The encrypted code of the main BackDoor.Bulknet.739 module is stored inside the image tag pair. The module is made to send numerous spam emails.

Aliases

8 security vendors flagged this file as malicious.

Anti-Virus Software Detection
Panda Trj/Genetic.gen
AVG SHeur4.BAQN
McAfee-GW-Edition Heuristic.BehavesLike.Win32.Suspicious.H
AntiVir TR/Crypt.XPACK.Gen
DrWeb BackDoor.Bulknet.739
Kaspersky UDS:DangerousObject.Multi.Generic
Symantec Suspicious.Cloud.5
McAfee Artemis!03D7F43AE26C

Trending

Most Viewed

Loading...