Threat Database Backdoors Backdoor.Dorkbot.ADDA

Backdoor.Dorkbot.ADDA

By CagedTech in Backdoors

Threat Scorecard

Threat Level: 60 % (Medium)
Infected Computers: 6
First Seen: November 28, 2022
Last Seen: March 1, 2026
OS(es) Affected: Windows

The detection of Backdoor.Dorkbot.ADDA on your system indicates a potential security threat that requires immediate attention. This backdoor threat can allow unauthorized access to your computer, compromising your personal data and system security. It is essential to understand the nature of this threat and take prompt action to remove it and prevent future infections.

What Is Backdoor.Dorkbot.ADDA?

Backdoor.Dorkbot.ADDA is a type of backdoor threat that can provide unauthorized access to your computer, allowing hackers to remotely control your system, steal sensitive information, or use your computer for malicious activities. Backdoor threats are designed to remain hidden and can be challenging to detect, making them a significant security concern. The name Backdoor.Dorkbot.ADDA suggests that it may be related to the Dorkbot malware family, known for its backdoor capabilities, but without further information, it's crucial to focus on the general characteristics of backdoor threats and the steps to remove them.

How Backdoor.Dorkbot.ADDA Operates

Backdoor threats like Backdoor.Dorkbot.ADDA typically operate by creating a covert communication channel between your computer and a command and control (C2) server controlled by the attacker. This channel allows the attacker to send commands to your computer, which can include instructions to steal data, install additional malware, or use your computer for malicious activities such as spamming or participating in distributed denial-of-service (DDoS) attacks. These threats can be spread through various means, including exploited vulnerabilities, phishing emails, or infected software downloads.

Symptoms of Infection

Symptoms of a Backdoor.Dorkbot.ADDA infection can be subtle and may not always be immediately apparent. However, some common indicators of a backdoor infection include unusual network activity, slow system performance, unexpected changes to system settings, or the presence of unfamiliar programs. If you suspect that your computer is infected, it's crucial to act quickly to minimize the potential damage.

How to Remove Backdoor.Dorkbot.ADDA

  1. Boot your computer in Safe Mode with Networking to prevent the malware from loading and to allow for a more effective removal process.
  2. Use a reputable anti-malware tool, such as SpyHunter, to perform a full scan of your system. This can help detect and remove the Backdoor.Dorkbot.ADDA threat and any associated malware.
  3. Uninstall any suspicious programs that you do not recognize or that were installed without your consent. Be cautious and only remove programs that you are sure are malicious to avoid damaging your system.
  4. Reset your web browsers, including Chrome, Firefox, and Edge, to their default settings to remove any malicious extensions or settings that the malware may have altered.
  5. Reboot your computer and perform another full scan with your anti-malware tool to ensure that the threat has been completely removed.

Conclusion

The removal of Backdoor.Dorkbot.ADDA requires careful and immediate action to protect your system and personal data. By following the steps outlined above and maintaining good security practices, such as keeping your software up to date, using strong antivirus protection, and being cautious with emails and downloads, you can significantly reduce the risk of future infections. Remember, vigilance and proactive security measures are key to safeguarding your digital security in the face of evolving threats like Backdoor.Dorkbot.ADDA.

Analysis Report

General information

Family Name: Backdoor.Dorkbot.ADDA
Signature status: No Signature

Known Samples

MD5: 5862d5491756469d6aa60276af1ff75b
SHA1: d77d2b8edcc10451750a5d0ce3d4c71c5edd5143
SHA256: 675399D5D63A84240089BBBF67C0B133A128A38A8251E4B923D026B30DD1169A
File Size: 389.12 KB, 389120 bytes
MD5: 511891a7a129e2756a2d50134fc09aa2
SHA1: 43c6f853ae938eb2d484fbbe8452c149eb50aac5
SHA256: 1EA362EF4651F429034BE2DFA27F68FF36714EF3DE9541F65A9C2A5E909A0A97
File Size: 166.91 KB, 166912 bytes

Windows Portable Executable Attributes

  • File doesn't have "Rich" header
  • File doesn't have debug information
  • File doesn't have exports table
  • File doesn't have relocations information
  • File doesn't have security information
  • File has exports table
  • File is 32-bit executable
  • File is console application (IMAGE_SUBSYSTEM_WINDOWS_CUI)
  • File is either console or GUI application
  • File is GUI application (IMAGE_SUBSYSTEM_WINDOWS_GUI)
Show More
  • File is Native application (NOT .NET application)
  • File is not packed
  • IMAGE_FILE_DLL is not set inside PE header (Executable)
  • IMAGE_FILE_EXECUTABLE_IMAGE is set inside PE header (Executable Image)

File Icons

Windows PE Version Information

Name Value
Company Name
  • Delcam
  • Microsoft Corporation
File Description IE 7.0 Unattended Install Utility
File Version
  • 8.00.7601.17514 (win7sp1_rtm.101119-1850)
  • 1, 3, 0, 0
Internal Name
  • ArtSpool
  • IEUNATT
Legal Copyright
  • Copyright © Delcam 2007
  • © Microsoft Corporation. All rights reserved.
Original Filename
  • ArtSpool
  • IEUNATT.EXE
Product Name
  • ArtSpool Application
  • Windows® Internet Explorer
Product Version
  • 8.00.7601.17514
  • 1, 3, 0, 0

File Traits

  • 2+ executable sections
  • HighEntropy
  • Installer Manifest
  • Installer Version
  • x86

Block Information

Total Blocks: 548
Potentially Malicious Blocks: 1
Whitelisted Blocks: 546
Unknown Blocks: 1

Visual Map

0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 2 2 0 0 0 2 3 1 0 1 1 0 0 0 0 2 0 0 0 0 0 1 0 0 0 1 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 1 0 0 0 0 1 0 0 0 0 0 0 0 0 0 0 0 0 2 2 0 2 0 0 2 0 0 0 2 2 2 2 2 0 0 0 0 0 1 1 0 1 0 0 0 1 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 1 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 1 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 1 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 1 0 0 1 0 0 0 2 2 2 2 2 2 2 2 2 2 2 2 2 2 2 2 2 2 2 2 2 2 2 2 2 2 2 2 2 2 2 2 2 2 2 2 2 2 2 2 2 2 2 0 2 2 2 2 2 2 2 2 2 2 2 2 2 2 2 2 2 2 2 2 2 2 2 2 2 2 2 2 2 2 2 2 2 2 2 2 2 2 2 2 2 2 2 2 2 2 2 2 2 2 2 2 2 2 2 2 2 2 2 2 2 2 2 2 2 2 2 2 2 2 2 2 2 2 2 2 2 2 2 2 2 2 2 2 2 2 2 2 2 2 2 2 2 2 2 2 2 2 2 2 2 2 2 2 2 2 2 2 2 2 1 2 2 2 2 2 2 2 2 2 2 2 2 2 2 2 2 2 2 2 2 0 0 0 0 1 0 1 0 1 0 0 0 0 1 0 0 0 0 1 1 3 1 1 1 0 1 0 1 1 0 0 0 1 0 0 0 0 0 0 0 0 0 0 0 1 0 1 1 0 0 0 0 0 0 ? x
0 - Probable Safe Block
? - Unknown Block
x - Potentially Malicious Block

Similar Families

  • Agent.AE
  • Agent.HGG
  • Agent.MAJ
  • Injector.MFA
  • Phorpiex.O
Show More
  • Trojan.Kryptik.Gen.AYK

Files Modified

File Attributes
c:\windows\panther\unattendgc\diagerr.xml Generic Read,Write Data,Write Attributes,Write extended,Append data
c:\windows\panther\unattendgc\diagwrn.xml Generic Read,Write Data,Write Attributes,Write extended,Append data
c:\windows\panther\unattendgc\setupact.log Generic Read,Write Data,Write Attributes,Write extended,Append data
c:\windows\panther\unattendgc\setuperr.log Generic Read,Write Data,Write Attributes,Write extended,Append data

Registry Modifications

Key::Value Data API Name
HKLM\system\controlset001\services\sharedaccess\parameters\firewallpolicy\standardprofile\authorizedapplications\list::c:\users\user\downloads\d77d2b8edcc10451750a5d0ce3d4c71c5edd5143_0000389120 c:\users\user\downloads\d77d2b8edcc10451750a5d0ce3d4c71c5edd5143_0000389120:*:enabled:@shell32.dll,-1 RegNtPreCreateKey
HKLM\system\controlset001\services\sharedaccess\parameters\firewallpolicy\standardprofile\authorizedapplications\list::c:\users\user\downloads\43c6f853ae938eb2d484fbbe8452c149eb50aac5_0000166912 c:\users\user\downloads\43c6f853ae938eb2d484fbbe8452c149eb50aac5_0000166912:*:enabled:@shell32.dll,-1 RegNtPreCreateKey

Windows API Usage

Category API
Anti Debug
  • IsDebuggerPresent

Related Posts

Trending

Most Viewed

Loading...