Threat Database Backdoors Backdoor.Grexden

Backdoor.Grexden

By GoldSparrow in Backdoors

Threat Scorecard

Ranking: 12,171
Threat Level: 10 % (Normal)
Infected Computers: 574
First Seen: May 8, 2014
Last Seen: September 18, 2023
OS(es) Affected: Windows

Backdoor.Grexden is a backdoor Trojan that may open a back door on the targeted PC. Backdoor.Grexden is commonly downloaded by a specially crafted document which exploits the Microsoft Windows Common Controls ActiveX Control Remote Code Execution Vulnerability (CVE-2012-0158). Once executed, Backdoor.Grexden creates potentially infected files. Backdoor.Grexden also creates registry entries under the certain registry subkey. Backdoor.Grexden then connects to the remote locations. Backdoor.Grexden may then carry out potentially harmful activities on the computer system such as download files, move files, create processes and enumerate the file system.

File System Details

Backdoor.Grexden may create the following file(s):
# File Name Detections
1. C:\Documents and Settings\\Application Data\Microsoft\Network\encrypt.dat
2. C:\Documents and Settings\\Application Data\Microsoft\Network\MSNETWORK.DLL

Registry Details

Backdoor.Grexden may create the following registry entry or registry entries:
HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\WinSock2\Parameters\Protocol_Catalog9\Catalog_Entries

Trending

Most Viewed

Loading...