Threat Database Backdoors Backdoor.Nineblog

Backdoor.Nineblog

By GoldSparrow in Backdoors

Threat Scorecard

Ranking: 6,592
Threat Level: 20 % (Normal)
Infected Computers: 4,927
First Seen: August 7, 2013
Last Seen: September 13, 2023
OS(es) Affected: Windows

Backdoor.Nineblog is a backdoor Trojan that opens a back door on the corrupted PC. Once run, Backdoor.Nineblog creates the infected files. Backdoor.Nineblog also creates the registry entry so that it can run automatically every time the PC user starts Windows. Backdoor.Nineblog contacts the specific remote location. Backdoor.Nineblog transmits the specific information such as the Host name and the list of running processes to the remote location. Backdoor.Nineblog then opens a back door and may drop and execute other Visual Basic scripts on the corrupted PC.

File System Details

Backdoor.Nineblog may create the following file(s):
# File Name Detections
1. %Windir%\Tasks\Microsoft-Experance-Improve.job
2. %UserProfile%\Application Data\Microsoft\Windows\Microsoft-Experance-Improve.vbe
3. %UserProfile%\Application Data\RECYCLER\desktop.ini
4. %UserProfile%\Application Data\RECYCLER\Microsoft-Windows-DiskCleaner.vbe

Registry Details

Backdoor.Nineblog may create the following registry entry or registry entries:
HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Run\Microsoft-Windows-DiskCleaner\"wscript.exe" = "%DriveLetter%\Documents and Settings\Administrator\Application Data\RECYCLER\Microsoft-Windows-DiskCleaner.vbe"

URLs

Backdoor.Nineblog may call the following URLs:

fbmedia-lys.com

Trending

Most Viewed

Loading...