Threat Database Backdoors Backdoor.Whalfrost

Backdoor.Whalfrost

By Sumo3000 in Backdoors

Threat Scorecard

Threat Level: 20 % (Normal)
Infected Computers: 117
First Seen: February 8, 2012
Last Seen: November 3, 2022
OS(es) Affected: Windows

Backdoor.Whalfrost is a hazardous backdoor Trojan infection that opens a back door on the infected computer system for enabling cybercriminals to gain remote access and control over the compromised PC. Backdoor.Whalfrost can collect and steal its victim's confidential data and transmit it to remote cybercriminals. Backdoor.Whalfrost may also drop other malicious system files onto the affected computer. Backdoor.Whalfrost also modifies the registry so that it can load each time you boot up Windows. Backdoor.Whalfrost can block your firewall and anti-virus software. Backdoor.Whalfrost may propagate by exploiting certain system vulnerabilities. Backdoor.Whalfrost attempts to contact a command and control (C&C) server in order to get commands from remote hackers to perform damaging actions on the corrupted PC. Uninstall Backdoor.Whalfrost before it harms your computer.

File System Details

Backdoor.Whalfrost may create the following file(s):
# File Name Detections
1. %UserProfile%\Application Data\msupdater.exe
2. %UserProfile%\Application Data\FAVORITES.DAT

Registry Details

Backdoor.Whalfrost may create the following registry entry or registry entries:
HKEY_CURRENT_USER\Software\Microsoft\Windows NT\CurrentVersion\Winlogon\"Shell" = "Explorer.exe "%UserProfile%\Application Data\msupdater.exe""

URLs

Backdoor.Whalfrost may call the following URLs:

initiaterecentmostthefile.vip

Trending

Most Viewed

Loading...