Threat Database Backdoors Backdoor.Win32.Agent.dboe

Backdoor.Win32.Agent.dboe

By Sumo3000 in Backdoors

Threat Scorecard

Ranking: 14,404
Threat Level: 80 % (High)
Infected Computers: 1,448
First Seen: April 22, 2013
Last Seen: July 31, 2023
OS(es) Affected: Windows

Backdoor.Win32.Agent.dboe is a backdoor Trojan, which connects to the C&C server 'mailsgoogle.com'. The C&C directs to the specific IP-address in the Netherlands, but this is a dedicated server provided for renting by Russian telecommunications firm Hostkey. Backdoor.Win32.Agent.dboe creates the process name 'explorer.exe, and embeds itself into it. Backdoor.Win32.Agent.dboe creates text strings byte-by-byte along its whole extent to obfuscate its occurrence. When 'explorer.exe' has been detected in memory, Backdoor.Win32.Agent.dboe embeds a part of itself into that process and remotely initiates a thread of its code in the context of 'explorer.exe'. This thread runs all the main tasks of Backdoor.Win32.Agent.dboe. Despite the fact that Backdoor.Win32.Agent.dboe is set to be executed only once when the OS is launched, after Backdoor.Win32.Agent.dboe has been added into 'explorer.exe' it generates a particular mutex to evade running multiple instances at the same time.

File System Details

Backdoor.Win32.Agent.dboe may create the following file(s):
# File Name Detections
1. agentm.exe
2. images.gif

Trending

Most Viewed

Loading...