Threat Database Backdoors Backdoor:Win32/Bezigate.B

Backdoor:Win32/Bezigate.B

By Domesticus in Backdoors

Threat Scorecard

Threat Level: 60 % (Medium)
Infected Computers: 34
First Seen: September 25, 2013
Last Seen: March 24, 2022
OS(es) Affected: Windows

Backdoor:Win32/Bezigate.B is a backdoor Trojan that permits cybercrooks to obtain remote unauthorized access and control of the targeted PC. Backdoor:Win32/Bezigate.B can accomplish various potentially harmful activities on the corrupted PC, incorporating but not limited to stealing sensitive details and files and transmitting them to a distant server. Backdoor:Win32/Bezigate.B drops and executes copies of itself in one of several folders (%current directory%, %windir% and %APPDATA%), as any of the file names. Backdoor:Win32/Bezigate.B modifies the Windows Registry to make sure that it can load automatically whenever the computer user boots up the affected computer. Backdoor:Win32/Bezigate.B tries to communicate with cybercrooks using the particular combinations of URLs and ports. Backdoor:Win32/Bezigate.B can create/remove/copy/move/modify files and folders, kill and start processes, steal information about the PCr, enumerate and make modifications to the Windows Registry, enumerate/modify/start/end running services, open and close Internet browser windows, retrieve files from the PC and transfer them to the cybercriminal, log keystrokes and steal private details.

SpyHunter Detects & Remove Backdoor:Win32/Bezigate.B

File System Details

Backdoor:Win32/Bezigate.B may create the following file(s):
# File Name MD5 Detections
1. file.exe 912d940cd2652d092cca54a8d6fad54c 1
2. microdbs.exe
3. msizap.exe
4. spsreng.exe
5. 456.exe
6. msiexc.exe
7. mypass.exe
8. xtreme.exe
9. 123.exe
10. mscon.exe
11. msupdt32.exe
12. stub2546.exe
13. file.exe 6b93722a18630cf1d2ed71f133041e01 0

Registry Details

Backdoor:Win32/Bezigate.B may create the following registry entry or registry entries:
HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Run "[malware file name]" for example, "456" = "[malware file path]" for example, "C:\Windows\456.exe"

URLs

Backdoor:Win32/Bezigate.B may call the following URLs:

78.184.197.86 1604
abdelsamed666.no-ip.com 5050
all.evilpacket.org 7709
barod.no-ip.biz 1515
ermenello.servegame.com 4781
fofo-123.no-ip.biz 1515
hack4ps.no-ip.info 131
jorlu.sytes.net 645
m30w.evilpacket.org 7709
monbebe.no-ip.org 1515
mrkarar.np-ip.ibz 1515
network-info.sytes.net 1604
nikt0x.no-ip.biz 1515
niku.uk.to 1515
nnqi.vicp.cc 81
r0x0r.no-ip.org 1515
rawr.evilpacket.org 7709
sorbbolindo.no-ip.biz 1515
topcumt2.zapto.org 1604
updupdupd.servepics.com 1604

Trending

Most Viewed

Loading...