Threat Database Backdoors Backdoor:Win32/Trubsil.B

Backdoor:Win32/Trubsil.B

By Domesticus in Backdoors

Threat Scorecard

Ranking: 4,873
Threat Level: 10 % (Normal)
Infected Computers: 1,276
First Seen: August 14, 2013
Last Seen: September 20, 2023
OS(es) Affected: Windows

Backdoor:Win32/Trubsil.B is a web-based backdoor Trojan that replicates itself into the specific folder on the corrupted PC. Backdoor:Win32/Trubsil.B creates the registry entry to guarantee that it can load automatically whenever the computer is started. Backdoor:Win32/Trubsil.B communicates with a remote host to execute other payloads. Backdoor:Win32/Trubsil.B executes password-guessing attacks depending on a list of passwords that it downloads from a distant server. Backdoor:Win32/Trubsil.B may also be able to update itself or drop other files. Backdoor:Win32/Trubsil.B contacts the certain servers to download commands and configuration information. Backdoor:Win32/Trubsil.B attempts to guess the administrator login data for a set of administrator login PHP pages for a certain URL using user names that it downloads from the distant server.

File System Details

Backdoor:Win32/Trubsil.B may create the following file(s):
# File Name Detections
1. %APPDATA%\system\djyvobbrgnsdwlaea.exe

Registry Details

Backdoor:Win32/Trubsil.B may create the following registry entry or registry entries:
HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Run [malware_file_name], for example djyvobbrgnsdwlaea = %APPDATA%\system\[malware_file_name]

URLs

Backdoor:Win32/Trubsil.B may call the following URLs:

bestsearchpdf.com
get.mypdf-search.com

Trending

Most Viewed

Loading...