Threat Database Backdoors BKDR_PLUGX.AQT

BKDR_PLUGX.AQT

By ZulaZuza in Backdoors

Threat Scorecard

Ranking: 14,408
Threat Level: 20 % (Normal)
Infected Computers: 4,421
First Seen: April 26, 2013
Last Seen: September 4, 2023
OS(es) Affected: Windows

BKDR_PLUGX.AQT is a backdoor Trojan that attacks genuine programs that include Microsoft, Lenovo, and McAfee. BKDR_PLUGX.AQT uses genuine programs to load its damaging .DLL components on the infected computer. BKDR_PLUGX.AQT uses any executable file and recognized programs. BKDR_PLUGX.AQT also uses a particular vulnerability detected in an executable when .DLLs are loaded, particularly on how executable files load the first .DLL file in a specific folder. BKDR_PLUGX.AQT uses numerous legal files to load its harmful components on the compromised PC. BKDR_PLUGX.AQT uses 'Mc.exe', which is an authentic McAfee file. BKDR_PLUGX.AQT loads 'McUtil.dll', which then loads 'McUtil.dll.url'. Both files are found as BKDR_PLUGX.AQT. BKDR_PLUGX.AQT connects to the bogus anti-malware website 'vip.{BLOCKED}ate.com'. BKDR_PLUGX.AQT pairs a specific .DLL file with an executable file. BKDR_PLUGX.AQT loads the encrypted file with the same file name with an additional extension.

File System Details

BKDR_PLUGX.AQT may create the following file(s):
# File Name Detections
1. McUtil.dll
2. Mc.exe
3. McUtil.dll.url

URLs

BKDR_PLUGX.AQT may call the following URLs:

publicconfirm.com

Trending

Most Viewed

Loading...