Threat Database Backdoors BKDR_RILER.SV

BKDR_RILER.SV

By LoneStar in Backdoors

Threat Scorecard

Ranking: 14,322
Threat Level: 20 % (Normal)
Infected Computers: 167
First Seen: May 15, 2012
Last Seen: August 5, 2023
OS(es) Affected: Windows

BKDR_RILER.SV is a backdoor Trojan that is a component of a spam email pertaining to Tibetan. BKDR_RILER.SV is delivered via spam emails supposedly promoting Tibetan culture, which allegedly incorporate instructions on how to use the Input Method by Tibetans who might use Apple iOS 4.2 gadgets. Stating that to make Tibetan culture widespread by helping people who want to learn Tibetan language, the malicious email declare that 'Digital Tibetan' recently developed the 'Input Method' for Tibetans who wish to successfully operate Apple iOS 4.2 gadgets. BKDR_RILER.SV is spread by other malware infections, specifically TROJ_ARTIEF.EDX, and is distributed as an executable file corrupted by a file infector malware infection identified as PE_SALITY.AC. This consequently executes both payloads of BKDR_RILER.SVR and PE_SALITY.AC on the infected machine. BKDR_RILER.SV connects to a particular domain to transmit and obtain information. BKDR_RILER.SV registers its DLL component as Layered Service Provider (LSP) by creating the specific registry entry so that it can launch automatically whenever you turn your computer on. The DLL component encompasses the backdoor routines of BKDR_RILER.SV. The DLL component, at first, checks if it is inserted to any of the many processes before proceeding with execution; otherwise, it terminates.

File System Details

BKDR_RILER.SV may create the following file(s):
# File Name Detections
1. %System%\utntweep.dll
2. %System%\goopnet.ini

Registry Details

BKDR_RILER.SV may create the following registry entry or registry entries:
HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\WinSock2\Parameters\Protocol_Catalog9\Catalog_Entries\0000000000{2 digit numbers} PackedCatalogItem = "%System%\utntweep.dll"

URLs

BKDR_RILER.SV may call the following URLs:

techsys.site

Trending

Most Viewed

Loading...