Threat Database Trojan Downloader Downloader.Castov.B

Downloader.Castov.B

By Sumo3000 in Trojan Downloader

Threat Scorecard

Ranking: 2,929
Threat Level: 70 % (High)
Infected Computers: 19,623
First Seen: August 13, 2013
Last Seen: September 20, 2023
OS(es) Affected: Windows

Downloader.Castov.B is a Trojan that drops other malware infections onto the affected computer system. Once run, Downloader.Castov.B creates the malevolent files and registry entries so that it can launch automatically whenever the computer user starts Windows. In order to obtain the compromised PC's IP address, Downloader.Castov.B connects to the specific remote location. Downloader.Castov.B may then aim at accessing the Tor anonymity network using one of the particular web addresses. Downloader.Castov.B may then drop additional files onto the targeted computer.

File System Details

Downloader.Castov.B may create the following file(s):
# File Name Detections
1. %UserProfile%\Application Data\Identities\{d79365c0-2a26-11e0-87a4-806d6172696f}\alg.exe
2. %UserProfile%\Application Data\Identities\{d79365c0-2a26-11e0-87a4-806d6172696f}\svchost.exe
3. %UserProfile%\Application Data\Identities\{d79365c0-2a26-11e0-87a4-806d6172696f}\ssleay32.dll
4. %UserProfile%\Application Data\Identities\{d79365c0-2a26-11e0-87a4-806d6172696f}\spoolsv.exe
5. %UserProfile%\Application Data\Identities\{d79365c0-2a26-11e0-87a4-806d6172696f}\libeay32.dll
6. %UserProfile%\Application Data\Identities\{d79365c0-2a26-11e0-87a4-806d6172696f}\mdm.exe
7. %UserProfile%\Application Data\Identities\{d79365c0-2a26-11e0-87a4-806d6172696f}\config.ini

Registry Details

Downloader.Castov.B may create the following registry entry or registry entries:
Data\Identities\{d79365c0-2a26-11e0-87a4-806d6172696f}\mdm.exe\""
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run\"mdm" = "\"%UserProfile%\Application
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run\"svchost" = "\"%UserProfile%\Application Data\Identities\{d79365c0-2a26-11e0-87a4-806d6172696f}\svchost.exe\""

URLs

Downloader.Castov.B may call the following URLs:

ipaddress.com

Trending

Most Viewed

Loading...