Home / malware Bifrose.SN
First posted on 01 March 2007.
Source: SecurityHomeAliases :
Bifrose.SN is also known as Backdoor.Win32.Bifrose.sn.
Explanation :
Bifrose.SN is a variant of the Bifrose family of backdoors.
criptionInstallation to the System
When run, Bifrose.SN copies itself under %SysDir% directory using the name winampxp.exe. It installs the following registry key to make sure it will be executed next time the system is started:
- [HKLMSoftwareMicrosoftWindowsCurrentVersionRun]
"startkey" = "winampxp.exe"
Backdoor Functions
After the installation, Bifrose.SN tries to locate a web browser and inject code into it. The injected code is the actual backdoor. The backdoor starts to communicate with the following servers using a specially crafted HTTP queries:
The servers can instruct the backdoor to execute the following actions:
- bfrost.gardenparadise.co.uk:4444
- zingg.no-ip.org:4444
- zingg2.no-ip.org:4444
- Basic file operations (copy, delete, rename, find, execute)
- Download/upload files
- Process operations (list, kill)
- Registry operations (create/delete keys/values)
- Create screenshots of the desktop
Last update 01 March 2007