Home / malwarePDF  

Backdoor:Win32/Hesetox.A


First posted on 31 March 2019.
Source: Microsoft

Aliases :

There are no other names known for Backdoor:Win32/Hesetox.A.

Explanation :

Backdoor:Win32/Hesetox.A is a trojan that allows unauthorized access and control of an affected computer. Installation When executed, Backdoor:Win32/Hesetox.A copies itself to c:documents and settingsadministratorapplication datasvchost.exe.
The malware modifies the following registry entries to ensure that its copy executes at each Windows start:

Adds value: "CCI Compliant Card"
With data: "c:documents and settingsadministratorapplication datasvchost.exe"
To subkey: HKLMSOFTWAREMicrosoftWindowsCurrentVersionRun Payload Modifies system security settings Backdoor:Win32/Hesetox.A adds itself to the list of applications that are authorized to access the Internet without being stopped by the Firewall, by making the following registry modification:

Adds value: "C:Documents and SettingsAdministratorApplication Datasvchost.exe"
With data: "c:documents and settingsadministratorapplication datasvchost.exe:*:enabled:svchost"
To subkey: HKLMSYSTEMCurrentControlSetServicesSharedAccessParametersFirewallPolicyStandardProfileAuthorizedApplicationsList
Allows backdoor access and control The malware allows unauthorized access and control of an affected computer. An attacker can perform any number of different actions on an affected computer using Backdoor:Win32/Hesetox.A. This could include, but is not limited to, the following actions:
Download and execute arbitrary files Upload files Spread to other computers using various methods of propagation Log keystrokes or steal sensitive data Modify system settings Run or terminate applications Delete files
This malware description was produced and published using our automated analysis system's examination of file SHA1 ba92073db95078973c02d5334422e304919c3d94.

Last update 31 March 2019

 

TOP