Home / malware Backdoor:Win32/Bafruz.J
First posted on 09 February 2020.
Source: MicrosoftAliases :
There are no other names known for Backdoor:Win32/Bafruz.J.
Explanation :
Backdoor:Win32/Bafruz.J is a trojan that allows unauthorized access and control of an affected computer. Installation When executed, Backdoor:Win32/Bafruz.J copies itself to %windir%update.2svchost.exe.
The malware modifies the following registry entries to ensure that its copy executes at each Windows start:
Adds value: ".exe"
With data: ".exe"
To subkey: HKLMSOFTWAREMicrosoftWindowsCurrentVersionRun Payload Modifies system security settings Backdoor:Win32/Bafruz.J adds itself to the list of applications that are authorized to access the Internet without being stopped by the Firewall, by making the following registry modification:
Adds value: "C:WINDOWSupdate.2svchost.exe"
With data: "c:windowsupdate.2svchost.exe:*:enabled:c:windowsupdate.2svchost.exe"
To subkey: HKLMSYSTEMCurrentControlSetServicesSharedAccessParametersFirewallPolicyStandardProfileAuthorizedApplicationsList
Allows backdoor access and control The malware allows unauthorized access and control of an affected computer. An attacker can perform any number of different actions on an affected computer using Backdoor:Win32/Bafruz.J. This could include, but is not limited to, the following actions:
Download and execute arbitrary files Upload files Spread to other computers using various methods of propagation Log keystrokes or steal sensitive data Modify system settings Run or terminate applications Delete files
This malware description was produced and published using our automated analysis system's examination of file SHA1 ffb93e5506b25790b6c86fcde11f4d3ccd047d6b.Last update 09 February 2020