Home / malware Backdoor:Win32/Stinj.A
First posted on 17 February 2015.
Source: MicrosoftAliases :
There are no other names known for Backdoor:Win32/Stinj.A.
Explanation :
Threat behavior
Installation
This malware can arrive on your PC with the file name intel.exe.
Payload
Allows backdoor access and control
This threat can give a malicious hacker access and control of your PC.
It connects to an HTTP server by opening a hidden instance of Internet Explorer and waits for commands from a malicious hacker.
We have seen it connect to the following server:
- www.yahoodns.sixth.biz/
The malware sets up a remote shell that can give a malicious hacker access to run commands on your PC, including downloading or uploading files.
Analysis by Horea Coroiu
Symptoms
The following can indicate that you have this threat on your PC:
- You have these files:
intel.exeLast update 17 February 2015