Home / malwarePDF  

Backdoor.Sinpid


First posted on 09 May 2014.
Source: Symantec

Aliases :

There are no other names known for Backdoor.Sinpid.

Explanation :

When the Trojan is executed, it creates the following file:
%UserProfile%\Application Data\Microsoft\MMC\MMC.exe

Next, the Trojan creates the following registry entry:
HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Run\"mmc" = "%UserProfile%\Application Data\Microsoft\MMC\mmc.exe"

The Trojan then connects to the following remote location:
[http://]cpanel.anydns.com/commo[REMOVED]

The Trojan may then perform the following actions:Upload and download filesCreate new processesUpdate itselfUninstall itself

Last update 09 May 2014

 

TOP