Home Malware Programs Backdoors Masot

Masot

Posted: March 28, 2006

Masot is a backdoor, which provides the attacker with unauthorized remote access to the compromised PC. The intruder can take screenshots of user activity, terminate running processes, download arbitrary files and thus steal user sensitive information. Masot can disable the Windows Firewall. The backdoor runs a hidden web server and can be controlled through the web interface. The attacker can reconfigure the spyware. Certain Masot variants may show fake error messages and use varied ports. The backdoor automatically runs on every Windows startup.

File System Modifications

  • The following files were created in the system:
    # File Name
    1 explorer64.exe

Registry Modifications

  • The following newly produced Registry Values are:
    HKEY..\..\..\..{RegistryKeys}HKEY_LOCAL_MACHINESOFTWAREMicrosoftWindowsCurrentVersionRunexplorer64
Loading...