Home Malware Programs Backdoors Backdoor.Blobhash

Backdoor.Blobhash

Posted: September 27, 2013

Threat Metric

Ranking: 10,395
Threat Level: 1/10
Infected PCs: 508
First Seen: September 27, 2013
Last Seen: September 29, 2023
OS(es) Affected: Windows

Backdoor.Blobhash is a backdoor Trojan that downloads files and opens a back door on the corrupted PC. When run, Backdoor.Blobhash creates the potentially malicious file. Backdoor.Blobhash then creates the registry subkey. Backdoor.Blobhash opens a back door on the affected computer, which allows an attacker to carry out harmful activities. Backdoor.Blobhash may then connect to the specific remote locations. Backdoor.Blobhash then downloads an encrypted DLL file and inserts it into the 'explorer.exe' process. The DLL file can receive the particular commands from a remote server, such as update existing DLL and modify configuration of the back door.

Technical Details

File System Modifications

Tutorials: If you wish to learn how to remove malware components manually, you can read the tutorials on how to find malware, kill unwanted processes, remove malicious DLLs and delete other harmful files. Always be sure to back up your PC before making any changes.

The following files were created in the system:



%UserProfile%\Application Data\Microsoft\Crypto\RSA\ntcrypt[RANDOM CHARACTERS].tpl File name: %UserProfile%\Application Data\Microsoft\Crypto\RSA\ntcrypt[RANDOM CHARACTERS].tpl
Mime Type: unknown/tpl
Group: Malware file

Registry Modifications

The following newly produced Registry Values are:

HKEY..\..\..\..{Subkeys}HKEY_CURRENT_USER\Software\Microsoft\SystemCertificates\CA\Certificates\5A82739996ED9EBA18F1BBCDCCA62D2C1D670CHKEY..\..\..\..{RegistryKeys}software\MyWordTool

Additional Information

The following directories were created:
%appdata%\MyWordTool%localappdata%\MyWordTool
The following URL's were detected:
37.221.162.4537.221.162.4746.45.181.50[http://]bestsolution134.org/SC/logo3[REMOVED][http://]bestsolution134.org/SC/logo6[REMOVED]
Loading...