Home Malware Programs Backdoors Backdoor.Mudsy

Backdoor.Mudsy

Posted: April 19, 2013

Threat Metric

Threat Level: 2/10
Infected PCs: 92
First Seen: April 22, 2013
OS(es) Affected: Windows

Backdoor.Mudsy is a backdoor Trojan that opens a back door on the corrupted PC. Backdoor.Mudsy is usually downloaded by a specially crafted RTF document which exploits the Microsoft Windows Common Controls ActiveX Control Remote Code Execution Vulnerability (CVE-2012-0158). When executed, Backdoor.Mudsy creates the potentially malicious files on the infected computer system. The document.doc file added by Backdoor.Mudsy is not malicious. Backdoor.Mudsy creates the registry entries so that it can run automatically every time Windows is started. Backdoor.Mudsy connects to port 8081 on the specific IP address. Backdoor.Mudsy may execute malicious actions such as download and upload files, execute commands and delete registry 'Run' keys.

Technical Details

File System Modifications

Tutorials: If you wish to learn how to remove malware components manually, you can read the tutorials on how to find malware, kill unwanted processes, remove malicious DLLs and delete other harmful files. Always be sure to back up your PC before making any changes.

The following files were created in the system:



%Temp%\document.doc File name: %Temp%\document.doc
Mime Type: unknown/doc
Group: Malware file
%Temp%\vbScript.bat File name: %Temp%\vbScript.bat
File type: Batch file
Mime Type: unknown/bat
Group: Malware file
%Temp%\update.exe File name: %Temp%\update.exe
File type: Executable File
Mime Type: unknown/exe
Group: Malware file
%System%\msdap.dll File name: %System%\msdap.dll
File type: Dynamic link library
Mime Type: unknown/dll
Group: Malware file

Registry Modifications

The following newly produced Registry Values are:

HKEY..\..\{Value}HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Run\"Display Card Driver" = "rundll32.exe %System%\msdap.dll,Display"HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run\"Display Card Driver" = "rundll32.exe %System%\msdap.dll,Display"
Loading...