Home Malware Programs Backdoors Backdoor:Win32/Bezigate.B

Backdoor:Win32/Bezigate.B

Posted: September 25, 2013

Threat Metric

Threat Level: 6/10
Infected PCs: 80
First Seen: September 25, 2013
Last Seen: March 24, 2022
OS(es) Affected: Windows

Backdoor:Win32/Bezigate.B is a backdoor Trojan that enables attackers to gain full remote access and control of the infected computer. Backdoor:Win32/Bezigate.B can execute numerous potentially damaging actions on the affected computer, involving but not limited to stealing confidential information and files and transferring it to a remote server. Backdoor:Win32/Bezigate.B downloads and runs copies of itself in one of a few folders (%current directory%, %windir% and %APPDATA%), as any of the file names. Backdoor:Win32/Bezigate.B makes modifications to the Windows Registry to assure that it can run automatically every time the PC user starts the targeted PC. Backdoor:Win32/Bezigate.B strives to communicate with attackers using the specific combinations of web addresses and ports. Backdoor:Win32/Bezigate.B can create/remove/copy/move/modify files and folders, end and start processes, steal information about your, enumerate and modify the Windows Registry computer, enumerate/modify/start/stop running services, open and close browser windows, retrieve files from the computer and send them to the attacker, and log keystrokes and steal personal information.

Technical Details

File System Modifications

Tutorials: If you wish to learn how to remove malware components manually, you can read the tutorials on how to find malware, kill unwanted processes, remove malicious DLLs and delete other harmful files. Always be sure to back up your PC before making any changes.

The following files were created in the system:



file.exe File name: file.exe
Size: 909.31 KB (909312 bytes)
MD5: 6b93722a18630cf1d2ed71f133041e01
Detection count: 39
File type: Executable File
Mime Type: unknown/exe
Group: Malware file
Last Updated: October 9, 2017
123.exe File name: 123.exe
File type: Executable File
Mime Type: unknown/exe
Group: Malware file
456.exe File name: 456.exe
File type: Executable File
Mime Type: unknown/exe
Group: Malware file
microdbs.exe File name: microdbs.exe
File type: Executable File
Mime Type: unknown/exe
Group: Malware file
mscon.exe File name: mscon.exe
File type: Executable File
Mime Type: unknown/exe
Group: Malware file
msiexc.exe File name: msiexc.exe
File type: Executable File
Mime Type: unknown/exe
Group: Malware file
msizap.exe File name: msizap.exe
File type: Executable File
Mime Type: unknown/exe
Group: Malware file
msupdt32.exe File name: msupdt32.exe
File type: Executable File
Mime Type: unknown/exe
Group: Malware file
mypass.exe File name: mypass.exe
File type: Executable File
Mime Type: unknown/exe
Group: Malware file
spsreng.exe File name: spsreng.exe
File type: Executable File
Mime Type: unknown/exe
Group: Malware file
stub2546.exe File name: stub2546.exe
File type: Executable File
Mime Type: unknown/exe
Group: Malware file
xtreme.exe File name: xtreme.exe
File type: Executable File
Mime Type: unknown/exe
Group: Malware file
C:\ProgramData\vmnetUserifshort\file.exe File name: file.exe
Size: 1.69 MB (1694208 bytes)
MD5: 912d940cd2652d092cca54a8d6fad54c
Detection count: 0
File type: Executable File
Mime Type: unknown/exe
Path: C:\ProgramData\vmnetUserifshort
Group: Malware file
Last Updated: July 8, 2018

Registry Modifications

The following newly produced Registry Values are:

HKEY..\..\{Value}HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Run "[malware file name]" for example, "456" = "[malware file path]" for example, "C:\Windows\456.exe"

Additional Information

The following URL's were detected:
78.184.197.86 1604abdelsamed666.no-ip.com 5050all.evilpacket.org 7709barod.no-ip.biz 1515ermenello.servegame.com 4781fofo-123.no-ip.biz 1515hack4ps.no-ip.info 131jorlu.sytes.net 645m30w.evilpacket.org 7709monbebe.no-ip.org 1515mrkarar.np-ip.ibz 1515network-info.sytes.net 1604nikt0x.no-ip.biz 1515niku.uk.to 1515nnqi.vicp.cc 81r0x0r.no-ip.org 1515rawr.evilpacket.org 7709sorbbolindo.no-ip.biz 1515topcumt2.zapto.org 1604updupdupd.servepics.com 1604
Loading...