Home Malware Programs Backdoors Backdoor:Win32/Trubsil.B

Backdoor:Win32/Trubsil.B

Posted: August 14, 2013

Threat Metric

Ranking: 4,896
Threat Level: 1/10
Infected PCs: 3,033
First Seen: August 14, 2013
Last Seen: October 16, 2023
OS(es) Affected: Windows

Backdoor:Win32/Trubsil.B is a web-based backdoor Trojan that creates copies of itself into the certain folder on the infected computer. Backdoor:Win32/Trubsil.B creates the registry entry to assure that it can run automatically each time the PC user starts the computer.
Backdoor:Win32/Trubsil.B communicates with a remote host to perform other payloads. Backdoor:Win32/Trubsil.B performs password-guessing attacks based on a list of passwords that it downloads from a remote server. Backdoor:Win32/Trubsil.B may also be able to update itself or download other files. Backdoor:Win32/Trubsil.B contacts the specific servers to download commands and configuration information. Backdoor:Win32/Trubsil.B strives to guess the administrator login data for a set of administrator login PHP pages for a specific web address using user names that it downloads from the remote server.

Technical Details

File System Modifications

Tutorials: If you wish to learn how to remove malware components manually, you can read the tutorials on how to find malware, kill unwanted processes, remove malicious DLLs and delete other harmful files. Always be sure to back up your PC before making any changes.

The following files were created in the system:



%APPDATA%\system\djyvobbrgnsdwlaea.exe File name: %APPDATA%\system\djyvobbrgnsdwlaea.exe
File type: Executable File
Mime Type: unknown/exe
Group: Malware file

Registry Modifications

The following newly produced Registry Values are:

HKEY..\..\{Value}HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Run [malware_file_name], for example djyvobbrgnsdwlaea = %APPDATA%\system\[malware_file_name]

Additional Information

The following URL's were detected:
bestsearchpdf.comget.mypdf-search.com
Loading...