Home Malware Programs Backdoors Backdoor.Zyklon

Backdoor.Zyklon

Posted: March 28, 2017

Threat Metric

Threat Level: 6/10
Infected PCs: 4,682
First Seen: March 28, 2017
Last Seen: May 2, 2022
OS(es) Affected: Windows

Technical Details

File System Modifications

Tutorials: If you wish to learn how to remove malware components manually, you can read the tutorials on how to find malware, kill unwanted processes, remove malicious DLLs and delete other harmful files. Always be sure to back up your PC before making any changes.

The following files were created in the system:



%APPDATA%\Microsoft\Windows\Start Menu\Programs\Startup\itunes.vbs File name: itunes.vbs
Size: 304B (304 bytes)
MD5: f7e92c5512088113e101f4d729b95dd6
Detection count: 239
Mime Type: unknown/vbs
Path: %APPDATA%\Microsoft\Windows\Start Menu\Programs\Startup
Group: Malware file
Last Updated: August 29, 2017
%APPDATA%\Microsoft\Windows\Start Menu\Programs\Startup\itunes.vbs File name: itunes.vbs
Size: 290B (290 bytes)
MD5: 4fec597184ebe47db1dcb267536a5165
Detection count: 222
Mime Type: unknown/vbs
Path: %APPDATA%\Microsoft\Windows\Start Menu\Programs\Startup
Group: Malware file
Last Updated: August 29, 2017
%APPDATA%\Microsoft\Windows\Start Menu\Programs\Startup\itunes.vbs File name: itunes.vbs
Size: 298B (298 bytes)
MD5: 8ba12dfc6f94e4c7433272b208a5f602
Detection count: 201
Mime Type: unknown/vbs
Path: %APPDATA%\Microsoft\Windows\Start Menu\Programs\Startup
Group: Malware file
Last Updated: August 29, 2017
%APPDATA%\Microsoft\Windows\Start Menu\Programs\Startup\itunes.vbs File name: itunes.vbs
Size: 306B (306 bytes)
MD5: 14e0605707eb8751f58d0f00fdff3d42
Detection count: 164
Mime Type: unknown/vbs
Path: %APPDATA%\Microsoft\Windows\Start Menu\Programs\Startup
Group: Malware file
Last Updated: August 29, 2017
%PROGRAMFILES%\iTunes\Morning start\itunes.vbs File name: itunes.vbs
Size: 259B (259 bytes)
MD5: e8677989ad1efa19cc5e8f9e9e3772b0
Detection count: 148
Mime Type: unknown/vbs
Path: %PROGRAMFILES%\iTunes\Morning start
Group: Malware file
Last Updated: August 29, 2017
%APPDATA%\Microsoft\Windows\Start Menu\Programs\Startup\itunes.vbs File name: itunes.vbs
Size: 298B (298 bytes)
MD5: a34e702859f1b332839afc20638a3442
Detection count: 108
Mime Type: unknown/vbs
Path: %APPDATA%\Microsoft\Windows\Start Menu\Programs\Startup
Group: Malware file
Last Updated: August 29, 2017
%APPDATA%\Microsoft\Windows\Start Menu\Programs\Startup\itunes.vbs File name: itunes.vbs
Size: 298B (298 bytes)
MD5: 52f498df52566b975d061dc5c57bb6d8
Detection count: 94
Mime Type: unknown/vbs
Path: %APPDATA%\Microsoft\Windows\Start Menu\Programs\Startup
Group: Malware file
Last Updated: August 29, 2017
%APPDATA%\Microsoft\Windows\Start Menu\Programs\Startup\itunes.vbs File name: itunes.vbs
Size: 308B (308 bytes)
MD5: 3cf0e84d7c946589672638a0c2f935dd
Detection count: 87
Mime Type: unknown/vbs
Path: %APPDATA%\Microsoft\Windows\Start Menu\Programs\Startup
Group: Malware file
Last Updated: August 29, 2017
%APPDATA%\Microsoft\Windows\Start Menu\Programs\Startup\itunes.vbs File name: itunes.vbs
Size: 312B (312 bytes)
MD5: 5e091aa7ec45c09ad162af970b9879b5
Detection count: 87
Mime Type: unknown/vbs
Path: %APPDATA%\Microsoft\Windows\Start Menu\Programs\Startup
Group: Malware file
Last Updated: August 29, 2017
%APPDATA%\Microsoft\Windows\Start Menu\Programs\Startup\itunes.vbs File name: itunes.vbs
Size: 302B (302 bytes)
MD5: 23ae149e9f34918608756c56998a2fd1
Detection count: 82
Mime Type: unknown/vbs
Path: %APPDATA%\Microsoft\Windows\Start Menu\Programs\Startup
Group: Malware file
Last Updated: August 29, 2017
%APPDATA%\Microsoft\Windows\Start Menu\Programs\Startup\itunes.vbs File name: itunes.vbs
Size: 298B (298 bytes)
MD5: 210497aeb4c5276b04ac5b79e2f56816
Detection count: 75
Mime Type: unknown/vbs
Path: %APPDATA%\Microsoft\Windows\Start Menu\Programs\Startup
Group: Malware file
Last Updated: August 29, 2017
%APPDATA%\Microsoft\Windows\Start Menu\Programs\Startup\itunes.vbs File name: itunes.vbs
Size: 292B (292 bytes)
MD5: ac28924bd6a9a882423e71063fbe1372
Detection count: 59
Mime Type: unknown/vbs
Path: %APPDATA%\Microsoft\Windows\Start Menu\Programs\Startup
Group: Malware file
Last Updated: August 29, 2017
%APPDATA%\Microsoft\Windows\Start Menu\Programs\Startup\itunes.vbs File name: itunes.vbs
Size: 298B (298 bytes)
MD5: bc2214e1e3a270fcf68fc6d43bceeb73
Detection count: 56
Mime Type: unknown/vbs
Path: %APPDATA%\Microsoft\Windows\Start Menu\Programs\Startup
Group: Malware file
Last Updated: August 29, 2017
%APPDATA%\Microsoft\Windows\Start Menu\Programs\Startup\itunes.vbs File name: itunes.vbs
Size: 332B (332 bytes)
MD5: 060eba626694b895d2853415c0c8e670
Detection count: 56
Mime Type: unknown/vbs
Path: %APPDATA%\Microsoft\Windows\Start Menu\Programs\Startup
Group: Malware file
Last Updated: August 29, 2017
%APPDATA%\Microsoft\Windows\Start Menu\Programs\Startup\itunes.vbs File name: itunes.vbs
Size: 294B (294 bytes)
MD5: d1be16d3bb86f8350b69d88704675914
Detection count: 42
Mime Type: unknown/vbs
Path: %APPDATA%\Microsoft\Windows\Start Menu\Programs\Startup
Group: Malware file
Last Updated: August 29, 2017
%APPDATA%\Microsoft\Windows\Start Menu\Programs\Startup\itunes.vbs File name: itunes.vbs
Size: 292B (292 bytes)
MD5: 18f222c326f9d32e42b304924ba8229f
Detection count: 37
Mime Type: unknown/vbs
Path: %APPDATA%\Microsoft\Windows\Start Menu\Programs\Startup
Group: Malware file
Last Updated: August 29, 2017
%APPDATA%\Microsoft\Windows\Start Menu\Programs\Startup\itunes.vbs File name: itunes.vbs
Size: 294B (294 bytes)
MD5: 601ffb8735ce56f99f1817bc60f3e523
Detection count: 37
Mime Type: unknown/vbs
Path: %APPDATA%\Microsoft\Windows\Start Menu\Programs\Startup
Group: Malware file
Last Updated: August 29, 2017
%APPDATA%\Microsoft\Windows\Start Menu\Programs\Startup\itunes.vbs File name: itunes.vbs
Size: 288B (288 bytes)
MD5: 95f4dac4135ab80c8ac20919e4648c1e
Detection count: 28
Mime Type: unknown/vbs
Path: %APPDATA%\Microsoft\Windows\Start Menu\Programs\Startup
Group: Malware file
Last Updated: August 29, 2017
%APPDATA%\Microsoft\Windows\Start Menu\Programs\Startup\itunes.vbs File name: itunes.vbs
Size: 298B (298 bytes)
MD5: 32e9c0d753be17287d0173674c677440
Detection count: 23
Mime Type: unknown/vbs
Path: %APPDATA%\Microsoft\Windows\Start Menu\Programs\Startup
Group: Malware file
Last Updated: August 29, 2017
%APPDATA%\itunes.exe File name: itunes.exe
Size: 5.15 MB (5156864 bytes)
MD5: 6bb44c92ecc8b97c940fb8b83c10a99b
Detection count: 22
File type: Executable File
Mime Type: unknown/exe
Path: %APPDATA%
Group: Malware file
Last Updated: July 18, 2017
%APPDATA%\Microsoft\Windows\Start Menu\Programs\Startup\itunes.vbs File name: itunes.vbs
Size: 290B (290 bytes)
MD5: fed3fae234bfc4bec029917f3a36cb7a
Detection count: 12
Mime Type: unknown/vbs
Path: %APPDATA%\Microsoft\Windows\Start Menu\Programs\Startup
Group: Malware file
Last Updated: June 26, 2017
%APPDATA%\itunes.exe File name: itunes.exe
Size: 5.15 MB (5156864 bytes)
MD5: 29086ba038f09e210f6bfa26ad6b3463
Detection count: 7
File type: Executable File
Mime Type: unknown/exe
Path: %APPDATA%
Group: Malware file
Last Updated: June 26, 2017
%APPDATA%\itunes.exe File name: itunes.exe
Size: 5.17 MB (5173248 bytes)
MD5: 86d4d3f186b8f4eef1da34ae2b653ba8
Detection count: 5
File type: Executable File
Mime Type: unknown/exe
Path: %APPDATA%
Group: Malware file
Last Updated: June 15, 2017

More files

Registry Modifications

The following newly produced Registry Values are:

Regexp file mask%APPDATA%\itunes_br.dat%APPDATA%\itunes_el.dat%APPDATA%\itunes_ftp.dat%APPDATA%\Microsoft\Windows\Start Menu\Programs\Startup\itunes.vbs
Loading...