Home Malware Programs Backdoors BKDR_LIFTOH.DLF

BKDR_LIFTOH.DLF

Posted: May 7, 2013

Threat Metric

Ranking: 5,845
Threat Level: 2/10
Infected PCs: 6,790
First Seen: May 7, 2013
Last Seen: October 15, 2023
OS(es) Affected: Windows

BKDR_LIFTOH.DLF is a backdoor Trojan that spreads via social media websites like Facebook and multi-protocol IM apps such as Skype, mIRC and other. BKDR_LIFTOH.DLF receives commands from its C&C server, one of them to download and execute other malware threats on the affected PC. The command also consists of the URL where BKDR_LIFTOH.DLF will be downloaded. The file of BKDR_LIFTOH.DLF is uploaded on Hotfile. BKDR_LIFTOH.DLF is also able to edit its configuration from its C&C server. The configuration consists of the C&C servers, connection timeout, max number of connection attempts, and malware build version. BKDR_LIFTOH.DLF can switch to different C&C servers to stay undetected. BKDR_LIFTOH.DLF's buildid field is build1, which means that BKDR_LIFTOH.DLF is in its first version. BKDR_LIFTOH.DLF also downloads another malware infections.

Technical Details

Additional Information

The following URL's were detected:
yourwebshield.com
Loading...