Home Malware Programs Trojans Trojan.Atraxbot

Trojan.Atraxbot

Posted: August 15, 2013

Threat Metric

Threat Level: 9/10
Infected PCs: 14
First Seen: August 15, 2013
Last Seen: April 27, 2021
OS(es) Affected: Windows

Trojan.Atraxbot is a Trojan that opens a back door on the infected computer and may steal personal information from the victimized PC. When executed, Trojan.Atraxbot creates the potentially malicious files. Trojan.Atraxbot also creates the registry entry. Trojan.Atraxbot opens a back door on the targeted PC, and connects to the certain URL. Trojan.Atraxbot may connect to the certain IP addresses. Trojan.Atraxbot may connect to the particular domains to gain the external routable IP of the corrupted PC. Trojan.Atraxbot may perform the malicious actions, such as steal form data and passwords from web browsers (Internet Explorer, Mozilla Firefox, Safari, and Opera), check for debuggers and check if it is running on a virtual computer.

Technical Details

File System Modifications

Tutorials: If you wish to learn how to remove malware components manually, you can read the tutorials on how to find malware, kill unwanted processes, remove malicious DLLs and delete other harmful files. Always be sure to back up your PC before making any changes.

The following files were created in the system:



C:\Documents and Settings\<username>\Application Data\CC250[RANDOM HEXADECIMAL NUMBERS] File name: C:\Documents and Settings\<username>\Application Data\CC250[RANDOM HEXADECIMAL NUMBERS]
Group: Malware file
C:\Documents and Settings\<username>\Application Data\[RANDOM NUMBERS].exe File name: C:\Documents and Settings\<username>\Application Data\[RANDOM NUMBERS].exe
File type: Executable File
Mime Type: unknown/exe
Group: Malware file

Registry Modifications

The following newly produced Registry Values are:

HKEY..\..\{Value}HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Run\"Microsoft Svchost" = "C:\Documents and Settings\All Users\Application Data\[RANDOM NUMBERS].exe"

Additional Information

The following URL's were detected:
[http://]checkip.dyndns.org[REMOVED][http://]ipv4.icanhazip.com[REMOVED]iloii7dnyotii3gr.onion
Loading...