MSIL/Rabasheeta [Threat Name] go to Threat
MSIL/Rabasheeta.A [Threat Variant Name]
Category | trojan |
Size | 49664 B |
Aliases | Backdoor.Rabasheeta (Symantec) |
BackDoor-FIT.trojan (McAfee) | |
Trojan.Agent.AXAG (BitDefender) |
Short description
The trojan serves as a backdoor. It can be controlled remotely.
Installation
The trojan does not create any copies of itself.
In order to be executed on every system start, the trojan sets the following Registry entry:
- [HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Run]
- "%malwarename%" = "%malwarefilepath%"
Other information
The trojan acquires data and commands from a remote computer or the Internet.
The trojan contains a list of (3) URLs. The HTTP protocol is used.
It can execute the following operations:
- download files from a remote computer and/or the Internet
- run executable files
- update itself to a newer version
- open a specific URL address
- modify website content
- capture screenshots
- log keystrokes
- send the list of files on specific drive to a remote computer
- send files to a remote computer
- delete files
- remove itself from the infected computer
The trojan may create the following files:
- cfg.dat
- del.bat
- ud.bat
- tmp