Analysis by: Jay Garcia

ALIASES:

Backdoor:PHP/OrbWS.WS!MTB (Microsoft); Backdoor.PHP.SpamBot (Ikarus)

 PLATFORM:

Windows

 OVERALL RISK RATING:
 DAMAGE POTENTIAL:
 DISTRIBUTION POTENTIAL:
 REPORTED INFECTION:
 INFORMATION EXPOSURE:

  • Threat Type: Backdoor

  • Destructiveness: No

  • Encrypted:

  • In the wild: Yes

  OVERVIEW

This Backdoor arrives on a system as a file dropped by other malware or as a file downloaded unknowingly by users when visiting malicious sites.

It requires being executed with a specific argument/parameter, an additional component, or in a specific environment in order to proceed with its intended routine.

  TECHNICAL DETAILS

Tamaño del archivo 66,027 bytes
Tipo de archivo PHP
Residente en memoria No
Fecha de recepción de las muestras iniciales 04 May 2020

Arrival Details

This Backdoor arrives on a system as a file dropped by other malware or as a file downloaded unknowingly by users when visiting malicious sites.

Other Details

This Backdoor requires being hosted on a web server in order to proceed with its intended routine.

It requires being executed with a specific argument/parameter, an additional component, or in a specific environment in order to proceed with its intended routine.