Home / malwarePDF  

Backdoor:Win32/Stinj.A


First posted on 17 February 2015.
Source: Microsoft

Aliases :

There are no other names known for Backdoor:Win32/Stinj.A.

Explanation :

Threat behavior

Installation

This malware can arrive on your PC with the file name intel.exe.

Payload

Allows backdoor access and control

This threat can give a malicious hacker access and control of your PC.

It connects to an HTTP server by opening a hidden instance of Internet Explorer and waits for commands from a malicious hacker.

We have seen it connect to the following server:

  • www.yahoodns.sixth.biz/


The malware sets up a remote shell that can give a malicious hacker access to run commands on your PC, including downloading or uploading files.



Analysis by Horea Coroiu

Symptoms

The following can indicate that you have this threat on your PC:

  • You have these files:

    intel.exe

Last update 17 February 2015

 

TOP