BodomBot

Copyright © MegaSecurity

By ?


Informations
Author ?
Family BodomBot
Category Remote Access
Version BodomBot
Additional Information
dropped file:
c:\WINDOWS\system32\msmpr32.exe
size: 19,456 bytes 

port: 113 TCP

startup:
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run "Microsoft MPR Library Host"
data: C:\WINDOWS\System32\msmpr32.exe §NõwTö Œö xö pö Ìú

attempts to connect to an IRC Server



tested on Windows XP
June 10, 2005

If you recognize any personal information on this page and wish to have it removed or redacted, please contact us at jplesueur@phrozen.io. We are committed to protecting your privacy in accordance with GDPR regulations.