|
Backdoor.Katien. Viruses Information
| Name: |
Backdoor.Katien. |
| Category: |
Viruses |
| Description:
|
Details
Backdoor.Katien.a
Katien is a backdoor trojan program. The trojan itself is a Windows PE EXE file about 50KB in length and written in Microsoft Visual C++.
Once executed the backdoor program registers itself in the system registry auto-run section:
HKLMSoftwareMicrosoftWindowsCurrentVersionRun
The key name depends on the backdoor variant:
TaskReg = %trojan file name% Service = %trojan file name%
Once this is done Katien then opens a backdoor connection and waits for its master's (person controlling the Trojan program) commands. The Katien backdoor program performs just a few commands:
gets a file from a requested URL
runs a command or specified local file
performs a DoS attack on the requested victim address
terminates itself
The backdoor program has copyright strings (lines) depending on the backdoor variant:
Voyager Alpha Force: Age of Kaiten
Kaiten Win32 API version: contem@efnet |
Top Viruses Visited Pages:
Invader. - 239 visits
not-a-virus:RiskWare.Tool.RegPatch. - 73 visits
Worm.P2P.Harex. - 66 visits
not-a-virus:RemoteAdmin.Win32.RAdmin.2 - 60 visits
Small.58. - 56 visits
Coito.64 - 54 visits
I-Worm.Mapson. - 48 visits
Win32.Hidra - 43 visits
Win16.Klon.1177 - 42 visits
Marine.500 - 35 visits
Random Viruses Pages:
Joker0
Trojan-Downloader.Win32.Agent.r
AmazonQueen.47
AP.NightCit
Twin.35
Tibet.142
Backdoor.Win32.Nanspy.
Harmless.108
Inch Famil
Hide.70
|