|
|
Global Killer RAT Information
| Name: |
Global Killer |
| Category: |
RAT |
| Alias: |
- Alias: Backdoor.Nimoo, Backdoor.VB.cs, Backdoor.VB.cw, Backdoor.VB.cw |
| Advice: |
Remove |
| Risk: |
Severe Risk
Severe threats typically are remotely exploitable vulnerabilities, which can lead to system compromise. Successful exploitation does not normally require any interaction and exploits are in the wild. There exists a high possibility of potential system damage or security flaw. Attacker has complete control over your computer or install new software on your machine. |
| Description:
|
Global Killer is a Trojan software that installs on a user’s computer and listens over the Internet for commands from the attacker.
Global Killer listens on TCP port 1266 when connected to the Internet.
The attacker can remotely perform some of the following tasks without the user’s consent, or the ability for the user to prevent it; Screenshot the desktop, Shutdown the computer, open the CD-Rom drive, launch the screen saver, log off the user, modify the Win.ini file, etc.
Global killer has been produced in Chili and is written in Visual Basic.
|
| Signatures:
|
process: cliente.exe: MD5 Hash: c62099919f9b58fd5b8...
process: server.exe: MD5 Hash: d744ebcfbec0503a445...
process: command.exe: MD5 Hash: .. |
| Type: |
RAT - A Trojan software is any software on a user's computer that the user is not aware or intentionally installed. Most Trojan software is designed to perform some sort of actions that could jeopardize the user's security or privacy. |
Top RAT Visited Pages:
SubSeven - Alias: BackDoor-G22, BackDoor-Sub7 - 286 visits
NetBus v.1.70 - 201 visits
The Prayer - Alias: BackDoor-DI, Backdoor.Prayer.15 - 75 visits
Cyrex msn trojan - Alias: BackDoor-AOB, Backdoor.VB.dm, Backdoor.VB.dm, Cyrex msn trojan, W32/Delf.B - 67 visits
Global Killer - Alias: Backdoor.GlobalKiller 1.0, Global Killer 1.0 - 54 visits
Systray BackDoor - 52 visits
AutoSpY - Alias: Backdoor.AutoSpy - 47 visits
Secret Agent - Alias: Backdoor.Antinuke.10, Secret Agent 1.0 - 46 visits
Netbus - Alias: Backdoor.Netbus - 41 visits
Undetected - Alias: Backdoor.tds.4f, Backdoor.tds.se.23, Backdoor.tds.se.23a, Backdoor.tds.se.30, Backdoor.TDS.SE.31, Ba - 39 visits
Random RAT Pages:
ProRAT - Alias: Backdoor.Prorat.10.a, Backdoor.Prorat.10.c, ProHack.Net Remote Administration Tool
Remote Kit - Alias: BackDoor-AQQ.cfg trojan, BackDoor-AQQ.cli trojan, BackDoor-AQQ.svr trojan
Supcount - Alias: BackDoor-AMT trojan, BackDoor-AMT, Backdoor.Supcount.10, SuperCount 1.0
The X
Dkangel - Alias: Backdoor.DKangel, Backdoor.DKangel.12, Backdoor.DKangel.20.a, Backdoor.DKangel.20.b, Backdoor.DKange
AutoSpY - Alias: Backdoor.AutoSpy
Alicia version d - Alias: Backdoor.Alicia
Majesty Backdoor
RBackdoor - Alias: BackDoor-AKT trojan, Backdoor.Redkod.11
ItADeM - Alias: Backdoor.Nimoo, Backdoor.VB.cs, Backdoor.VB.cw, Backdoor.VB.cw
|
|