TROJ_FORUCON.BMC

TROJ_FORUCON.BMC also known as Trojan.MSIL.Injector.CFS, Trojan.Win32.Generic!BT.

Malware Analysis of TROJ_FORUCON.BMC

Created files:

%Appdata%\audx86.exe
%Temp%\1.tmp\example.bat
C:\sand-box\jhProtominer.exe

Autostart registry keys:

HKLM\Software\Microsoft\Windows\CurrentVersion\Run\Win32 Audio (x86): “%Appdata%\audx86.exe”

Detected by UnHackMe:

AUDX86.EXE
Default location: %APPDATA%\AUDX86.EXE

Written by 

Malware Hunter.

Leave a Reply