FANDOM


Rootkit.Win32.Tibia.aev or Tibia.aev is a rootkit and trojan that acts to similar to a worm, on Microsoft Windows (Win32).

Payload

During installation, the file saves its configuration to the following file:

%WinDir%\cchost.ini

The rootkit/trojan is designed to flood victims with spam. When launched, it attempts to download the spam that is forwarded to the victims.

http://www.smalltool.net/remotewatch/send_****.php

After that, it will download a list of emails from the following domain.

http://www.smalltool.net/remotewatch/user****.php

It will forward the downloaded spam to the email addresses on the list.

Sources