Submission Summary:

What's been foundSeverity Level
Stealth-mode characteristics common to Rootkits.
Downloads/requests other files from Internet.
Creates a startup registry entry.
Contains characteristics of an identified security risk.

 

Technical Details:

 

Possible Security Risk

Security RiskDescription
Rootkit.Agent.EX Rootkit.Agent.EX hides its presence in infected machine in order to perform malicious actions without user's knowledge.
Trojan-PWS.Papras Trojan-PWS.Papras drop a rookit file and has keylogger characteristic in order to perform malicious action without user's knowledge.

Threat CategoryDescription
A keylogger program that can capture all user keystrokes (including confidential details such username, password, credit card number, etc.)
A code with the rootkit-specific techniques designed to hide the software presence in the system

 

File System Modifications

#Filename(s)File SizeFile HashAlias
1 %Windir%\9129837.exe
[file and pathname of the sample #1]
52,736 bytes MD5: 0x03E3CCDF10B8FD43D762B10BA5ED4289
SHA-1: 0x944D5A20E48BED9B2F5712E53F16B28B03209623
Infostealer.Snifula [Symantec]
Trojan-PSW.Win32.Papras.ea [Kaspersky Lab]
Spy-Agent.bg [McAfee]
Mal/EncPk-DB [Sophos]
TrojanSpy:Win32/Ursnif.DP [Microsoft]
Trojan-PWS.Win32.Papras [Ikarus]
Win-Trojan/Papras.52736 [AhnLab]
2 %System%\abcdefg.bat 80 bytes MD5: 0x3C2C2719C39678A7EF5013EB16B6F6EF
SHA-1: 0x323DFEA7B524E2781DC2A4584A72A22981EEE9A0
Trojan-Spy.Agent [Ikarus]

#Filename(s)File SizeFile HashAlias
1 %Windir%\new_drv.sys 7,680 bytes MD5: 0xBAD3CF56B46ACBE2806ADC84E67B682C
SHA-1: 0xC96EC3963D0CB20AE3466C7421503D1F1C9F745D
Infostealer.Snifula [Symantec]
Rootkit.Win32.Agent.sz [Kaspersky Lab]
Generic Rootkit.d [McAfee]
Mal/Generic-A [Sophos]
VirTool:WinNT/Ursnif.A [Microsoft]
Rootkit.Win32.Agent.ex [Ikarus]
Win-Trojan/Agent.7680.CN [AhnLab]

 

Memory Modifications

Process NameProcess FilenameMain Module Size
[filename of the sample #1][file and pathname of the sample #1]107,520 bytes

Process NameMain Module Size
9129837.exe107,520 bytes

Service NameDisplay NameNew StatusService Filename
ALGApplication Layer Gateway Service"Stopped"%System%\alg.exe
SharedAccessWindows Firewall/Internet Connection Sharing (ICS)"Stopped"%System%\svchost.exe -k netsvcs
wscsvcSecurity Center"Stopped"%System%\svchost.exe -k netsvcs

Driver NameDriver Filename
new_drv.sys%Windir%\new_drv.sys

System CallDriver nameDriver Filename
NtEnumerateValueKey(not recognised)(not recognised)
NtQueryDirectoryFile(not recognised)(not recognised)
NtQuerySystemInformation(not recognised)(not recognised)

 

Registry Modifications

 

Other details

Server NameServer PortConnect as UserConnection Password
in.webstat12.com80(null)(null)
in.webstat12.com0(null)(null)

 

 

All content ("Information") contained in this report is the copyrighted work of Threat Expert Ltd and its associated companies ("ThreatExpert") and may not be copied without the express permission of ThreatExpert.

The Information is provided on an "as is" basis. ThreatExpert disclaims all warranties, whether express or implied, to the maximum extent permitted by law, including the implied warranties that the Information is merchantable, of satisfactory quality, accurate, fit for a particular purpose or need, or non-infringing, unless such implied warranties are legally incapable of exclusion. Further, ThreatExpert does not warrant or make any representations regarding the use or the results of the use of the Information in terms of their correctness, accuracy, reliability, or otherwise.

Copyright © 2013 ThreatExpert. All rights reserved.