Submission Summary:

What's been foundSeverity Level
Capability to send out email message(s) with the built-in SMTP client engine.


Technical Details:


File System Modifications

#Filename(s)File SizeFile Hash
1 %CommonPrograms%\Windows Managing System.lnk 853 bytes MD5: 0x25A6455AFD3428E8D29971DA9B508FBC
SHA-1: 0x45D92C26989DE16A7009DCFC02026D51BED81469
2 %AppData%\Macromedia\Flash Player\\support\flashplayer\sys\#local\settings.sol 102 bytes MD5: 0x8548AC8F2A90DFEAA7AC7E24BA675533
SHA-1: 0x5EB7CCA867CFC1C21E20EF9B1C969A06A4A63EBF
3 %AppData%\Protector-cdw.exe 1,970,688 bytes MD5: 0x1E75FFDC5F6CC36D877BFD4012A126A3
SHA-1: 0x5A2823E9CE85FDDF865E52A2B7535394BC92FE4A
4 %AppData%\result.db 329 bytes MD5: 0x749CFB5CAECC81A612BF017B9F6CFC88
SHA-1: 0x558ED2F46CEC92F68FC8F7F4CD705038C3A92285
5 %DesktopDir%\Windows Managing System.lnk 823 bytes MD5: 0xE57C629DE1A26F96F9361A0EB0E4FCDA
SHA-1: 0x319871072EBAFDD5DB3264F2BABDE2D660E6612D
6 [file and pathname of the sample #1] 2,109,815 bytes MD5: 0x0F92961523BFBBBD656C2D5EE2BEE941
SHA-1: 0xA9D3B0E1CB379E9D83110DBC2A2603F57DD82F69


Memory Modifications

Process NameProcess FilenameMain Module Size
Protector-cdw.exe%AppData%\protector-cdw.exe4,145,152 bytes
[filename of the sample #1][file and pathname of the sample #1]176,128 bytes


Registry Modifications


Other details

Russian Federation

1034UDPProtector-cdw.exe (%AppData%\Protector-cdw.exe)



All content ("Information") contained in this report is the copyrighted work of Threat Expert Ltd and its associated companies ("ThreatExpert") and may not be copied without the express permission of ThreatExpert.

The Information is provided on an "as is" basis. ThreatExpert disclaims all warranties, whether express or implied, to the maximum extent permitted by law, including the implied warranties that the Information is merchantable, of satisfactory quality, accurate, fit for a particular purpose or need, or non-infringing, unless such implied warranties are legally incapable of exclusion. Further, ThreatExpert does not warrant or make any representations regarding the use or the results of the use of the Information in terms of their correctness, accuracy, reliability, or otherwise.

Copyright © 2015 ThreatExpert. All rights reserved.