Submission Summary:

What's been foundSeverity Level
Produces outbound traffic.
Creates a startup registry entry.
Contains characteristics of an identified security risk.

 

Technical Details:

 

Possible Security Risk

Threat CategoryDescription
A keylogger program that can capture all user keystrokes (including confidential details such username, password, credit card number, etc.)

 

File System Modifications

#Filename(s)File SizeFile HashAlias
1 [file and pathname of the sample #1] 1,451,967 bytes MD5: 0x1092C39537473DDC6FD20531B0D4987A
SHA-1: 0x404356C3C6FB88BB28883AB98AC779A7DC25CB27
not-a-virus:RemoteAdmin.Win32.eSurveiller.120 [Kaspersky Lab]
MonitoringTool [Ikarus]
2 %System%\tcphost.exe 644,096 bytes MD5: 0x55EED365A34F99397F3280AF267BF60F
SHA-1: 0x6CDA35CAEBC04AAF46608C56003BFE7A0C32B31E
Infostealer [Symantec]
not-a-virus:RemoteAdmin.Win32.eSurveiller.120 [Kaspersky Lab]
RemAdm-ESurveiller [McAfee]
MonitoringTool:Win32/ESurveiller [Microsoft]
not-a-virus:Monitor.Win32.007SpySoft.308 [Ikarus]
3 %System%\tcphost.ini 421 bytes MD5: 0x2FCDA2AFC8128D294A0F89E3945E4E4C
SHA-1: 0xFC72910F402C6520800A0C6FF649F3F981652F61
(not available)
4 %System%\tcphost.tmp 19 bytes MD5: 0xC2DCB86B6D6FCE014001F352634C9F87
SHA-1: 0xD6CCD441A0ACB0CCFC39C22053C31A94C85C9DCD
(not available)
5 %System%\zlib.dll 53,248 bytes MD5: 0x4965107D112666D3835308A831A29274
SHA-1: 0x50439B99CE525ECB74C554E1DC43DDB39481DFA4
(not available)

 

Memory Modifications

Process NameProcess FilenameMain Module Size
tcphost.exe%System%\tcphost.exe671,744 bytes
[filename of the sample #1][file and pathname of the sample #1]73,728 bytes
install.exe%Temp%\install.exe45,056 bytes

 

Registry Modifications

 

Other details

France

PortProtocolProcess
1033TCPtcphost.exe (%System%\tcphost.exe)

Remote HostPort Number
MAXIMOUS424

 

Outbound traffic (potentially malicious)

 

 

All content ("Information") contained in this report is the copyrighted work of Threat Expert Ltd and its associated companies ("ThreatExpert") and may not be copied without the express permission of ThreatExpert.

The Information is provided on an "as is" basis. ThreatExpert disclaims all warranties, whether express or implied, to the maximum extent permitted by law, including the implied warranties that the Information is merchantable, of satisfactory quality, accurate, fit for a particular purpose or need, or non-infringing, unless such implied warranties are legally incapable of exclusion. Further, ThreatExpert does not warrant or make any representations regarding the use or the results of the use of the Information in terms of their correctness, accuracy, reliability, or otherwise.

Copyright © 2013 ThreatExpert. All rights reserved.