Submission Summary:

What's been foundSeverity Level
Produces outbound traffic.
Communication with a remote SMTP server and sending out email.
Creates a startup registry entry.
Contains characteristics of an identified security risk.

 

Technical Details:

 

Possible Security Risk

Security RiskDescription
Trojan.Agent Trojan.Agent will spy on the browsing habits of users, modify Internet Explorer settings and download malicious files.

Threat CategoryDescription
A malicious backdoor trojan that runs in the background and allows remote access to the compromised system
A virus capable to modify other files by infecting, prepending, or overwriting them them with its own body
A malicious trojan horse or bot that may represent security risk for the compromised system and/or its network environment

 

File System Modifications

#Filename(s)File SizeFile HashAlias
1 %UserProfile%\reader_s.exe
%System%\reader_s.exe
[file and pathname of the sample #1]
33,280 bytes MD5: 0x1BF532E8B9E7498D35B1A69A4759CF6D
SHA-1: 0x2C7881D7FC350AEAFB27C76040C9BF7BD0C767A5
Packed.Generic.264 [Symantec]
Backdoor.Win32.Small.zp [Kaspersky Lab]
2 %System%\dllcache\ndis.sys 212,480 bytes MD5: 0x0811697768F503138F9E498662D49435
SHA-1: 0xBCC6B06D1B65981C3D41084EA39C846629808B8F
Trojan.Neprodoor!inf [Symantec]
Virus.Win32.Protector.b [Kaspersky Lab]
Troj/Pushu-Gen, Mal/Fakedis-A [Sophos]
Virus.Win32.Protector [Ikarus]
Win32/Dnis.C [AhnLab]

 

Memory Modifications

Process NameProcess FilenameMain Module Size
reader_s.exe%System%\reader_s.exe49,152 bytes
reader_s.exe%UserProfile%\reader_s.exe49,152 bytes

Process NameProcess FilenameAllocated Size
svchost.exe%System%\svchost.exe5,124,096 bytes

 

Registry Modifications

 

Other details

Remote HostPort Number
132.239.0.11825
192.61.61.10325
195.2.72.14425
46.59.85ae.static.theplanet.com25
204.16.46.125
205.160.42.7925
206.212.0.24125
207.126.147.1025
207.251.48.1025
209.87.180.7125
78.159.121.568562

 

Outbound traffic (potentially malicious)

 

Generated SMTP traffic

Dear customer! The courier company was not able to deliver your parcel by your address. Cause: Error in shipping address. You may pickup the parcel at our post office personaly! Parcel: Asus EeeBox EBXB202 Attention! The shipping label is attached to this e-mail. Print this label to get this package at our post office. Please do not reply to this e-mail, it is an unmonitored mailbox! Thank you, DHL Delivery Services.
Dear customer! The courier company was not able to deliver your parcel by your address. Cause: Error in shipping address. You may pickup the parcel at our post office personaly! Parcel: HP Pavilion Elite M9500F Attention! The shipping label is attached to this e-mail. Print this label to get this package at our post office. Please do not reply to this e-mail, it is an unmonitored mailbox! Thank you, DHL Express Services.

 

 

All content ("Information") contained in this report is the copyrighted work of Threat Expert Ltd and its associated companies ("ThreatExpert") and may not be copied without the express permission of ThreatExpert.

The Information is provided on an "as is" basis. ThreatExpert disclaims all warranties, whether express or implied, to the maximum extent permitted by law, including the implied warranties that the Information is merchantable, of satisfactory quality, accurate, fit for a particular purpose or need, or non-infringing, unless such implied warranties are legally incapable of exclusion. Further, ThreatExpert does not warrant or make any representations regarding the use or the results of the use of the Information in terms of their correctness, accuracy, reliability, or otherwise.

Copyright © 2009 ThreatExpert. All rights reserved.