Submission Summary:

What's been foundSeverity Level
Contains characteristics of an identified security risk.

 

Technical Details:

NOTICE: The content shown in the above window is captured automatically and is not controlled or endorsed by ThreatExpert.
Please contact us on this link should any material be offensive or inappropriate and we will ensure any such content is blocked from future viewers of the report.

 

Possible Security Risk

Threat CategoryDescription
A network-aware worm that attempts to replicate across the existing network(s)
A malicious trojan horse or bot that may represent security risk for the compromised system and/or its network environment

 

File System Modifications

#Filename(s)File SizeFile HashAlias
1 %System%\di_build.exe 295,936 bytes MD5: 0x387D5D969771AD0812774DE7B95D2182
SHA-1: 0x0B2EE570222A0D6BB0729BDAF8581AC5C9D7222A
Trojan.Gen [Symantec]
Worm.Win32.Zwr.h [Kaspersky Lab]
W32/Autorun.worm!qk [McAfee]
Worm:Win32/Secrar.A [Microsoft]
Worm.Win32.Secrar [Ikarus]
2 %System%\di_build.exedi_build.exe
%System%\di_build.exedi_build.exedi_build.exe
%System%\di_build.exedi_build.exedi_build.exedi_build.exe
%System%\di_build.exedi_build.exedi_build.exedi_build.exedi_build.exe
%System%\di_build.exedi_build.exedi_build.exedi_build.exedi_build.exedi_build.exe
%System%\di_build.exedi_build.exedi_build.exedi_build.exedi_build.exedi_build.exedi_build.exe
%System%\di_build.exedi_build.exedi_build.exedi_build.exedi_build.exedi_build.exedi_build.exedi_build.exe
%System%\di_build.exedi_build.exedi_build.exedi_build.exedi_build.exedi_build.exedi_build.exedi_build.exedi_build.exe
%System%\di_build.exedi_build.exedi_build.exedi_build.exedi_build.exedi_build.exedi_build.exedi_build.exedi_build.exedi_build.exe
%System%\di_build.exedi_build.exedi_build.exedi_build.exedi_build.exedi_build.exedi_build.exedi_build.exedi_build.exedi_build.exedi_build.exe
%System%\di_build.exedi_build.exedi_build.exedi_build.exedi_build.exedi_build.exedi_build.exedi_build.exedi_build.exedi_build.exedi_build.exedi_build.exe
%System%\di_build.exedi_build.exedi_build.exedi_build.exedi_build.exedi_build.exedi_build.exedi_build.exedi_build.exedi_build.exedi_build.exedi_build.exedi_build.exe
%System%\di_build.exedi_build.exedi_build.exedi_build.exedi_build.exedi_build.exedi_build.exedi_build.exedi_build.exedi_build.exedi_build.exedi_build.exedi_build.exedi_build.exe
%System%\di_build.exedi_build.exedi_build.exedi_build.exedi_build.exedi_build.exedi_build.exedi_build.exedi_build.exedi_build.exedi_build.exedi_build.exedi_build.exedi_build.exedi_build.exe
%System%\di_build.exedi_build.exedi_build.exedi_build.exedi_build.exedi_build.exedi_build.exedi_build.exedi_build.exedi_build.exedi_build.exedi_build.exedi_build.exedi_build.exedi_build.exedi_build.exe
%System%\di_build.exedi_build.exedi_build.exedi_build.exedi_build.exedi_build.exedi_build.exedi_build.exedi_build.exedi_build.exedi_build.exedi_build.exedi_build.exedi_build.exedi_build.exedi_build.exedi_build.exe
%System%\di_build.exedi_build.exedi_build.exedi_build.exedi_build.exedi_build.exedi_build.exedi_build.exedi_build.exedi_build.exedi_build.exedi_build.exedi_build.exedi_build.exedi_build.exedi_build.exedi_build.exedi_build.exe
%System%\di_build.exedi_build.exedi_build.exedi_build.exedi_build.exedi_build.exedi_build.exedi_build.exedi_build.exedi_build.exedi_build.exedi_build.exedi_build.exedi_build.exedi_build.exedi_build.exedi_build.exedi_build.exedi_build.exe
295,936 bytes MD5: 0x4E4300901DA116F223395A30C38213DB
SHA-1: 0xEE6166A3DE3BD59C54BEAFE778333EDD5192E2C3
Trojan.Gen [Symantec]
Worm.Win32.Zwr.h [Kaspersky Lab]
Generic.dx!bfb4 [McAfee]
Worm:Win32/Secrar.A [Microsoft]
Worm.Win32.Secrar [Ikarus]
3 %System%\packer.exe 293,889 bytes MD5: 0x11E0BD99A207CD8CD25C4F96406889FA
SHA-1: 0x78D39530A9197A6AEF63E5C363B1302073925347
packed with UPX [Kaspersky Lab]
4 [file and pathname of the sample #1] 651,264 bytes MD5: 0x217DB3414766B0244504B9DC471C4D86
SHA-1: 0xD6DD7726AB50A8A9ED879D52E7B27ABDD5119133
Backdoor.Win32.Emogen [Ikarus]

 

Memory Modifications

Process NameProcess FilenameMain Module Size
[filename of the sample #1][file and pathname of the sample #1]663,552 bytes
packer.exe%System%\packer.exe1,613,824 bytes
di_build.exe%System%\di_build.exe303,104 bytes
di_build.exedi_build.exe%System%\di_build.exedi_build.exe303,104 bytes
di_build.exedi_build.exedi_build.exe%System%\di_build.exedi_build.exedi_build.exe303,104 bytes
di_build.exedi_build.exedi_build.exedi_build.exe%System%\di_build.exedi_build.exedi_build.exedi_build.exe303,104 bytes
di_build.exedi_build.exedi_build.exedi_build.exedi_build.exe%System%\di_build.exedi_build.exedi_build.exedi_build.exedi_build.exe303,104 bytes

 

Other details

Russian Federation

 

 

All content ("Information") contained in this report is the copyrighted work of Threat Expert Ltd and its associated companies ("ThreatExpert") and may not be copied without the express permission of ThreatExpert.

The Information is provided on an "as is" basis. ThreatExpert disclaims all warranties, whether express or implied, to the maximum extent permitted by law, including the implied warranties that the Information is merchantable, of satisfactory quality, accurate, fit for a particular purpose or need, or non-infringing, unless such implied warranties are legally incapable of exclusion. Further, ThreatExpert does not warrant or make any representations regarding the use or the results of the use of the Information in terms of their correctness, accuracy, reliability, or otherwise.

Copyright © 2013 ThreatExpert. All rights reserved.