Submission Summary:

 

Technical Details:

 

Possible Security Risk

Threat CategoryDescription
A malicious trojan horse or bot that may represent security risk for the compromised system and/or its network environment

 

File System Modifications

#Filename(s)File SizeFile HashAlias
1 %AppData%\addons.dat 24,923 bytes MD5: 0x930858FDAE362EA451339F9B5468AEBE
SHA-1: 0x5C128E27C04A258C58F301AA7671085A91AAC75E
(not available)
2 %AppData%\Microsoft\CLR Security Config\v2.0.50727.42\security.config.cch 724 bytes MD5: 0xAC16C4F9F4C72D9635BF40D9606F5E0E
SHA-1: 0xAFA2309AA4108633C4126B7D46D167F6E01428E7
(not available)
3 %Temp%\1.tmp
%System%\Bifrost\server.exe
83,676 bytes MD5: 0xCD3718120E701CF1219636DC8A07E5CA
SHA-1: 0x75250DE78125FD2AEA7A1DF2A58996F479311B66
Trojan-Dropper.Win32.Injector [Ikarus]
4 %Windir%\Microsoft.NET\Framework\v2.0.50727\CONFIG\enterprisesec.config.cch
%Windir%\Microsoft.NET\Framework\v2.0.50727\CONFIG\security.config.cch
1,066 bytes MD5: 0xEC1DB3DAA172F8D247AD21652AE74D04
SHA-1: 0xB502D239C51DAB1CBEF9849B9A05810E38BA3C27
(not available)
5 %System%\Bifrost\logg.dat 0 bytes MD5: 0xD41D8CD98F00B204E9800998ECF8427E
SHA-1: 0xDA39A3EE5E6B4B0D3255BFEF95601890AFD80709
(not available)
6 [file and pathname of the sample #1] 1,553,408 bytes MD5: 0x2DE7603114F2F6AF8DAB305DC3A32060
SHA-1: 0x5728E47E3239853AFE46C8164DE4085AF15162A9
Trojan.Win32.Patched.ka [Kaspersky Lab]
Generic Dropper.pm.gen [McAfee]
Mal/EncPk-UJ [Sophos]
Constructor:Win32/Bifrose.A [Microsoft]
Constructor.Win32.Bifrose [Ikarus]

 

Memory Modifications

Process NameProcess FilenameMain Module Size
[filename of the sample #1][file and pathname of the sample #1]1,578,496 bytes
server.exe%System%\Bifrost\server.exe33,696 bytes
1.tmp%Temp%\1.tmp33,696 bytes

Process NameMain Module Size
IEXPLORE.EXE102,400 bytes
IEXPLORE.EXE102,400 bytes
IEXPLORE.EXE102,400 bytes
IEXPLORE.EXE102,400 bytes
IEXPLORE.EXE102,400 bytes
IEXPLORE.EXE102,400 bytes
IEXPLORE.EXE102,400 bytes
IEXPLORE.EXE102,400 bytes
IEXPLORE.EXE102,400 bytes
IEXPLORE.EXE102,400 bytes
IEXPLORE.EXE102,400 bytes
IEXPLORE.EXE102,400 bytes
IEXPLORE.EXE102,400 bytes
IEXPLORE.EXE102,400 bytes
IEXPLORE.EXE102,400 bytes
IEXPLORE.EXE102,400 bytes
IEXPLORE.EXE102,400 bytes
IEXPLORE.EXE102,400 bytes
IEXPLORE.EXE102,400 bytes
IEXPLORE.EXE102,400 bytes
IEXPLORE.EXE102,400 bytes
IEXPLORE.EXE102,400 bytes
IEXPLORE.EXE102,400 bytes
IEXPLORE.EXE102,400 bytes
IEXPLORE.EXE102,400 bytes
IEXPLORE.EXE102,400 bytes
IEXPLORE.EXE102,400 bytes
IEXPLORE.EXE102,400 bytes
IEXPLORE.EXE102,400 bytes

 

Registry Modifications

 

Other details

Sweden

PortProtocolProcess
81TCP[file and pathname of the sample #1]

Remote HostPort Number
zaki2000.no-ip.info81

 

Outbound traffic (potentially malicious)

 

 

All content ("Information") contained in this report is the copyrighted work of Threat Expert Ltd and its associated companies ("ThreatExpert") and may not be copied without the express permission of ThreatExpert.

The Information is provided on an "as is" basis. ThreatExpert disclaims all warranties, whether express or implied, to the maximum extent permitted by law, including the implied warranties that the Information is merchantable, of satisfactory quality, accurate, fit for a particular purpose or need, or non-infringing, unless such implied warranties are legally incapable of exclusion. Further, ThreatExpert does not warrant or make any representations regarding the use or the results of the use of the Information in terms of their correctness, accuracy, reliability, or otherwise.

Copyright © 2013 ThreatExpert. All rights reserved.