Submission Summary:

What's been foundSeverity Level
Produces outbound traffic.
Creates a startup registry entry.
Contains characteristics of an identified security risk.

 

Technical Details:

 

Possible Security Risk

Threat CategoryDescription
A malicious trojan horse or bot that may represent security risk for the compromised system and/or its network environment

 

File System Modifications

#Filename(s)File SizeFile HashAlias
1 %Windir%\Config\svchsot.exe 179,200 bytes MD5: 0x3658589DF3D6C47115A689511F6B613F
SHA-1: 0x9F45CF2CB8DC501950AAEF0A3F316CDA74118210
Trojan.Gen [Symantec]
Trojan-Proxy.Win32.Horst.hz [Kaspersky Lab]
Trojan.Win32.Spy [Ikarus]
2 %Windir%\Tasks\At1.job 344 bytes MD5: 0x3062C66924F8ED7A2CE12FEB58BF1309
SHA-1: 0x2E55BAEA1E7EA6C51D966B0D9E8B0799896924AC
(not available)
3 %Windir%\Tasks\At10.job 344 bytes MD5: 0x6DD9E58F7EA04C4C6E6369C4F9BA6907
SHA-1: 0x1F2C1A97873ED6229841F305A081C8B4545AB231
(not available)
4 %Windir%\Tasks\At11.job 344 bytes MD5: 0xD49E2FD78AE294CADC8CA256D438FAE8
SHA-1: 0x0DD64ABAE4E229238B6E6D422881029D68BAF3DD
(not available)
5 %Windir%\Tasks\At12.job 344 bytes MD5: 0x47F11801903DCE4508AD00A3B0539BFA
SHA-1: 0xF371759434A8C61E864E22C660E7ABA645F0ED16
(not available)
6 %Windir%\Tasks\At13.job 344 bytes MD5: 0xB24070A73BD806A925159E475DC04A0F
SHA-1: 0x787E9825117706DB904206715F7FB44FFDEA48AB
(not available)
7 %Windir%\Tasks\At14.job 344 bytes MD5: 0x4497BA3E91D3C620A5992C0E67CF5816
SHA-1: 0x6D968B7D2A9F092822F504F755F89C0AAC571FD0
(not available)
8 %Windir%\Tasks\At15.job 344 bytes MD5: 0x1F3BD8AECF4C384BEC63FD472626A9CD
SHA-1: 0xA380EA5830662A955FD4426B400131B6AC7FA254
(not available)
9 %Windir%\Tasks\At16.job 344 bytes MD5: 0x33E602B37A2B946239A34AFF2B1C3EB5
SHA-1: 0xA27400272BD0378A998990E1CB55AC24738EBEBE
(not available)
10 %Windir%\Tasks\At17.job 344 bytes MD5: 0x67B8039A87724FC4BB7C88DCB8B0295E
SHA-1: 0x02A7696D72AD54F65BDD6817E25B4DD123C4CFCD
(not available)
11 %Windir%\Tasks\At18.job 344 bytes MD5: 0xB610EC5885B3D88B559FCA2159B21DA7
SHA-1: 0xA864A87F394B391B986B06BBBCF7C9EBE44E0211
(not available)
12 %Windir%\Tasks\At19.job 344 bytes MD5: 0x6D59EB8C69C3968E568B02AA9D44A4E7
SHA-1: 0xEFB099F3ECD209A486B4E57AFDD9AD53014C9DB7
(not available)
13 %Windir%\Tasks\At2.job 344 bytes MD5: 0xBCA5E8016409BE68E775C940F4ED598B
SHA-1: 0xF3EA5F8A58F6E4554D5EC5D2E35FBA586E9A3DE4
(not available)
14 %Windir%\Tasks\At20.job 344 bytes MD5: 0x02AF08D2CB20B6C369ED67CFB0B40A4C
SHA-1: 0x9712E8B49D28659CD44C3A745A88D0179980108F
(not available)
15 %Windir%\Tasks\At21.job 344 bytes MD5: 0xD02610D70C189C16EEA359F30273DAFC
SHA-1: 0xA7072A83558EBC947E65ADF790AE336BADFBB822
(not available)
16 %Windir%\Tasks\At22.job 344 bytes MD5: 0x1ABEC734E44D446A314F16E54EA506C2
SHA-1: 0x1978F2C80D72DF9AD89334DCD558579683933F8C
(not available)
17 %Windir%\Tasks\At23.job 344 bytes MD5: 0xE21A3B8940F7C03386F6F0C19C55F7AD
SHA-1: 0xB42A292921B91AE50C8595EAE5B68A1CE067BEF4
(not available)
18 %Windir%\Tasks\At24.job 344 bytes MD5: 0xF3E285FD328B94823B60DDE1D632831F
SHA-1: 0x406ABCC5390708121E37FD8CE1FB1C8FADB08DE7
(not available)
19 %Windir%\Tasks\At3.job 344 bytes MD5: 0xBCC6C1FBCBA206DF4EB17AC17EC6B4DD
SHA-1: 0xCF444A531CE026F83FCC9F4BB011A0643E15DF38
(not available)
20 %Windir%\Tasks\At4.job 344 bytes MD5: 0x72DB97095F8F529B384DCF9A81611069
SHA-1: 0xD807326B16A37F7FE5DEDC1C763AB97F2CEAD6B1
(not available)
21 %Windir%\Tasks\At5.job 344 bytes MD5: 0x861E5D004E0777D4ED385727AC18C3C5
SHA-1: 0x13D9FA1DD36B723D3EA8A74AFC99B0465476E6E5
(not available)
22 %Windir%\Tasks\At6.job 344 bytes MD5: 0x934ED5D30E37074A7C02DFC758177647
SHA-1: 0x637590048078E77BE78ECCFB68F2BE695AF1D0BA
(not available)
23 %Windir%\Tasks\At7.job 344 bytes MD5: 0x14E25320B1340F0374815C08D5850BCA
SHA-1: 0xBD7F10C68E678B7A7754F37A3B977295BD1EBC64
(not available)
24 %Windir%\Tasks\At8.job 344 bytes MD5: 0xB85E0F36C098CEE31B2DC829F7F6E5BF
SHA-1: 0x4D531154169EEE691984B0305B1D2EAE36698A47
(not available)
25 %Windir%\Tasks\At9.job 344 bytes MD5: 0xB0CFB7F6E60F33D5E73D09EC012EE714
SHA-1: 0x988C99A543DC94CC23C4C0FA32D60B04CCCDDF8A
(not available)

 

Registry Modifications

 

Other details

Remote HostPort Number
www.meserver2.com8282

 

Outbound traffic (potentially malicious)

 

 

All content ("Information") contained in this report is the copyrighted work of Threat Expert Ltd and its associated companies ("ThreatExpert") and may not be copied without the express permission of ThreatExpert.

The Information is provided on an "as is" basis. ThreatExpert disclaims all warranties, whether express or implied, to the maximum extent permitted by law, including the implied warranties that the Information is merchantable, of satisfactory quality, accurate, fit for a particular purpose or need, or non-infringing, unless such implied warranties are legally incapable of exclusion. Further, ThreatExpert does not warrant or make any representations regarding the use or the results of the use of the Information in terms of their correctness, accuracy, reliability, or otherwise.

Copyright © 2013 ThreatExpert. All rights reserved.