Submission Summary:

What's been foundSeverity Level
Downloads/requests other files from Internet.
Modifies some system settings that may have negative impact on overall system security state.
Creates a startup registry entry.
Contains characteristics of an identified security risk.

 

Technical Details:

 

Possible Security Risk

Threat CategoryDescription
A network-aware worm that attempts to replicate across the existing network(s)
A malicious trojan horse or bot that may represent security risk for the compromised system and/or its network environment

 

File System Modifications

#Filename(s)File SizeFile HashAlias
1 %Windir%\regsvr.exe
%System%\regsvr.exe
[file and pathname of the sample #1]
%System%\svchost .exe
681,984 bytes MD5: 0x4DAEF1AA18A0B69FD7EF1711EBE9E362
SHA-1: 0xBB5157B34FA3BBC79C8B7CBA7506F9A2A189B528
W32.Imaut [Symantec]
IM-Worm.Win32.Sohanad.qi [Kaspersky Lab]
Trojan.Autoit [Ikarus]
Dropper/Agent.617984 [AhnLab]
2 %System%\28463\svchost.001 2,800 bytes MD5: 0xC427F41A9EB12166C278DA8FED8A0C4A
SHA-1: 0xE0E1D1C8F6B58675A544F1461997CFC37A2E6C63
IM-Worm.Win32.Sohanad.it [Kaspersky Lab]
IM-Worm.Win32.Sohanad [Ikarus]
3 %System%\setting.ini 0 bytes MD5: 0xD41D8CD98F00B204E9800998ECF8427E
SHA-1: 0xDA39A3EE5E6B4B0D3255BFEF95601890AFD80709
(not available)
4 %System%\setup.ini 96 bytes MD5: 0x9ECE103C47335F0CC777F1132B8D522F
SHA-1: 0x63AFA171C64F86D99DB81723E1335E960E85FA43
Trojan.Win32.AutoRun.ke [Kaspersky Lab]
Generic!atr [McAfee]
Troj/Agent-GXM [Sophos]
Trojan.Win32.AutoRun [Ikarus]
TextImage/Autorun [AhnLab]
5 %Windir%\Tasks\At1.job 350 bytes MD5: 0x89BE362D4B8460B542C04B5C6ED5B920
SHA-1: 0xA948A5A39CE0617A75D781B06D00DE4D87CF844A
(not available)
6 %Windir%\Tasks\At2.job 350 bytes MD5: 0x4CFB344C22DFCCDF827A8AE8CD9F2EE1
SHA-1: 0xCFC2F68C447AE20A8B65743521AF235E30C9BC5E
(not available)

 

Memory Modifications

Process NameProcess FilenameMain Module Size
[filename of the sample #1][file and pathname of the sample #1]876,544 bytes
regsvr.exe%System%\regsvr.exe876,544 bytes
regsvr.exe%Windir%\regsvr.exe876,544 bytes

 

Registry Modifications

 

Other details

United Kingdom

PortProtocolProcess
1052TCP[file and pathname of the sample #1]

Remote HostPort Number
209.191.122.7080
69.147.125.6580
72.30.2.4380

 

 

All content ("Information") contained in this report is the copyrighted work of Threat Expert Ltd and its associated companies ("ThreatExpert") and may not be copied without the express permission of ThreatExpert.

The Information is provided on an "as is" basis. ThreatExpert disclaims all warranties, whether express or implied, to the maximum extent permitted by law, including the implied warranties that the Information is merchantable, of satisfactory quality, accurate, fit for a particular purpose or need, or non-infringing, unless such implied warranties are legally incapable of exclusion. Further, ThreatExpert does not warrant or make any representations regarding the use or the results of the use of the Information in terms of their correctness, accuracy, reliability, or otherwise.

Copyright © 2013 ThreatExpert. All rights reserved.