Submission Summary:

What's been foundSeverity Level
Downloads/requests other files from Internet.
Modifies some system settings that may have negative impact on overall system security state.
Registers a 32-bit in-process server DLL.
Contains characteristics of an identified security risk.

 

Technical Details:

 

Possible Security Risk

Threat CategoryDescription
A malicious trojan horse or bot that may represent security risk for the compromised system and/or its network environment

 

File System Modifications

#Filename(s)File SizeFile HashAlias
1 %AppData%\Microsoft\Windows Media\9.0\WMSDKNSD.XML 53 bytes MD5: 0xA9B5DA9AEC61657B32393D96217165F0
SHA-1: 0x80B5C577155ACD269B450D70F6B2CBED693EDF49
(not available)
2 %MyDocuments%\My eBooks.lnk 1,526 bytes MD5: 0xDB6394A5C6040C64F7071B4FE128D6EF
SHA-1: 0x8A9759BF8463B39452213754E2EDC414B2B29CCD
(not available)
3 %MyDocuments%\My Music.lnk 1,520 bytes MD5: 0xFE3A94317F1DB8F35B5F3ECAC4317191
SHA-1: 0x0DDF51B973FC30D04B8FE9B784C402C314CB1B00
(not available)
4 %MyDocuments%\My Pictures.lnk 1,538 bytes MD5: 0xEBB34F4483D0F0CC3394717A374745E8
SHA-1: 0x79911434D4D0931B888F2ECCE69C392F664D80B5
(not available)
5 %MyDocuments%\R?CYCL?R\desktop.ini
c:\R?CYCL?R\desktop.ini
65 bytes MD5: 0xAD0B0B4416F06AF436328A3C12DC491B
SHA-1: 0x743C7AD130780DE78CCBF75AA6F84298720AD3FA
(not available)
6 %MyDocuments%\R?CYCL?R\??.com
%ProgramFiles%\Windows Media Player\wmplayerc.exe
c:\R?CYCL?R\??.com
[file and pathname of the sample #1]
74,006 bytes MD5: 0x529A61E430599EE324DFA36D60B4CE39
SHA-1: 0x62C2AD5618B0143FAD605CB326D2A3561E269FA5
BackDoor-EE [McAfee]
Virus.Win32.Sality [Ikarus]
Win-Trojan/Swisyn.67072 [AhnLab]
7 c:\Inetpub.lnk 1,514 bytes MD5: 0x9BE2CBE83B64EA92A4A1AF4D1BEAF571
SHA-1: 0x88F15366FD2D365186499928369EC9C7E0CA9107
(not available)
8 %ProgramFiles%\Windows Media Player\svchost.exe 9,216 bytes MD5: 0x5742797D62DE674F299CB991E927687E
SHA-1: 0x7E7B097B67B5CF55AF1D3B4DA8A8D2B9BEC3551A
Trojan Horse [Symantec]
BackDoor-EE [McAfee]
W32/SillyFDC-EI [Sophos]
Trojan.Win32.Agent [Ikarus]
9 c:\Program Files.lnk 1,550 bytes MD5: 0x948A1F2B5FDA5EADD07E0903A37B3163
SHA-1: 0x4FBAA8388FCECC1BD10A06DC40DFB3B38A864C2F
(not available)
10 c:\WINDOWS.lnk 1,514 bytes MD5: 0x73CFE1F35071755502DDB3A5744C46E7
SHA-1: 0x216B3B2F371B96779384B8D2DAFC39EF929E2721
(not available)

 

Memory Modifications

Process NameProcess FilenameMain Module Size
svchost.exe%ProgramFiles%\Windows Media Player\svchost.exe69,632 bytes

 

Registry Modifications

 

Other details

Server NameServer PortConnect as UserConnection Password
www.17tahun.us80(null)(null)
www.duniasex.com80(null)(null)
www.filmbebas.com80(null)(null)
www.susuaku.us80(null)(null)
www.downloadbokep.net80(null)(null)
www.syok3gp.net80(null)(null)
www.cewekina.net80(null)(null)
www.toketgadis.com80(null)(null)
www.17tahun1.com80(null)(null)
www.bokeps.com80(null)(null)
www.bok3p.com80(null)(null)

 

 

All content ("Information") contained in this report is the copyrighted work of Threat Expert Ltd and its associated companies ("ThreatExpert") and may not be copied without the express permission of ThreatExpert.

The Information is provided on an "as is" basis. ThreatExpert disclaims all warranties, whether express or implied, to the maximum extent permitted by law, including the implied warranties that the Information is merchantable, of satisfactory quality, accurate, fit for a particular purpose or need, or non-infringing, unless such implied warranties are legally incapable of exclusion. Further, ThreatExpert does not warrant or make any representations regarding the use or the results of the use of the Information in terms of their correctness, accuracy, reliability, or otherwise.

Copyright © 2013 ThreatExpert. All rights reserved.