Submission Summary:

What's been foundSeverity Level
Downloads/requests other files from Internet.
Packed with a packer that is known to be used by malware (e.g. to complicate threat analysis or detection).
Contains characteristics of an identified security risk.

 

Technical Details:

 

Possible Security Risk

Security RiskDescription
Worm.AutoRun.WHY Worm.Autorun.WHY is a threat that spread through removable drives and it can run in the background without the knowledge of the user.

Threat CategoryDescription
A keylogger program that can capture all user keystrokes (including confidential details such username, password, credit card number, etc.)
A network-aware worm that attempts to replicate across the existing network(s)
A malicious trojan horse or bot that may represent security risk for the compromised system and/or its network environment
A malicious backdoor trojan that runs in the background and allows remote access to the compromised system

 

File System Modifications

#Filename(s)File SizeFile HashAlias
1 %Temp%\w.exe 2,184 bytes MD5: 0x966CFEE642B76F14B511DA24BEC0E51F
SHA-1: 0x3C169B08531148C22ACE696229FBC032BDCFC4E9
Worm.AutoRun.WHY [PCTools]
Infostealer.Gampass [Symantec]
Generic.dx [McAfee]
Mal/TibsPk-A [Sophos]
Trojan:Win32/Meredrop [Microsoft]
Virus.Win32.Trojan [Ikarus]
Packed/Upack [AhnLab]
packed with PE_Patch [Kaspersky Lab]
2 c:\good.bat 51 bytes MD5: 0x43BC67DB587D96F1BDF63C24F31F96B0
SHA-1: 0x95591A166B17BEA01A0A02B4E24AB5B5A16137C4
Trojan.BAT.KillAV.ec [Kaspersky Lab]
Trojan.BAT.KillAV [Ikarus]
3 %ProgramFiles%\Internet Explorer\smss.exe
[file and pathname of the sample #1]
25,988 bytes MD5: 0x53FD83615AC4AB21FAA6867ECFDC62EE
SHA-1: 0xC368220F44CF2A4144953A6BCCE0C4A902D9DC19
Trojan.Dropper [Symantec]
Worm.Win32.AutoRun.acdm [Kaspersky Lab]
New Malware.aj [McAfee]
Mal/Emogen-F [Sophos]
Trojan-PWS.Win32.OnLineGames [Ikarus]
Packed/Upack [AhnLab]
packed with PE_Patch [Kaspersky Lab]
4 %ProgramFiles%\ltass.exe 38,056 bytes MD5: 0x516B6363B5789AABD136C790D5BBFD54
SHA-1: 0xF38E54E2EAE59B4A843906EE9A5218BEE7CB20C1
Worm.AutoRun.WHY [PCTools]
Trojan.Dropper [Symantec]
Backdoor.Win32.Hupigon.eqzg [Kaspersky Lab]
BackDoor-AWQ.b [McAfee]
Mal/Behav-328, Mal/Behav-024, Mal/Behav-214, Mal/Emogen-I, Mal/Emogen-Z, Mal/Dropper-G [Sophos]
Trojan:Win32/Bepdro.A [Microsoft]
Backdoor.Win32.HacDef.073.B [Ikarus]
Win-Trojan/Hupigon.12024764 [AhnLab]

 

Memory Modifications

Process NameProcess FilenameMain Module Size
[filename of the sample #1][file and pathname of the sample #1]135,168 bytes
ltass.exe%ProgramFiles%\ltass.exe57,344 bytes

 

Other details

China

 

 

All content ("Information") contained in this report is the copyrighted work of Threat Expert Ltd and its associated companies ("ThreatExpert") and may not be copied without the express permission of ThreatExpert.

The Information is provided on an "as is" basis. ThreatExpert disclaims all warranties, whether express or implied, to the maximum extent permitted by law, including the implied warranties that the Information is merchantable, of satisfactory quality, accurate, fit for a particular purpose or need, or non-infringing, unless such implied warranties are legally incapable of exclusion. Further, ThreatExpert does not warrant or make any representations regarding the use or the results of the use of the Information in terms of their correctness, accuracy, reliability, or otherwise.

Copyright © 2013 ThreatExpert. All rights reserved.