Submission Summary:

What's been foundSeverity Level
Creates a startup registry entry.
Contains characteristics of an identified security risk.

 

Technical Details:

 

Possible Security Risk

Security RiskDescription
Email-Worm.Brontok!ct Email-Worm.Brontok!ct is a mass-mailing application that propagates from one system to another by creating a new email message, attaching itself and then sending the message without user's consent

Threat CategoryDescription
A network-aware worm that attempts to replicate across the existing network(s)
A malicious trojan horse or bot that may represent security risk for the compromised system and/or its network environment

 

File System Modifications

#Filename(s)File SizeFile HashAlias
1 %CommonPrograms%\Startup\Startup.exe
%AppData%\%UserName%.exe
%Windir%\Shell\explorer.exe
%Windir%\Shell\Hide IP.exe
%Windir%\Shell\iexplorer.exe
[file and pathname of the sample #1]
%System%\%UserName%'s Setting.scr
44,485 bytes MD5: 0x831AC51EA2A887936A1F60A10052D156
SHA-1: 0x37ED8C442095CC84EDCC46BE0FA35B3D92341711
Email-Worm.Rontokbro [PCTools]
W32.Rontokbro.K@mm [Symantec]
Email-Worm.Win32.Brontok.ai [Kaspersky Lab]
W32/Rontokbro.gen@MM [McAfee]
PE_BRONTOK.A [Trend Micro]
W32/Brontok-DX [Sophos]
Worm:Win32/Brontok.FF [Microsoft]
Trojan.Matba [Ikarus]
Win32/Brontok.worm.182784 [AhnLab]
packed with Polyene [Kaspersky Lab]
2 %DesktopDir%\about me.htm 320 bytes MD5: 0x027B0F0597C01DEA9439E3F1845937CC
SHA-1: 0x37CA20771D2DC7D76CCB5BFD6D07A67782E22EF8
HTML/Rontokbro [McAfee]
3 %AppData%\msvbvm60.dll
%Windir%\Shell\msvbvm60.dll
%Windir%\system\msvbvm60.dll
1,386,496 bytes MD5: 0xF28EB5CBC3CA6D8C787F09F047D1F9C8
SHA-1: 0x70DB1FAC822974BC9B636A984BCC1DA2E67F8DE5
(not available)
4 %Windir%\Shell\Reaming.bat 81 bytes MD5: 0x406EB82976BB1B571A751C679E6FB824
SHA-1: 0xE50677D8F86E1AFD9C0ECD73E72C0C74AAD78C84
Trojan.Generic [PCTools]
Trojan Horse [Symantec]
Bat/Rontokbro [McAfee]
BAT.AddUser [Ikarus]

 

Memory Modifications

Process NameProcess FilenameMain Module Size
%UserName%.exe%AppData%\%UserName%.exe106,496 bytes
[filename of the sample #1][file and pathname of the sample #1]106,496 bytes

Module NameModule FilenameAddress Space Details
MSVBVM60.DLL%AppData%\MSVBVM60.DLLProcess name: %UserName%.exe
Process filename: %AppData%\%UserName%.exe
Address space: 0x66000000 - 0x66152000

 

Registry Modifications

 

 

All content ("Information") contained in this report is the copyrighted work of Threat Expert Ltd and its associated companies ("ThreatExpert") and may not be copied without the express permission of ThreatExpert.

The Information is provided on an "as is" basis. ThreatExpert disclaims all warranties, whether express or implied, to the maximum extent permitted by law, including the implied warranties that the Information is merchantable, of satisfactory quality, accurate, fit for a particular purpose or need, or non-infringing, unless such implied warranties are legally incapable of exclusion. Further, ThreatExpert does not warrant or make any representations regarding the use or the results of the use of the Information in terms of their correctness, accuracy, reliability, or otherwise.

Copyright © 2013 ThreatExpert. All rights reserved.