Submission Summary:

 

Technical Details:

 

File System Modifications

#Filename(s)File SizeFile Hash
1 %Temp%\WinUpdater.exe 125 bytes MD5: 0x7C5F5A68051F6B0C0E9A2AD33C40D415
SHA-1: 0x120865765927A61AF83F02B83DC297EEDE61EC41
2 [file and pathname of the sample #1] 50,688 bytes MD5: 0x93443E59C473B89B5AFAD940A843982A
SHA-1: 0x70862E5147A2A4EDC2CB986BD42F020A6C2D56A8

 

Memory Modifications

Process NameProcess FilenameMain Module Size
[filename of the sample #1][file and pathname of the sample #1]N/A

 

Other details

 

 

Downloaded File Summary:

 

Technical Details:

 

File System Modifications

#Filename(s)File SizeFile HashAlias
1 %Temp%\WinUpdate.exe 1,330,688 bytes MD5: 0x3EE465299C78E4477E3B604FFF1F052A
SHA-1: 0x3ABDF68172AE10C99D7961FA1655B5D7B1865199
Win32.SuspectCrc [Ikarus]
packed with PE_Patch.Enigma [Kaspersky Lab]
2 %Programs%\Startup\(Skype).lnk 858 bytes MD5: 0xB0B43EF385E5F4DF997E37F91500B0FC
SHA-1: 0xCF55BD6A11F00845790B7042672F65C029A3D2EC
(not available)
3 [file and pathname of the sample #1] 1,428,199 bytes MD5: 0xD66E114AF7505938EAF80CF3A69DDE7D
SHA-1: 0x7FFA998680C79B65E553708A047B975E5E3CEAA7
Win32.SuspectCrc [Ikarus]

 

Memory Modifications

Process NameProcess FilenameMain Module Size
[filename of the sample #1][file and pathname of the sample #1]212,992 bytes

 

Registry Modifications

 

Other details

Remote HostPort Number
216.6.0.28911

 

Outbound traffic (potentially malicious)

 

 

All content ("Information") contained in this report is the copyrighted work of Threat Expert Ltd and its associated companies ("ThreatExpert") and may not be copied without the express permission of ThreatExpert.

The Information is provided on an "as is" basis. ThreatExpert disclaims all warranties, whether express or implied, to the maximum extent permitted by law, including the implied warranties that the Information is merchantable, of satisfactory quality, accurate, fit for a particular purpose or need, or non-infringing, unless such implied warranties are legally incapable of exclusion. Further, ThreatExpert does not warrant or make any representations regarding the use or the results of the use of the Information in terms of their correctness, accuracy, reliability, or otherwise.

Copyright © 2013 ThreatExpert. All rights reserved.