Submission Summary:

What's been foundSeverity Level
Creates a startup registry entry.
Contains characteristics of an identified security risk.

 

Technical Details:

 

Possible Security Risk

Threat CategoryDescription
A keylogger program that can capture all user keystrokes (including confidential details such username, password, credit card number, etc.)

 

File System Modifications

#Filename(s)File SizeFile HashAlias
1 %Windir%\B6BE281E\svchsot.exe
[file and pathname of the sample #1]
81,920 bytes MD5: 0x9779E84A35B1272E244A2D219FEA3A37
SHA-1: 0x28172C2EA9AE9E4B79C15D781685CBF15EDFA759
Trojan-Spy.Win32.Agent.cbot [Kaspersky Lab]
BackDoor-FGQ [McAfee]
Troj/Agent-WIB [Sophos]
Backdoor:Win32/Morix.B [Microsoft]
Backdoor.Win32.Morix [Ikarus]
2 %Windir%\Tasks\At1.job 348 bytes MD5: 0x81902606F2E0505685FFBFDF11026156
SHA-1: 0x00735BC7284B86395992A29E06D675401C48FABC
(not available)
3 %Windir%\Tasks\At10.job 348 bytes MD5: 0xB578952F5C28272E234CC2DAA0EB9BCA
SHA-1: 0x68F485C6229EB92C7784FF7E0FA59193FC5E3260
(not available)
4 %Windir%\Tasks\At11.job 348 bytes MD5: 0x34B13FC2484184728D2649ACB6F1CC2D
SHA-1: 0xFF1410AB1230D56F2EED3A72C0F23EF750ECADDD
(not available)
5 %Windir%\Tasks\At12.job 348 bytes MD5: 0x46F6B16623A6624AB9CAB78562410D84
SHA-1: 0x15DDD793293A49778149977106FA03179FEF0C20
(not available)
6 %Windir%\Tasks\At13.job 348 bytes MD5: 0xE55E264DCD1FDFBD340E29F024B0408C
SHA-1: 0xBD1DD11F8B38DE455917134AEF5AE4BD2C4F72AD
(not available)
7 %Windir%\Tasks\At14.job 348 bytes MD5: 0xAA3C3DB47DC4F24EAE0320AAB7E182F2
SHA-1: 0x1807D27955CBDD9C62A0C48938325AA2C80F1902
(not available)
8 %Windir%\Tasks\At15.job 348 bytes MD5: 0x94F778359E7BDE783B3D37DFE8B9E73D
SHA-1: 0xE2E09D7F855C1C48468D78608A878CDF5A2952F4
(not available)
9 %Windir%\Tasks\At16.job 348 bytes MD5: 0xCB8E957A9424E9C675633032D1D4C1C3
SHA-1: 0x142D5C590D636A193FFD2D7B3C1D99551C18F667
(not available)
10 %Windir%\Tasks\At17.job 348 bytes MD5: 0x92436F221E584E1AE1198ACEC2C400BC
SHA-1: 0x3BF260DAAB9FC67E3C98F67BADE4309E5167AF5C
(not available)
11 %Windir%\Tasks\At18.job 348 bytes MD5: 0x8457D44C54B4236AC8FA6C65E0EDB6E9
SHA-1: 0x836F2EA9F7E3653509AA1E10ACE181CED8F72080
(not available)
12 %Windir%\Tasks\At19.job 348 bytes MD5: 0x9D2244AE4CAD14C735CB7DF15C8837B6
SHA-1: 0x6B518FFEDDC7A2B167A1005DA12ECF3720ACF847
(not available)
13 %Windir%\Tasks\At2.job 348 bytes MD5: 0x6B252E423C77B83D425B69E795599DC2
SHA-1: 0xD271BC5C04C70163BB9B96B49190749FBCFCC9C8
(not available)
14 %Windir%\Tasks\At20.job 348 bytes MD5: 0x272EE4427B604334EC83A887BAF96A0C
SHA-1: 0x5033DF307EC8188789543A45D4398F9DE7D126CD
(not available)
15 %Windir%\Tasks\At21.job 348 bytes MD5: 0xDC6CF7F7EC7A1B152F0FB58F5C6994A7
SHA-1: 0xB09A75C3878C7D48513410B907DFD8060296E760
(not available)
16 %Windir%\Tasks\At22.job 348 bytes MD5: 0x85FAECA3BFAACA126DECBADF33B6CC2C
SHA-1: 0x1EB74FD515CD62A0CBE3556A46E4A8216CA3AD89
(not available)
17 %Windir%\Tasks\At23.job 348 bytes MD5: 0x5C6CC0B7A4A2D967D971FB0A1475DB28
SHA-1: 0x85D6364CE0ADFE9B27F399CA69275331B9FE2643
(not available)
18 %Windir%\Tasks\At24.job 348 bytes MD5: 0x9CAB4BB2CAC0819CFEB6190552AF6D5A
SHA-1: 0x1AD2544DFFE8CDDCB8067FB42C2F07C77C4A1659
(not available)
19 %Windir%\Tasks\At3.job 348 bytes MD5: 0xA9D8151BA8675A4B59B1D97991B0F24A
SHA-1: 0xC8A351C27287E42D53CCD926F47940CDC10BECE0
(not available)
20 %Windir%\Tasks\At4.job 348 bytes MD5: 0x8E2659E055AFE9A569C1C272F8E76FFC
SHA-1: 0x8770AA516064ABF2AE758B20FD76531E57377F40
(not available)
21 %Windir%\Tasks\At5.job 348 bytes MD5: 0x75A3B361D9273B270408858C5E7FD1A9
SHA-1: 0x596145DD67AF936810F3F421FB7B332A808FCF67
(not available)
22 %Windir%\Tasks\At6.job 348 bytes MD5: 0xCE8B5B117DCB4F599A24E873D32410E4
SHA-1: 0x738EAB88F60759395AB220346586B30BB7CA1DA1
(not available)
23 %Windir%\Tasks\At7.job 348 bytes MD5: 0x61D9BADC060DBCD96BB0083F0844DE18
SHA-1: 0xB5A395E76281B450819DE11658524AF7674FACBF
(not available)
24 %Windir%\Tasks\At8.job 348 bytes MD5: 0x80BAF8BD91ABE17C06A252BA5F3660CB
SHA-1: 0xCD1286111FF3354EC91A5BCEE6EECEC4BFB9E6F6
(not available)
25 %Windir%\Tasks\At9.job 348 bytes MD5: 0xFD8CDE3718390EDC03E474ED8F5F999A
SHA-1: 0x45B1193D00E5C9F5B317261B9068E14E7869309E
(not available)

 

Memory Modifications

Process NameProcess FilenameMain Module Size
[filename of the sample #1][file and pathname of the sample #1]98,304 bytes

 

Registry Modifications

 

Other details

Remote HostPort Number
jingjingdeaini.3322.org2012

 

 

All content ("Information") contained in this report is the copyrighted work of Threat Expert Ltd and its associated companies ("ThreatExpert") and may not be copied without the express permission of ThreatExpert.

The Information is provided on an "as is" basis. ThreatExpert disclaims all warranties, whether express or implied, to the maximum extent permitted by law, including the implied warranties that the Information is merchantable, of satisfactory quality, accurate, fit for a particular purpose or need, or non-infringing, unless such implied warranties are legally incapable of exclusion. Further, ThreatExpert does not warrant or make any representations regarding the use or the results of the use of the Information in terms of their correctness, accuracy, reliability, or otherwise.

Copyright © 2013 ThreatExpert. All rights reserved.