| Visit ThreatExpert web site | | | Close Report |
NOTICE: The content shown in the above window is captured automatically and is not controlled or endorsed by ThreatExpert.
Please contact us on this link should any material be offensive or inappropriate and we will ensure any such content is blocked from future viewers of the report.
![]() | File System Modifications |
| # | Filename(s) | File Size | File Hash | Alias |
| 1 | %AppData%\Macromedia\AdobeInstall.exe | 4,220,113 bytes | MD5: 0xEE61772D2327E38A141028482A59CF15 SHA-1: 0x098CD4EA314B9C72E7B42D4FC9EEF70022188088 |
Program:Win32/Pameseg.BU [Microsoft] |
| 2 |
%AppData%\Macromedia\flashutill.exe
[file and pathname of the sample #1] |
4,274,176 bytes | MD5: 0x9A1270B0A1E88F4613A6367D0B142498 SHA-1: 0xA973BF923C8141C1FF67F599A78EE8CADD442E38 |
(not available) |
| 3 | %AppData%\Macromedia\ProxyService.dll | 27,136 bytes | MD5: 0x919F36AF64D9E535086665BD2834A67E SHA-1: 0xE37AE96CA3E3E317DDE9AE098AE8E11B824DEB95 |
(not available) |
| 4 | %AppData%\Macromedia\Resources.resources | 180 bytes | MD5: 0xD85FE5B9A2E22066B1D7DC89C16EE527 SHA-1: 0x78147369BCAC902B8AEFBE59E26852E0E179BFB6 |
(not available) |
| 5 |
%AppData%\Macromedia\TestApp.exe
|
6,144 bytes | MD5: 0x6C8628F3ED8ADD118A3A0C9E8903AD05 SHA-1: 0xAABB83641888376AE03C1F148B18347C1860317A |
(not available) |
| 6 | %AppData%\Macromedia\TestApp.exe.config | 370 bytes | MD5: 0x48F843FD4118AF09B3E260654ADC7088 SHA-1: 0x0A244F7DAF0C0159A8D25EB89F9C980C1BE16FBB |
(not available) |
| 7 |
%Temp%\{963798FA-D2B8-46BF-A104-6DEBB571B39F}.dll
%Temp%\{C76A2844-927D-4F5D-8F75-39B6958D6924}.dll |
122,880 bytes | MD5: 0xC9F333D1FF898672A34805F94A265329 SHA-1: 0x2DEAAC66698FB2E9B3868D23034C3211C508B739 |
packed with UPX [Kaspersky Lab] |
![]() | Memory Modifications |
| Process Name | Process Filename | Main Module Size |
| adobeinstall.exe | %AppData%\macromedia\adobeinstall.exe | 2,617,344 bytes |
| [filename of the sample #1] | [file and pathname of the sample #1] | N/A |
![]() | Registry Modifications |
![]() | Other details |
![]() |
Russian Federation |
![]() |
Australia |
All content ("Information") contained in this report is the copyrighted work of Threat Expert Ltd and its associated companies ("ThreatExpert") and may not be copied without the express permission of ThreatExpert.
The Information is provided on an "as is" basis. ThreatExpert disclaims all warranties, whether express or implied, to the maximum extent permitted by law, including the implied warranties that the Information is merchantable, of satisfactory quality, accurate, fit for a particular purpose or need, or non-infringing, unless such implied warranties are legally incapable of exclusion. Further, ThreatExpert does not warrant or make any representations regarding the use or the results of the use of the Information in terms of their correctness, accuracy, reliability, or otherwise.
Copyright © 2013 ThreatExpert. All rights reserved.