Submission Summary:

What's been foundSeverity Level
Produces outbound traffic.
Creates a startup registry entry.

 

Technical Details:

 

File System Modifications

#Filename(s)File SizeFile HashAlias
1 %AppData%\Microsoft\Windows\.data 466 bytes MD5: 0xB074392F8629EDB965349928028FAEE3
SHA-1: 0xDD4A42C83F5AB6C9FE9F9ECEE3BC1A2B96D66181
(not available)
2 %AppData%\Microsoft\Windows\msshell.exe 18,432 bytes MD5: 0x4C3B10F4BD2717818E3555278F69E7F4
SHA-1: 0x6652F0FD5FE7338950FDCD2C47C79A8014B1CF57
Trojan-Dropper.Win32.Delf [Ikarus]
3 %AppData%\Microsoft\Windows\unicode2.nls 162,304 bytes MD5: 0x3292C2BC1D01FEDC8609C89FCE066DCF
SHA-1: 0x705F477B29E397729816695B485FB9071F8C33A7
Backdoor.Win32.Vipdataend [Ikarus]
4 [file and pathname of the sample #1] 305,664 bytes MD5: 0xAD2E1FAE851E527E691EE53877840EDD
SHA-1: 0xEAF56FB6546B7C134945864841735669625F598F
(not available)

 

Memory Modifications

Process NameProcess FilenameMain Module Size
msshell.exe%AppData%\microsoft\windows\msshell.exe49,152 bytes
[filename of the sample #1][file and pathname of the sample #1]339,968 bytes

Module NameModule FilenameAddress Space Details
unicode2.nls%AppData%\Microsoft\Windows\unicode2.nlsProcess name: explorer.exe
Process filename: %Windir%\explorer.exe
Address space: 0xD70000 - 0xD9C000

 

Registry Modifications

 

Other details

Remote HostPort Number
89.144.61.145443

 

Outbound traffic (potentially malicious)

 

 

All content ("Information") contained in this report is the copyrighted work of Threat Expert Ltd and its associated companies ("ThreatExpert") and may not be copied without the express permission of ThreatExpert.

The Information is provided on an "as is" basis. ThreatExpert disclaims all warranties, whether express or implied, to the maximum extent permitted by law, including the implied warranties that the Information is merchantable, of satisfactory quality, accurate, fit for a particular purpose or need, or non-infringing, unless such implied warranties are legally incapable of exclusion. Further, ThreatExpert does not warrant or make any representations regarding the use or the results of the use of the Information in terms of their correctness, accuracy, reliability, or otherwise.

Copyright © 2013 ThreatExpert. All rights reserved.