Submission Summary:

What's been foundSeverity Level
Downloads/requests other files from Internet.
Registers a 32-bit in-process server DLL.

 

Technical Details:

 

File System Modifications

#Filename(s)File SizeFile HashAlias
1 %Windir%\AhnRpta.exe 69,120 bytes MD5: 0x388B8FBC36A8558587AFC90FB23A3B99
SHA-1: 0xED55AD0A7078651857BD8FC0EEDD8B07F94594CC
(not available)
2 %System%\afmain0.dll 78,848 bytes MD5: 0xC7926ABA862831526A6D6E1B64B8A85A
SHA-1: 0x45ED45C26573364686B25A07D57ECC824925F314
TrojanDownloader:Win32/Frethog.C [Microsoft]
Worm.Win32.Viking [Ikarus]
packed with PE_Patch [Kaspersky Lab]
3 [file and pathname of the sample #1] 97,091 bytes MD5: 0xBA0069B922185D5048A5A8094E9E0824
SHA-1: 0x12762096FE398A756BC41DE18A3EA5FB3486756C
TrojanDownloader:Win32/Frethog.C [Microsoft]
Worm.Win32.Viking [Ikarus]

 

Memory Modifications

Process NameProcess FilenameMain Module Size
AhnRpta.exe%Windir%\ahnrpta.exe81,920 bytes
[filename of the sample #1][file and pathname of the sample #1]225,280 bytes

Process NameProcess FilenameAllocated Size
IEXPLORE.EXE%ProgramFiles%\internet explorer\iexplore.exe524,288 bytes

Module NameModule FilenameAddress Space Details
afmain0.dll%System%\afmain0.dllProcess name: explorer.exe
Process filename: %Windir%\explorer.exe
Address space: 0x19C0000 - 0x19EB000
afmain0.dll%System%\afmain0.dllProcess name: dllhost.exe
Process filename: %System%\dllhost.exe
Address space: 0x2530000 - 0x255B000
afmain0.dll%System%\afmain0.dllProcess name: sdnsmain.exe
Process filename: %Windir%\dns\sdnsmain.exe
Address space: 0x1620000 - 0x164B000
afmain0.dll%System%\afmain0.dllProcess name: AhnRpta.exe
Process filename: %Windir%\ahnrpta.exe
Address space: 0x8D0000 - 0x8FB000
afmain0.dll%System%\afmain0.dllProcess name: IEXPLORE.EXE
Process filename: %ProgramFiles%\internet explorer\iexplore.exe
Address space: 0xC50000 - 0xC7B000

 

Registry Modifications

 

Other details

URL to be downloadedFilename for the downloaded bits
http://cscs7.com/xmfx/mg12.txt%Temp%\mg12.txt
http://cscs7.com/xmfx/mg11.txt%Temp%\mg11.txt
http://mgaazz.com/xxc/ddr.rar%System%\ddr.exe

 

 

All content ("Information") contained in this report is the copyrighted work of Threat Expert Ltd and its associated companies ("ThreatExpert") and may not be copied without the express permission of ThreatExpert.

The Information is provided on an "as is" basis. ThreatExpert disclaims all warranties, whether express or implied, to the maximum extent permitted by law, including the implied warranties that the Information is merchantable, of satisfactory quality, accurate, fit for a particular purpose or need, or non-infringing, unless such implied warranties are legally incapable of exclusion. Further, ThreatExpert does not warrant or make any representations regarding the use or the results of the use of the Information in terms of their correctness, accuracy, reliability, or otherwise.

Copyright © 2009 ThreatExpert. All rights reserved.