Submission Summary:

What's been foundSeverity Level
Produces outbound traffic.

 

Technical Details:

 

File System Modifications

#Filename(s)File SizeFile HashAlias
1 %UserProfile%\PUTTY.RND 600 bytes MD5: 0xFADA40881F1084345DB1D5F93498D21E
SHA-1: 0x7434C174BCF01F1CF6C1B04EB741E558537F3241
(not available)
2 [file and pathname of the sample #1] 778,240 bytes MD5: 0xBB4330922380177D417933A700D85C63
SHA-1: 0x7DE60092DC427372264110668A8DF92F180E8C62
Generic.dx!upb [McAfee]
Trojan.SuspectCRC [Ikarus]
3 %System%\U1013.exe 1,105,920 bytes MD5: 0xAB5DF308F5586D30F3CA287B139B861A
SHA-1: 0x014DEDA1700F66168FF02E005DBF33538988FE9C
(not available)
4 %System%\utmp\Bfxuvxcmqxme3w5s 48 bytes MD5: 0x3F8B10CF65294555C3603DA4F367541C
SHA-1: 0x66B00A5E889D3C0281B403DC8CF83E3316BE7B0E
(not available)
5 %System%\utmp\Booiczptcrtx2r5v 28 bytes MD5: 0x654662D6A3E66FAA35378D947E5D3A2B
SHA-1: 0x88FF76DFC71B33C36B0A390B8A07E470B93C2B47
(not available)
6 %System%\utmp\Flbkumxjbkjc2w5j 40 bytes MD5: 0xBBA402CBC2F6D43E34CA60E31D9C9DFF
SHA-1: 0x33514397BE9602E32C03BC990CEA46DDBF083E4E
(not available)
7 %System%\utmp\Hbnphjbczecf3l1z 95 bytes MD5: 0x2C8214FAF94ADB6DA8388A1173A5D3BF
SHA-1: 0x7D19CDAA3738D1B5794299239C65F15EF906B56B
(not available)
8 %System%\utmp\Hkemxebrlyry2o1c 36 bytes MD5: 0x9D75933FA2718A8E1AED91433288EDDB
SHA-1: 0x019954353F974770F09720DA7CDFF5B7915AAB39
(not available)
9 %System%\utmp\Lqtcwtwswlsx3o3a 16 bytes MD5: 0xD1667A71FFFFAAD767982011EBAAEFDB
SHA-1: 0x39A7F29DF6B19ED04A085BA7EB62DF02AADBA226
(not available)
10 %System%\utmp\Pngvfgriveic3l3o 30 bytes MD5: 0xFFC52D102A80EB670E7767ECB719CB2E
SHA-1: 0x947D5A9187D75BAD4D81C228219844FB57E0512F
(not available)

 

Memory Modifications

Process NameProcess FilenameMain Module Size
[filename of the sample #1][file and pathname of the sample #1]5,767,168 bytes

 

Registry Modifications

 

Other details

Taiwan
China

PortProtocolProcess
1065TCP[file and pathname of the sample #1]
9666TCP[file and pathname of the sample #1]

Remote HostPort Number
61.223.57.16323620
65.49.14.10443

 

Outbound traffic (potentially malicious)

 

 

All content ("Information") contained in this report is the copyrighted work of Threat Expert Ltd and its associated companies ("ThreatExpert") and may not be copied without the express permission of ThreatExpert.

The Information is provided on an "as is" basis. ThreatExpert disclaims all warranties, whether express or implied, to the maximum extent permitted by law, including the implied warranties that the Information is merchantable, of satisfactory quality, accurate, fit for a particular purpose or need, or non-infringing, unless such implied warranties are legally incapable of exclusion. Further, ThreatExpert does not warrant or make any representations regarding the use or the results of the use of the Information in terms of their correctness, accuracy, reliability, or otherwise.

Copyright © 2013 ThreatExpert. All rights reserved.