| Visit ThreatExpert web site | | | Close Report |
[Ikarus]| What's been found | Severity Level |
| Produces outbound traffic. | ![]() |
![]() | File System Modifications |
| # | Filename(s) | File Size | File Hash | Alias |
| 1 | %UserProfile%\PUTTY.RND | 600 bytes | MD5: 0xFADA40881F1084345DB1D5F93498D21E SHA-1: 0x7434C174BCF01F1CF6C1B04EB741E558537F3241 |
(not available) |
| 2 | [file and pathname of the sample #1] | 778,240 bytes | MD5: 0xBB4330922380177D417933A700D85C63 SHA-1: 0x7DE60092DC427372264110668A8DF92F180E8C62 |
Generic.dx!upb [McAfee] Trojan.SuspectCRC [Ikarus] |
| 3 | %System%\U1013.exe | 1,105,920 bytes | MD5: 0xAB5DF308F5586D30F3CA287B139B861A SHA-1: 0x014DEDA1700F66168FF02E005DBF33538988FE9C |
(not available) |
| 4 | %System%\utmp\Bfxuvxcmqxme3w5s | 48 bytes | MD5: 0x3F8B10CF65294555C3603DA4F367541C SHA-1: 0x66B00A5E889D3C0281B403DC8CF83E3316BE7B0E |
(not available) |
| 5 | %System%\utmp\Booiczptcrtx2r5v | 28 bytes | MD5: 0x654662D6A3E66FAA35378D947E5D3A2B SHA-1: 0x88FF76DFC71B33C36B0A390B8A07E470B93C2B47 |
(not available) |
| 6 | %System%\utmp\Flbkumxjbkjc2w5j | 40 bytes | MD5: 0xBBA402CBC2F6D43E34CA60E31D9C9DFF SHA-1: 0x33514397BE9602E32C03BC990CEA46DDBF083E4E |
(not available) |
| 7 | %System%\utmp\Hbnphjbczecf3l1z | 95 bytes | MD5: 0x2C8214FAF94ADB6DA8388A1173A5D3BF SHA-1: 0x7D19CDAA3738D1B5794299239C65F15EF906B56B |
(not available) |
| 8 | %System%\utmp\Hkemxebrlyry2o1c | 36 bytes | MD5: 0x9D75933FA2718A8E1AED91433288EDDB SHA-1: 0x019954353F974770F09720DA7CDFF5B7915AAB39 |
(not available) |
| 9 | %System%\utmp\Lqtcwtwswlsx3o3a | 16 bytes | MD5: 0xD1667A71FFFFAAD767982011EBAAEFDB SHA-1: 0x39A7F29DF6B19ED04A085BA7EB62DF02AADBA226 |
(not available) |
| 10 | %System%\utmp\Pngvfgriveic3l3o | 30 bytes | MD5: 0xFFC52D102A80EB670E7767ECB719CB2E SHA-1: 0x947D5A9187D75BAD4D81C228219844FB57E0512F |
(not available) |
![]() | Memory Modifications |
| Process Name | Process Filename | Main Module Size |
| [filename of the sample #1] | [file and pathname of the sample #1] | 5,767,168 bytes |
![]() | Registry Modifications |
![]() | Other details |
![]() |
Taiwan |
![]() |
China |
| Port | Protocol | Process |
| 1065 | TCP | [file and pathname of the sample #1] |
| 9666 | TCP | [file and pathname of the sample #1] |
| Remote Host | Port Number |
| 61.223.57.163 | 23620 |
| 65.49.14.10 | 443 |
![]() | Outbound traffic (potentially malicious) |
All content ("Information") contained in this report is the copyrighted work of Threat Expert Ltd and its associated companies ("ThreatExpert") and may not be copied without the express permission of ThreatExpert.
The Information is provided on an "as is" basis. ThreatExpert disclaims all warranties, whether express or implied, to the maximum extent permitted by law, including the implied warranties that the Information is merchantable, of satisfactory quality, accurate, fit for a particular purpose or need, or non-infringing, unless such implied warranties are legally incapable of exclusion. Further, ThreatExpert does not warrant or make any representations regarding the use or the results of the use of the Information in terms of their correctness, accuracy, reliability, or otherwise.
Copyright © 2013 ThreatExpert. All rights reserved.