Submission Summary:

What's been foundSeverity Level
Produces outbound traffic.
Downloads/requests other files from Internet.
Creates a startup registry entry.
Contains characteristics of an identified security risk.

 

Technical Details:

 

Possible Security Risk

Security RiskDescription
Trojan.DNSblocker Trojan.DNSblocker is a malicious trojan horse or bot that may represent security risk for the compromised system and/or its network environment.

Threat CategoryDescription
A malicious trojan horse or bot that may represent security risk for the compromised system and/or its network environment
A code with the rootkit-specific techniques designed to hide the software presence in the system
A network-aware worm that attempts to replicate across the existing network(s)

 

File System Modifications

#Filename(s)File SizeFile HashAlias
1 %Windir%\010112010146116101.xxe
%Windir%\0101120101465355.xxe
2 bytes MD5: 0x4F59236A872D3D23FE86871831A2ADC8
SHA-1: 0x27CD3AD00D41D7F0601DE9C8B22998E9E173F882
(not available)
2 %Windir%\bk23567.dat
%Windir%\fdgg34353edfgdfdf
1 bytes MD5: 0xC81E728D9D4C2F636F067F89CC14862C
SHA-1: 0xDA4B9237BACCCDF19C0760CAB7AEC4A8359010B0
(not available)
3 %Windir%\freddy75.exe 56,320 bytes MD5: 0x7543B53DB465A6F2A21C669DAC1BBF7C
SHA-1: 0x853CECE36F4E4C8F3E7E52A3691FFF7F16AD1587
(not available)
4 %Windir%\ld15.exe
[file and pathname of the sample #1]
41,472 bytes MD5: 0xC2D546A6CC6507F4D7AC7BA59AF765EA
SHA-1: 0x49BBCFE9F89CBE1B69A6EB578B75648FB5DC2006
(not available)
5 %Windir%\pp12.exe 38,912 bytes MD5: 0xAB28A26A31391F2E477A4090EB8F7421
SHA-1: 0xB800603FD4AE1E395D6FB33CE521D5864C93E8CB
(not available)
6 %Windir%\rdr_1259465923.exe
%Windir%\rdr_1259466011.exe
92,672 bytes MD5: 0xEA9173CC0A85B804E6D7B764DEEB0BBF
SHA-1: 0xF993EC082306FB217208AEFEB458607B1F4A8677
Trojan.Dropper [Symantec]
Trojan-Dropper.Win32.Agent.biin [Kaspersky Lab]
W32/Koobface.worm.gen.d [McAfee]
W32/KoobFa-N [Sophos]
VirTool:WinNT/Koobface.gen!D [Microsoft]
Worm.Win32.Koobface [Ikarus]
Win32/Koobface.worm.92672 [AhnLab]
7 %System%\drivers\fio32.sys 59,520 bytes MD5: 0xB5897245E34DF833A207241A11C065F8
SHA-1: 0x5B164A222DC6B83C7E851FD9F28D45A57F352DB6
Trojan Horse [Symantec]
Rootkit.Win32.Agent.wqv [Kaspersky Lab]
Generic.dx!gzf [McAfee]
Mal/Generic-A [Sophos]
VirTool:WinNT/Koobface.gen!D [Microsoft]
Rootkit.Win32.Agent [Ikarus]
8 %System%\fio32.dll 50,688 bytes MD5: 0x2926C3F8EA16177F03DC8969AC983EAA
SHA-1: 0x2A14DC70513D317E9DC7E2698EE45E0C3D7279D9
W32.Koobface.A [Symantec]
Net-Worm.Win32.Koobface.cln [Kaspersky Lab]
Mal/Generic-A, Mal/KoobHeur-A [Sophos]
Worm.Win32.Koobface [Ikarus]
Win32/Koobface.worm.50688.C [AhnLab]

 

Memory Modifications

Process NameProcess FilenameMain Module Size
freddy75.exe%Windir%\freddy75.exe57,344 bytes
pp12.exe%Windir%\pp12.exe57,344 bytes

Module NameModule FilenameAddress Space Details
fio32.dll%System%\fio32.dllProcess name: svchost.exe
Process filename: %System%\svchost.exe
Address space: 0x10000000 - 0x10024000

Service NameDisplay NameStatusService Filename
fioo32fioo32"Starting"%System%\SvchOst.eXE -k fioo32

Driver NameDriver Filename
fio32.sys%System%\drivers\fio32.sys

 

Registry Modifications

 

Other details

PortProtocolProcess
1065UDPfreddy75.exe (%Windir%\freddy75.exe)

Remote HostPort Number
198.92.147.24880
200.58.120.5680
204.0.5.1080
204.0.5.1980
61.235.117.8380
62.221.197.1880
69.63.181.1280
69.63.181.1680
72.167.232.20580
72.52.158.10580

 

Outbound traffic (potentially malicious)

 

 

All content ("Information") contained in this report is the copyrighted work of Threat Expert Ltd and its associated companies ("ThreatExpert") and may not be copied without the express permission of ThreatExpert.

The Information is provided on an "as is" basis. ThreatExpert disclaims all warranties, whether express or implied, to the maximum extent permitted by law, including the implied warranties that the Information is merchantable, of satisfactory quality, accurate, fit for a particular purpose or need, or non-infringing, unless such implied warranties are legally incapable of exclusion. Further, ThreatExpert does not warrant or make any representations regarding the use or the results of the use of the Information in terms of their correctness, accuracy, reliability, or otherwise.

Copyright © 2010 ThreatExpert. All rights reserved.