| Visit ThreatExpert web site | | | Close Report |
| What's been found | Severity Level |
| Produces outbound traffic. | ![]() |
| Downloads/requests other files from Internet. | ![]() |
| Creates a startup registry entry. | ![]() |
| Contains characteristics of an identified security risk. | ![]() |
![]() | Possible Security Risk |
| Security Risk | Description |
| Trojan.DNSblocker | Trojan.DNSblocker is a malicious trojan horse or bot that may represent security risk for the compromised system and/or its network environment. |
| Threat Category | Description |
![]() |
A malicious trojan horse or bot that may represent security risk for the compromised system and/or its network environment |
![]() |
A code with the rootkit-specific techniques designed to hide the software presence in the system |
![]() |
A network-aware worm that attempts to replicate across the existing network(s) |
![]() | File System Modifications |
| # | Filename(s) | File Size | File Hash | Alias |
| 1 |
%Windir%\010112010146116101.xxe
%Windir%\0101120101465355.xxe |
2 bytes | MD5: 0x4F59236A872D3D23FE86871831A2ADC8 SHA-1: 0x27CD3AD00D41D7F0601DE9C8B22998E9E173F882 |
(not available) |
| 2 |
%Windir%\bk23567.dat
%Windir%\fdgg34353edfgdfdf |
1 bytes | MD5: 0xC81E728D9D4C2F636F067F89CC14862C SHA-1: 0xDA4B9237BACCCDF19C0760CAB7AEC4A8359010B0 |
(not available) |
| 3 | %Windir%\freddy75.exe | 56,320 bytes | MD5: 0x7543B53DB465A6F2A21C669DAC1BBF7C SHA-1: 0x853CECE36F4E4C8F3E7E52A3691FFF7F16AD1587 |
(not available) |
| 4 |
%Windir%\ld15.exe
[file and pathname of the sample #1] |
41,472 bytes | MD5: 0xC2D546A6CC6507F4D7AC7BA59AF765EA SHA-1: 0x49BBCFE9F89CBE1B69A6EB578B75648FB5DC2006 |
(not available) |
| 5 |
%Windir%\pp12.exe
|
38,912 bytes | MD5: 0xAB28A26A31391F2E477A4090EB8F7421 SHA-1: 0xB800603FD4AE1E395D6FB33CE521D5864C93E8CB |
(not available) |
| 6 |
%Windir%\rdr_1259465923.exe
%Windir%\rdr_1259466011.exe |
92,672 bytes | MD5: 0xEA9173CC0A85B804E6D7B764DEEB0BBF SHA-1: 0xF993EC082306FB217208AEFEB458607B1F4A8677 |
Trojan.Dropper [Symantec]Trojan-Dropper.Win32.Agent.biin [Kaspersky Lab] W32/Koobface.worm.gen.d [McAfee] W32/KoobFa-N [Sophos] VirTool:WinNT/Koobface.gen!D [Microsoft] Worm.Win32.Koobface [Ikarus]Win32/Koobface.worm.92672 [AhnLab] |
| 7 |
%System%\drivers\fio32.sys
|
59,520 bytes | MD5: 0xB5897245E34DF833A207241A11C065F8 SHA-1: 0x5B164A222DC6B83C7E851FD9F28D45A57F352DB6 |
Trojan Horse [Symantec]Rootkit.Win32.Agent.wqv [Kaspersky Lab] Generic.dx!gzf [McAfee] Mal/Generic-A [Sophos]VirTool:WinNT/Koobface.gen!D [Microsoft] Rootkit.Win32.Agent [Ikarus] |
| 8 |
%System%\fio32.dll
|
50,688 bytes | MD5: 0x2926C3F8EA16177F03DC8969AC983EAA SHA-1: 0x2A14DC70513D317E9DC7E2698EE45E0C3D7279D9 |
W32.Koobface.A [Symantec]Net-Worm.Win32.Koobface.cln [Kaspersky Lab] Mal/Generic-A , Mal/KoobHeur-A [Sophos]Worm.Win32.Koobface [Ikarus]Win32/Koobface.worm.50688.C [AhnLab] |
![]() | Memory Modifications |
| Process Name | Process Filename | Main Module Size |
| freddy75.exe | %Windir%\freddy75.exe | 57,344 bytes |
pp12.exe![]() | %Windir%\pp12.exe![]() | 57,344 bytes |
| Module Name | Module Filename | Address Space Details |
fio32.dll![]() | %System%\fio32.dll![]() | Process name: svchost.exe![]() Process filename: %System%\svchost.exe ![]() Address space: 0x10000000 - 0x10024000 |
| Service Name | Display Name | Status | Service Filename |
| fioo32 | fioo32 | "Starting" | %System%\SvchOst.eXE -k fioo32 |
| Driver Name | Driver Filename |
fio32.sys![]() | %System%\drivers\fio32.sys![]() |
![]() | Registry Modifications |
![]() | Other details |
| Port | Protocol | Process |
| 1065 | UDP | freddy75.exe (%Windir%\freddy75.exe) |
| Remote Host | Port Number |
| 198.92.147.248 | 80 |
| 200.58.120.56 | 80 |
| 204.0.5.10 | 80 |
| 204.0.5.19 | 80 |
| 61.235.117.83 | 80 |
| 62.221.197.18 | 80 |
| 69.63.181.12 | 80 |
| 69.63.181.16 | 80 |
| 72.167.232.205 | 80 |
| 72.52.158.105 | 80 |
![]() | Outbound traffic (potentially malicious) |
All content ("Information") contained in this report is the copyrighted work of Threat Expert Ltd and its associated companies ("ThreatExpert") and may not be copied without the express permission of ThreatExpert.
The Information is provided on an "as is" basis. ThreatExpert disclaims all warranties, whether express or implied, to the maximum extent permitted by law, including the implied warranties that the Information is merchantable, of satisfactory quality, accurate, fit for a particular purpose or need, or non-infringing, unless such implied warranties are legally incapable of exclusion. Further, ThreatExpert does not warrant or make any representations regarding the use or the results of the use of the Information in terms of their correctness, accuracy, reliability, or otherwise.
Copyright © 2010 ThreatExpert. All rights reserved.