Submission Summary:

What's been foundSeverity Level
Downloads/requests other files from Internet.
Creates a startup registry entry.

 

Technical Details:

 

File System Modifications

#Filename(s)File SizeFile HashAlias
1 %Temp%\FILE_ID.DIZ 48 bytes MD5: 0x645D3EE70CE0F661B971126875EEA36C
SHA-1: 0x903454C047AF1E3C909629636F576A68FCE42A1B
(not available)
2 %Temp%\Hide_My_Ip_V_5_serials_key_by_ViKiNG.exe 376,320 bytes MD5: 0x53CDC5E32CE394C9BBD608AB31706513
SHA-1: 0x8BCD01485C91B08FA8BD00A6300F962CC6AD2031
Trojan.Win32.Nebuler [Ikarus]
packed with UPX [Kaspersky Lab]
3 %Temp%\ViKiNG.nfo 2,921 bytes MD5: 0x51B6DB381292A9C0ACD56E76415689EB
SHA-1: 0xD235F6C057B6E4F83A988F26981168041CF2D5BC
(not available)
4 %System%\msixld32.dll
%System%\msizph32.dll
177,152 bytes MD5: 0xA3F08E1B7245D2CCD9F3AACF6ABCD07C
SHA-1: 0x0DCB2B156F2E5FE5307BB40B5AE9606C992D9106
Troj/Nuage-B [Sophos]
Trojan.Win32.Nebuler [Ikarus]
packed with UPX [Kaspersky Lab]
5 [file and pathname of the sample #1] 366,734 bytes MD5: 0xC97BB6CF85E4260DF6CF1CA4E6F010F4
SHA-1: 0xE6BD8AF55A3B418BC2F9910099CBB109F5433303
Trojan.Win32.Nebuler [Ikarus]

 

Memory Modifications

Module NameModule FilenameAddress Space Details
msixld32.dll%System%\msixld32.dllProcess name: [generic host process]
Process filename: [generic host process filename]
Address space: 0xB50000 - 0xBD7000
msizph32.dll%System%\msizph32.dllProcess name: [generic host process]
Process filename: [generic host process filename]
Address space: 0xB50000 - 0xBD7000

 

Registry Modifications

 

Other details

Server NameServer PortConnect as UserConnection Password
madcapphotoworks.com80(null)(null)
www.bts.brainz.cz80(null)(null)
www.kopta-vojtech.xf.cz80(null)(null)

 

 

All content ("Information") contained in this report is the copyrighted work of Threat Expert Ltd and its associated companies ("ThreatExpert") and may not be copied without the express permission of ThreatExpert.

The Information is provided on an "as is" basis. ThreatExpert disclaims all warranties, whether express or implied, to the maximum extent permitted by law, including the implied warranties that the Information is merchantable, of satisfactory quality, accurate, fit for a particular purpose or need, or non-infringing, unless such implied warranties are legally incapable of exclusion. Further, ThreatExpert does not warrant or make any representations regarding the use or the results of the use of the Information in terms of their correctness, accuracy, reliability, or otherwise.

Copyright © 2013 ThreatExpert. All rights reserved.