Submission Summary:

What's been foundSeverity Level
Produces outbound traffic.
Downloads/requests other files from Internet.
Creates a startup registry entry.

 

Technical Details:

 

File System Modifications

#Filename(s)File SizeFile HashAlias
1 %AppData%\Yqod\mode.exe 329,376 bytes MD5: 0x412EC8B02E633DB1A7EDDD9A27763D72
SHA-1: 0xA838C3B3D507F00FF169B4028B005B7825A00771
PWS-Zbot.gen.uh [McAfee]
Mal/Cleaman-B [Sophos]
Virus.Win32.Zbot [Ikarus]
2 %Temp%\tmp9de6b57c.bat 168 bytes MD5: 0x8E5937FFCCFBE857D10481AE371ECD18
SHA-1: 0xF577C07973FF4B10E21E475EE8F95412A5AEF01F
(not available)
3 [file and pathname of the sample #1] 329,376 bytes MD5: 0xDEA7013F2068EA25CF00E8C87014F096
SHA-1: 0xD4114C00EB5D90D7FAEC3E9E4F98734EFD6ED914
PWS-Zbot.gen.uh [McAfee]
Mal/Cleaman-B [Sophos]
Virus.Win32.Zbot [Ikarus]

 

Memory Modifications

Process NameProcess FilenameAllocated Size
cmd.exe%System%\cmd.exe278,528 bytes

 

Registry Modifications

 

Other details

Remote HostPort Number
173.194.33.1980
89.149.123.1013429

 

Outbound traffic (potentially malicious)

 

 

All content ("Information") contained in this report is the copyrighted work of Threat Expert Ltd and its associated companies ("ThreatExpert") and may not be copied without the express permission of ThreatExpert.

The Information is provided on an "as is" basis. ThreatExpert disclaims all warranties, whether express or implied, to the maximum extent permitted by law, including the implied warranties that the Information is merchantable, of satisfactory quality, accurate, fit for a particular purpose or need, or non-infringing, unless such implied warranties are legally incapable of exclusion. Further, ThreatExpert does not warrant or make any representations regarding the use or the results of the use of the Information in terms of their correctness, accuracy, reliability, or otherwise.

Copyright © 2013 ThreatExpert. All rights reserved.