| Visit Threat Expert web site | | | Close Report |
| What's been found | Severity Level |
| A network-aware worm that uses known exploit(s) in order to replicate across vulnerable networks. | ![]() |
| Bugtraq ID 9213: DameWare Mini Remote Control Server Pre-Authentication Buffer Overflow Vulnerability. | ![]() |
| MS03-026: DCOM RPC Interface Buffer Overrun Vulnerability - replication across TCP 135/139/445/593 (common for Spybot, Randex, other IRC Bots). | ![]() |
| MS04-012: DCOM RPC Overflow exploit - replication across TCP 135/139/445/593 (common for Blaster, Welchia, Spybot, Randex, other IRC Bots). | ![]() |
| MS03-007: Microsoft IIS WebDAV Remote Compromise Vulnerability - Unchecked Buffer In Windows Component Could Cause Server Compromise. | ![]() |
| MS04-011: LSASS Overflow exploit - replication across TCP 445 (common for Sasser, Bobax, Kibuv, Korgo, Gaobot, Spybot, Randex, other IRC Bots). | ![]() |
| Capability to perform DoS attacks against other computers. | ![]() |
| Backdoor functionality: connected remote users are able to perform multiple actions on the compromised system. | ![]() |
| Capability to join IRC channels and communicate with the remote computers (e.g. with the purpose of notification or remote administration). | ![]() |
| Capability to terminate Antivirus, Firewall and other security related processes. | ![]() |
| Replication across networks by exploiting weekly restricted shares (common for Randex family of worms). | ![]() |
| Creates a startup registry entry. | ![]() |
| Contains characteristics of a known security risk. | ![]() |
![]() | Possible Security Risk |
| Security Risk | Description |
| Backdoor.Rbot.Gen | Backdoor.Rbot.Gen is an IRC controlled backdoor (or "bot") that can be used to gain unauthorized access to a victim's machine. It can also exhibit worm-like functionality by exploiting weak passwords on network shares. |
![]() | File System Modifications |
| # | Filename(s) | Filename Size | Filename MD5 | Alias |
| 1 | %Temp%\C27D8FEF-D7AE-42c0-82E6-F30598265639.exe | 3,584 bytes | 0x7152446FD31220DD1038B6F7D95AB8A3 | Backdoor.Rbot.Gen [PCTools]Trojan.Win32.KillFiles.im [Kaspersky Lab]TROJ_KFILES.AK [Trend Micro] |
| 2 | %System%\rruxdkf.exe | 180,224 bytes | 0xE6C4776CB9AFFA027F20CAA9F68A5250 | Backdoor.Win32.Rbot.adf [Kaspersky Lab]W32.Spybot.Worm [Symantec]BKDR_Generic [Trend Micro] |
![]() | Memory Modifications |
| Process Name | Process Filename | Main Module Size |
| rruxdkf.exe | %System%\rruxdkf.exe | 679,936 bytes |
| [filename of the sample #1] | [file and pathname of the sample #1] | 679,936 bytes |
| C27D8FEF-D7AE-42c0-82E6-F30598265639.exe | %Temp%\C27D8FEF-D7AE-42c0-82E6-F30598265639.exe | 16,384 bytes |
![]() | Registry Modifications |
![]() | Other details |
![]() | Heuristics Analysis |
All content ("Information") contained in this report is the copyrighted work of Threat Expert Ltd and its associated companies ("Threat Expert") and may not be copied without the express permission of Threat Expert.
The Information is provided on an "as is" basis. Threat Expert disclaims all warranties, whether express or implied, to the maximum extent permitted by law, including the implied warranties that the Information is merchantable, of satisfactory quality, accurate, fit for a particular purpose or need, or non-infringing, unless such implied warranties are legally incapable of exclusion. Further, Threat Expert does not warrant or make any representations regarding the use or the results of the use of the Information in terms of their correctness, accuracy, reliability, or otherwise.
Copyright © 2007 Threat Expert. All rights reserved.