Submission Summary:

What's been foundSeverity Level
Downloads/requests other files from Internet.

 

Technical Details:

 

File System Modifications

#Filename(s)File SizeFile HashAlias
1 [file and pathname of the sample #1] 11,776 bytes MD5: 0xEB4209AC9062804A8C83831FFB0DC6C7
SHA-1: 0xFD765CA128A0034E8D7582D81423B690B9A71693
Suspicious.MH690 [Symantec]
Trojan-GameThief.Win32.Lmir.cha [Kaspersky Lab]
Mal/Behav-328, Mal/Behav-010, Mal/Emogen-I [Sophos]
packed with PE_Patch.UPX [Kaspersky Lab]

 

Memory Modifications

Process NameProcess FilenameMain Module Size
[filename of the sample #1][file and pathname of the sample #1]61,440 bytes

 

Other details

URL to be downloadedFilename for the downloaded bits
http://arplgm.cn/1.exe%Windir%\1.exe
http://arplgm.cn/2.exe%Windir%\2.exe
http://arplgm.cn/3.exe%Windir%\3.exe
http://arplgm.cn/4.exe%Windir%\4.exe
http://arplgm.cn/5.exe%Windir%\5.exe
http://arplgm.cn/6.exe%Windir%\6.exe
http://arplgm.cn/7.exe%Windir%\7.exe
http://arplgm.cn/8.exe%Windir%\8.exe
http://arplgm.cn/9.exe%Windir%\9.exe
http://arplgm.cn/0.exe%Windir%\0.exe
http://arplgm.cn/11.exe%Windir%\11.exe
http://arplgm.cn/12.exe%Windir%\12.exe
http://arplgm.cn/13.exe%Windir%\13.exe
http://arplgm.cn/14.exe%Windir%\14.exe
http://arplgm.cn/15.exe%Windir%\15.exe
http://arplgm.cn/16.exe%Windir%\16.exe

 

 

Downloaded File Summary:

What's been foundSeverity Level
Registers a 32-bit in-process server DLL.
Registers a Browser Helper Object (Microsoft's Internet Explorer plugin module).
Contains characteristics of an identified security risk.

 

Technical Details:

 

Possible Security Risk

Security RiskDescription
Trojan-PWS.OnLineGames.GEN Trojan-PWS.OnLineGames.GEN is a trojan that drops a dll and tries to steal vital information from the infected machine with regards to various online games and then tries to send that information to the author of the trojan.
Trojan-Spy.Banker.ALR Trojan.Spy.Banker.ALR steals personal information from an infected PC by monitoring users online activities including but not limited to login information and creditcard numbers which are subsequently sent to a remote server.

 

File System Modifications

#Filename(s)File SizeFile HashAlias
1 %System%\Assicen.dll 792,064 bytes MD5: 0x6728270CB7DBB776ED086F5AC4C82310
SHA-1: 0xE913CC86F68627541DAE2A92509AB230F427E980
(not available)
2 %System%\Hatanem.dat 256 bytes MD5: 0x4ED88D8233C270356D21925B36DC01E6
SHA-1: 0x636C0D8A188A0C9E67AD373730558A6C624A70BC
(not available)
3 %System%\Marctw.dll 9,216 bytes MD5: 0x43F1A08A6FBEFB6F5FF05F5DBD499A35
SHA-1: 0xCE4C84C928806AC9B83713590791D4BAD0426C6D
Mal/HckPk-E [Sophos]
4 %System%\myInsDll.exe 33,280 bytes MD5: 0x8358193945474F68A2D498CBED8EB97E
SHA-1: 0xA905C9849147628387F6B1D5A7BF88FD5A64F15F
(not available)
5 %System%\Ntuscrc.dll 14,848 bytes MD5: 0x22A93F9F1ADF7C253B4943CAA176785D
SHA-1: 0xE051377F94220C8C56C9D34E74E78B6253E9B5F2
packed with ASPack [Kaspersky Lab]
6 %System%\QQ.dll 187,904 bytes MD5: 0x354D2E3AB343FA7340D3D12D153FC2CC
SHA-1: 0xC7AF1DA65C905D49790798CA6C7B2C9572FBA728
packed with PE_Patch.UPX [Kaspersky Lab]
7 [file and pathname of the sample #1] 205,312 bytes MD5: 0x5AEB58CD335731D731E2136D601893EB
SHA-1: 0xEE2D0B92927D2792A4193A43B2A663AE4EC8A74F
Mal/Generic-A [Sophos]
Trojan-Dropper.Delf [Ikarus]
8 [file and pathname of the sample #2] 16,896 bytes MD5: 0xDF1E477C084CBA34C8CAAF33912B67A4
SHA-1: 0xE6992E8316A3EF3C62497A63440CD8FD635B9D56
Suspicious.MH690 [Symantec]
Mal/HckPk-A [Sophos]
Trojan.Zlob [Ikarus]
9 [file and pathname of the sample #3] 18,944 bytes MD5: 0x8CA28416EDF8C0DA6FCB764EA25EE8BE
SHA-1: 0x89B3F8F06E4A3F33538FD869C1D1EA0BA901A20A
Suspicious.MH690 [Symantec]
Mal/HckPk-A [Sophos]
Virus.Win32.JunkPoly [Ikarus]
10 %System%\sfc32.dll 133,120 bytes MD5: 0xE8F132E41430A1EFD24282BE4DFF0723
SHA-1: 0x96FF851E5CC953D99950110F64D0DA8E67D9B215
Trojan-Spy.Banker.ALR [PCTools]
PatchedSFC [McAfee]
11 %System%\Yamezakw.dll 3,584 bytes MD5: 0xCFF013F4A17F309B8456269A836B1A6E
SHA-1: 0x77D60AE7AF31CA90579348F30F8F12022881BC76
Mal/HckPk-E [Sophos]
12 %System%\Ynams.dat 256 bytes MD5: 0x9DBB43890B4A2964A96573679673B561
SHA-1: 0x0FEA263548AB2BA775AD9BA9FA221A4CA6CFA070
(not available)

 

Memory Modifications

Process NameProcess FilenameMain Module Size
[filename of the sample #1][file and pathname of the sample #1]229,376 bytes
myInsDll.exe%System%\myinsdll.exe45,056 bytes
[filename of the sample #3][file and pathname of the sample #3]57,344 bytes
[filename of the sample #2][file and pathname of the sample #2]57,344 bytes
[generic host process][generic host process filename]20,480 bytes

Module NameModule FilenameAddress Space Details
Ntuscrc.dll%System%\Ntuscrc.dllProcess name: myInsDll.exe
Process filename: %System%\myinsdll.exe
Address space: 0xAC0000 - 0xBC3000
sfc32.dll%System%\sfc32.dllProcess name: myInsDll.exe
Process filename: %System%\myinsdll.exe
Address space: 0x76C60000 - 0x76C89000

 

Registry Modifications

 

Other details

China

 

 

All content ("Information") contained in this report is the copyrighted work of Threat Expert Ltd and its associated companies ("ThreatExpert") and may not be copied without the express permission of ThreatExpert.

The Information is provided on an "as is" basis. ThreatExpert disclaims all warranties, whether express or implied, to the maximum extent permitted by law, including the implied warranties that the Information is merchantable, of satisfactory quality, accurate, fit for a particular purpose or need, or non-infringing, unless such implied warranties are legally incapable of exclusion. Further, ThreatExpert does not warrant or make any representations regarding the use or the results of the use of the Information in terms of their correctness, accuracy, reliability, or otherwise.

Copyright © 2009 ThreatExpert. All rights reserved.