Submission Summary:

What's been foundSeverity Level
Downloads/requests other files from Internet.
Contains characteristics of an identified security risk.

 

Technical Details:

 

Possible Security Risk

Threat CategoryDescription
A program that downloads files to the local computer that may represent security risk
A malicious trojan horse or bot that may represent security risk for the compromised system and/or its network environment
A keylogger program that can capture all user keystrokes (including confidential details such username, password, credit card number, etc.)
A malicious backdoor trojan that runs in the background and allows remote access to the compromised system

 

File System Modifications

#Filename(s)File SizeFile HashAlias
1 %Temp%\aimbot 25.2.exe 237,568 bytes MD5: 0x20F1A871D82F7B36B82144BE343CEC69
SHA-1: 0xBED7B3A54C90658EB8C16B99CA5BDD73C97B2499
Downloader [Symantec]
Downloader.a!bhh [McAfee]
Mal/Behav-363 [Sophos]
Trojan:Win32/Meredrop [Microsoft]
Trojan-Clicker.Win32.VB [Ikarus]
2 %Temp%\AIMBOT-FIX For CF Russia.exe 61,440 bytes MD5: 0xFBF53CA546143366A34FBE69E19968C7
SHA-1: 0xCFA574B37EB82DA6A4CC4BEEFD67A124AF13EBC9
Trojan.Gen [Symantec]
Trojan.Win32.Inject.dakx [Kaspersky Lab]
Generic.evx!br [McAfee]
Mal/Behav-363 [Sophos]
Trojan:Win32/Dynamer!dtc [Microsoft]
Trojan.Win32.Inject [Ikarus]
3 %Temp%\aimbot.dll 200,704 bytes MD5: 0xF5E17B9C6A4B732178D30BEB25221781
SHA-1: 0xBE3071EAA1C2715982C3E35B77EB108502339EE4
Backdoor.Trojan [Symantec]
Trojan-Spy.Win32.Agent.bynj [Kaspersky Lab]
Generic PWS.y!dx3 [McAfee]
Mal/Behav-363 [Sophos]
Trojan:Win32/Orsam!rts [Microsoft]
Trojan-Spy.Win32.Agent [Ikarus]
4 %Temp%\setup.reg 294 bytes MD5: 0x511683832EB1F696E831053D67857ABC
SHA-1: 0x6468C5D33F320E40A6718101E3F71F1E5F7B9CFF
(not available)
5 %System%\ads.exe 65,536 bytes MD5: 0x23D6B5AB28D9BB93208159F3BD7E0E7E
SHA-1: 0x7E923709B829C3E4CCDBCBB410480EA3FB5EE4CE
Trojan.Gen [Symantec]
Trojan-Clicker.Win32.VB.hpz [Kaspersky Lab]
Generic PWS.xa [McAfee]
Mal/Behav-363 [Sophos]
TrojanDownloader:Win32/VB.gen!C [Microsoft]
Trojan-Dropper.Win32.BeTrung [Ikarus]
6 %System%\ads2.exe 61,440 bytes MD5: 0xDB6D7BF9B8550AEC897BF056F18B802C
SHA-1: 0x77D7151C4E2BF6D811846C03A3934E22DE27D4D6
Trojan.Gen [Symantec]
Trojan-Clicker.Win32.VB.hpu [Kaspersky Lab]
Generic PWS.xa [McAfee]
Mal/Behav-363 [Sophos]
TrojanDownloader:Win32/VB.gen!C [Microsoft]
Trojan-Clicker.Win32.VB [Ikarus]
7 %System%\ads3.exe 65,536 bytes MD5: 0xCFBB08460416A9758E55D5C9ED1A1EC4
SHA-1: 0x3DBF459E717A8E4A7F759530B74B44B9436C57F9
Trojan.Gen [Symantec]
Trojan-Clicker.Win32.VB.hpv [Kaspersky Lab]
Generic PWS.xa [McAfee]
Mal/Behav-363 [Sophos]
TrojanDownloader:Win32/VB.gen!C [Microsoft]
8 [file and pathname of the sample #1] 452,286 bytes MD5: 0xEDA7690E75C0DF611A7CDF041BEEA97E
SHA-1: 0xAD7B1C6F0AE9EA53472C3F81B43395B28FA990CF
Backdoor.Trojan [Symantec]
Trojan.Win32.Inject.dakx, Trojan-Spy.Win32.Agent.bynj [Kaspersky Lab]
Trojan-Spy.Win32.Agent [Ikarus]

 

Memory Modifications

Process NameProcess FilenameMain Module Size
AIMBOT-FIX For CF Russia.exe%Temp%\aimbot-fix for cf russia.exe94,208 bytes
aimbot 25.2.exe%Temp%\aimbot 25.2.exe503,808 bytes
[generic host process][generic host process filename]45,056 bytes

 

Registry Modifications

 

Other details

PortProtocolProcess
1046UDPaimbot 25.2.exe (%Temp%\aimbot 25.2.exe)

Server NameServer PortConnect as UserConnection Password
adf.ly80(null)(null)
m.aimbotcf.net80(null)(null)

 

 

All content ("Information") contained in this report is the copyrighted work of Threat Expert Ltd and its associated companies ("ThreatExpert") and may not be copied without the express permission of ThreatExpert.

The Information is provided on an "as is" basis. ThreatExpert disclaims all warranties, whether express or implied, to the maximum extent permitted by law, including the implied warranties that the Information is merchantable, of satisfactory quality, accurate, fit for a particular purpose or need, or non-infringing, unless such implied warranties are legally incapable of exclusion. Further, ThreatExpert does not warrant or make any representations regarding the use or the results of the use of the Information in terms of their correctness, accuracy, reliability, or otherwise.

Copyright © 2013 ThreatExpert. All rights reserved.