Submission Summary:

What's been foundSeverity Level
Produces outbound traffic.
Downloads/requests other files from Internet.
Creates a startup registry entry.
Contains characteristics of an identified security risk.

 

Technical Details:

 

Possible Security Risk

Security RiskDescription
Trojan.DNSblocker Trojan.DNSblocker is a malicious trojan horse or bot that may represent security risk for the compromised system and/or its network environment.

Threat CategoryDescription
A network-aware worm that attempts to replicate across the existing network(s)
A malicious trojan horse or bot that may represent security risk for the compromised system and/or its network environment
A code with the rootkit-specific techniques designed to hide the software presence in the system

 

File System Modifications

#Filename(s)File SizeFile HashAlias
1 %Temp%\zpskon_1259758877.exe 46,080 bytes MD5: 0x2BEE8080D2FBD6E1B8C9065A1C0A0FE3
SHA-1: 0xC9B0B53A85D801FEA51093478A53D1F1DC9157E6
(not available)
2 %Windir%\010112010146100101.xxe
%Windir%\010112010146111103.xxe
%Windir%\0101120101465355.xxe
2 bytes MD5: 0x4F59236A872D3D23FE86871831A2ADC8
SHA-1: 0x27CD3AD00D41D7F0601DE9C8B22998E9E173F882
(not available)
3 %Windir%\bk23567.dat
%Windir%\fdgg34353edfgdfdf
1 bytes MD5: 0xC81E728D9D4C2F636F067F89CC14862C
SHA-1: 0xDA4B9237BACCCDF19C0760CAB7AEC4A8359010B0
(not available)
4 %Windir%\freddy75.exe 55,296 bytes MD5: 0xB50A54B54E64F87AC1DC5D3EFFF0662F
SHA-1: 0xC9390822FD27CF2BA38EE77B41719173BA5C4CD1
Net-Worm.Win32.Koobface.csf [Kaspersky Lab]
Win-Trojan/Malware.55296.G [AhnLab]
5 %Windir%\ld15.exe
[file and pathname of the sample #1]
41,472 bytes MD5: 0xEE54F6FC8B1A3C42A1263708C67FA4AD
SHA-1: 0x1B37349241DD7CD55515D7CC307934A3BA40BA15
Net-Worm.Koobface [PCTools]
W32.Koobface.D [Symantec]
Net-Worm.Win32.Koobface.csa [Kaspersky Lab]
W32/Koobface.worm.gen.u [McAfee]
6 %Windir%\pp12.exe 38,912 bytes MD5: 0x9BC9652E2E1C633BCBDCF9594956D74C
SHA-1: 0xC2406F79E64D4169F876844EE15EE44A789253E6
Net-Worm.Win32.Koobface.cse [Kaspersky Lab]
7 %Windir%\rdr_1259729075.exe
%Windir%\rdr_1259729158.exe
92,672 bytes MD5: 0xEA9173CC0A85B804E6D7B764DEEB0BBF
SHA-1: 0xF993EC082306FB217208AEFEB458607B1F4A8677
Trojan.Dropper [PCTools]
Trojan.Dropper [Symantec]
Trojan-Dropper.Win32.Agent.biin [Kaspersky Lab]
W32/Koobface.worm.gen.d [McAfee]
W32/KoobFa-N [Sophos]
VirTool:WinNT/Koobface.gen!D [Microsoft]
Worm.Win32.Koobface [Ikarus]
Win32/Koobface.worm.92672 [AhnLab]
8 %System%\drivers\fio32.sys 59,520 bytes MD5: 0xB5897245E34DF833A207241A11C065F8
SHA-1: 0x5B164A222DC6B83C7E851FD9F28D45A57F352DB6
Trojan.Generic [PCTools]
Trojan Horse [Symantec]
Rootkit.Win32.Agent.wqv [Kaspersky Lab]
Generic.dx!gzf [McAfee]
Mal/Generic-A [Sophos]
VirTool:WinNT/Koobface.gen!D [Microsoft]
Rootkit.Win32.Agent [Ikarus]
9 %System%\fio32.dll 50,688 bytes MD5: 0x2926C3F8EA16177F03DC8969AC983EAA
SHA-1: 0x2A14DC70513D317E9DC7E2698EE45E0C3D7279D9
Net-Worm.Koobface [PCTools]
W32.Koobface.A [Symantec]
Net-Worm.Win32.Koobface.cln [Kaspersky Lab]
Mal/Generic-A, Mal/KoobHeur-A [Sophos]
Worm.Win32.Koobface [Ikarus]
Win32/Koobface.worm.50688.C [AhnLab]
10 %System%\__c003F894.dat
%System%\__c0081000.dat
34,816 bytes MD5: 0x9BE2B2412E653B3969A988C8D4A44087
SHA-1: 0x4DA69696E22B1B27A2DFFFB558EE599F6396D29E
packed with PE_Patch [Kaspersky Lab]
11 c:\xcrashdump.dat 57 bytes MD5: 0xC538F93E7A688C0F45489B3B7CFC4DF9
SHA-1: 0xE4724C7F1A22CF4C06DF8603D71309EA0E1C4360
(not available)

 

Memory Modifications

Process NameProcess FilenameMain Module Size
freddy75.exe%Windir%\freddy75.exe57,344 bytes
pp12.exe%Windir%\pp12.exe94,208 bytes

Module NameModule FilenameAddress Space Details
__c0081000.dat%System%\__c0081000.datProcess name: explorer.exe
Process filename: %Windir%\explorer.exe
Address space: 0xF90000 - 0xF9C9BC
__c0081000.dat%System%\__c0081000.datProcess name: IEXPLORE.EXE
Process filename: %ProgramFiles%\internet explorer\iexplore.exe
Address space: 0x1990000 - 0x199C9BC
fio32.dll%System%\fio32.dllProcess name: svchost.exe
Process filename: %System%\svchost.exe
Address space: 0x10000000 - 0x10024000

Driver NameDriver Filename
fio32.sys%System%\drivers\fio32.sys

 

Registry Modifications

 

Other details

Russian Federation

PortProtocolProcess
1067UDPfreddy75.exe (%Windir%\freddy75.exe)

Remote HostPort Number
200.58.120.5680
204.0.5.1080
204.0.5.1980
213.193.213.12380
61.235.117.8380
62.149.165.2980
64.6.241.2680
69.63.181.1180
69.63.187.1980
74.125.95.10380

 

Outbound traffic (potentially malicious)

 

 

All content ("Information") contained in this report is the copyrighted work of Threat Expert Ltd and its associated companies ("ThreatExpert") and may not be copied without the express permission of ThreatExpert.

The Information is provided on an "as is" basis. ThreatExpert disclaims all warranties, whether express or implied, to the maximum extent permitted by law, including the implied warranties that the Information is merchantable, of satisfactory quality, accurate, fit for a particular purpose or need, or non-infringing, unless such implied warranties are legally incapable of exclusion. Further, ThreatExpert does not warrant or make any representations regarding the use or the results of the use of the Information in terms of their correctness, accuracy, reliability, or otherwise.

Copyright © 2010 ThreatExpert. All rights reserved.