Submission Summary:

What's been foundSeverity Level
Produces outbound traffic.
Downloads/requests other files from Internet.
Contains characteristics of an identified security risk.

 

Technical Details:

 

Possible Security Risk

Threat CategoryDescription
A malicious trojan horse or bot that may represent security risk for the compromised system and/or its network environment

 

File System Modifications

#Filename(s)File SizeFile HashAlias
1 %AppData%\{cbf70787-72f9-b6ef-7e3c-8c19ccb74892}\@ 2,048 bytes MD5: 0xE88CB2F68B24365A46A21ABB1402FCFB
SHA-1: 0x09DFE8A60032B9CE4A41A1F2E82B2C623B7662A9
Mal/ZAccConf-A [Sophos]
2 %AppData%\{cbf70787-72f9-b6ef-7e3c-8c19ccb74892}\n
%Windir%\Installer\{cbf70787-72f9-b6ef-7e3c-8c19ccb74892}\n
48,640 bytes MD5: 0xD737A492DA92181661400B0E4893AB6D
SHA-1: 0xA5CA42E61F43F4A192A2F091DAED2A441D0F3DCA
(not available)
3 %Windir%\Installer\{cbf70787-72f9-b6ef-7e3c-8c19ccb74892}\@ 2,048 bytes MD5: 0xC08CF76E733281CFF3C0F09210D6DF72
SHA-1: 0x8EAE98F34727AC69A919A223F9A604DE2109D0A2
Mal/ZAccConf-A [Sophos]
4 %Windir%\Installer\{cbf70787-72f9-b6ef-7e3c-8c19ccb74892}\U\00000001.@ 1,696 bytes MD5: 0x218F559363F0BE9BDF0BADE486717862
SHA-1: 0x8E6ABE478C95262A1BB0FBA464DA119E64143A10
Generic.dx!b2z4 [McAfee]
Mal/ZAccess-X [Sophos]
Trojan.Win32.Sirefef [Ikarus]
5 %Windir%\Installer\{cbf70787-72f9-b6ef-7e3c-8c19ccb74892}\U\80000000.@ 13,312 bytes MD5: 0xA9200C6035A01D7C65CB20E737095070
SHA-1: 0x543F4BCDCA70979360389F9EB6DE40170D1D836C
Trojan.Zeroaccess [Symantec]
ZeroAccess.ee [McAfee]
Mal/ZAccess-CA [Sophos]
Win64 [Ikarus]
6 %Windir%\Installer\{cbf70787-72f9-b6ef-7e3c-8c19ccb74892}\U\800000cb.@ 19,456 bytes MD5: 0x4493ED95174AC75A859F86767C324E78
SHA-1: 0x71292BB55126F2406BF6D35C213B402ABB5128F2
ZeroAccess.eh [McAfee]
Mal/ZAccess-CA [Sophos]
Virus.Win32.Vundo [Ikarus]
7 [file and pathname of the sample #1] 185,856 bytes MD5: 0x1D221B72943837D6BFF6FA5204E00676
SHA-1: 0x0824EF47E289CA43EA9237EBB17D41407AAB22AE
(not available)

 

Memory Modifications

Process NameProcess FilenameAllocated Size
services.exe%System%\services.exe28,672 bytes
services.exe%System%\services.exe40,960 bytes
services.exe%System%\services.exe36,864 bytes

Service NameDisplay NameNew StatusService Filename
ALGApplication Layer Gateway Service"Stopped"%System%\alg.exe

 

Registry Modifications

 

Other details

Remote HostPort Number
213.108.252.18580
97.103.163.24916464

 

Outbound traffic (potentially malicious)

 

 

All content ("Information") contained in this report is the copyrighted work of Threat Expert Ltd and its associated companies ("ThreatExpert") and may not be copied without the express permission of ThreatExpert.

The Information is provided on an "as is" basis. ThreatExpert disclaims all warranties, whether express or implied, to the maximum extent permitted by law, including the implied warranties that the Information is merchantable, of satisfactory quality, accurate, fit for a particular purpose or need, or non-infringing, unless such implied warranties are legally incapable of exclusion. Further, ThreatExpert does not warrant or make any representations regarding the use or the results of the use of the Information in terms of their correctness, accuracy, reliability, or otherwise.

Copyright © 2013 ThreatExpert. All rights reserved.