Examples of HPsus/Meredrp-A include:
Example 1
File Information
- Size
- 164K
- SHA-1
- 58fb046a7721f519076f8f719675ede09adb9bf7
- MD5
- 01732397a24c3f1af041705503203942
- CRC-32
- 2f51cea5
- File type
- Windows executable
- First seen
- 2011-12-18
Runtime Analysis
Copies Itself To
- C:\WINDOWS\system32\drivers\KM.EXE
- C:\WINDOWS\system32\drivers\SVCHOSTS.EXE
- F:/SVCHOSTS.EXE
Dropped Files
- F:/AUTORUN.INF
- Size
- 64
- SHA-1
- 7aa213d92f55d81fe87b4f676e43ae940689947c
- MD5
- fdf7723402f8befa38220a8e98732832
- CRC-32
- 01509e7f
- File type
- Configuration Data File (generic)
- First seen
- 2011-11-24
- c:\Documents and Settings\test user\Local Settings\Temp\~DF2B47.tmp
Registry Keys Created
- HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Run
- SVCHOST
- C:\WINDOWS\SYSTEM32\DRIVERS\SVCHOSTS.EXE
- HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon
- SVCHOST
- C:\WINDOWS\SYSTEM32\DRIVERS\SVCHOSTS.EXE
Example 2
File Information
- Size
- 148K
- SHA-1
- 73dbbadc1266d19a31a92d8105800ee2bfda57b8
- MD5
- 1e580dd4aea6e8f5485daf44a6dd59cf
- CRC-32
- 47625455
- File type
- Windows executable
- First seen
- 2011-12-18
Runtime Analysis
Copies Itself To
- C:\WINDOWS\system32\drivers\KM.EXE
- C:\WINDOWS\system32\drivers\SVCHOSTS.EXE
- F:/SVCHOSTS.EXE
Dropped Files
- c:\Documents and Settings\test user\Local Settings\Temp\~DF2848.tmp
- F:/AUTORUN.INF
- Size
- 64
- SHA-1
- 7aa213d92f55d81fe87b4f676e43ae940689947c
- MD5
- fdf7723402f8befa38220a8e98732832
- CRC-32
- 01509e7f
- File type
- Configuration Data File (generic)
- First seen
- 2011-11-24
Registry Keys Created
- HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Run
- SVCHOST
- C:\WINDOWS\SYSTEM32\DRIVERS\SVCHOSTS.EXE
- HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon
- SVCHOST
- C:\WINDOWS\SYSTEM32\DRIVERS\SVCHOSTS.EXE