Examples of Mal/Katusha-F include:
Example 1
File Information
- Size
- 87K
- SHA-1
- 480b802fd8374161c94f5e210cfb73a31ec42acd
- MD5
- e6f66ce084b9cc2f3f2f8c35b1636ab8
- CRC-32
- a3915a0f
- File type
- Windows executable
- First seen
- 2012-06-22
Example 2
File Information
- Size
- 92K
- SHA-1
- 4c34309a02f5f7637e0e5dbe720ac4a3bf5e6218
- MD5
- a0fb84626eb64b273cdaf802dd09451e
- CRC-32
- c9ebb798
- File type
- Windows executable
- First seen
- 2012-06-26
Runtime Analysis
Copies Itself To
- c:\Documents and Settings\test user\Application Data\KB00954719.exe
Registry Keys Created
- HKCU\Software\Microsoft\Windows\CurrentVersion\Run
- KB00954719.exe
- "c:\Documents and Settings\test user\Application Data\KB00954719.exe"
- HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings
- GlobalUserOffline
- 0x00000000
Processes Created
- c:\Documents and Settings\test user\application data\kb00954719.exe
- c:\windows\system32\cmd.exe
IP Connections
- 110.234.150.163:8080
- 123.49.61.59:8080
- 173.203.96.79:8080
- 184.106.189.124:8080
- 190.81.107.70:8080
- 202.143.147.35:8080
- 203.172.252.26:8080
- 203.172.252.29:8080
- 203.217.147.52:8080
- 211.44.250.173:8080
- 41.168.5.140:8080
- 83.238.208.55:8080
- 89.111.176.87:8080
- 91.121.103.143:8080
- 95.142.167.193:8080
- 97.74.75.172:8080
Example 3
File Information
- Size
- 89K
- SHA-1
- 6fdb8b6b79dfa19300d663d5c1f7f094f75faf26
- MD5
- 5a51705c2be86bd8ea6155c894d76977
- CRC-32
- 9015bb98
- File type
- Windows executable
- First seen
- 2012-06-24