Mal/Katusha-F

Category: Viruses and Spyware Protection available since:27 Jun 2012 19:09:42 (GMT)
Type: Malicious behavior Last Updated:27 Jun 2012 19:09:42 (GMT)
Prevalence: Small Number of Reports

Download Download our free Virus Removal Tool - Find and remove threats your antivirus missed

Examples of Mal/Katusha-F include:

Example 1

File Information

Size
87K
SHA-1
480b802fd8374161c94f5e210cfb73a31ec42acd
MD5
e6f66ce084b9cc2f3f2f8c35b1636ab8
CRC-32
a3915a0f
File type
Windows executable
First seen
2012-06-22

Example 2

File Information

Size
92K
SHA-1
4c34309a02f5f7637e0e5dbe720ac4a3bf5e6218
MD5
a0fb84626eb64b273cdaf802dd09451e
CRC-32
c9ebb798
File type
Windows executable
First seen
2012-06-26

Runtime Analysis

Copies Itself To
  • c:\Documents and Settings\test user\Application Data\KB00954719.exe
Registry Keys Created
  • HKCU\Software\Microsoft\Windows\CurrentVersion\Run
    KB00954719.exe
    "c:\Documents and Settings\test user\Application Data\KB00954719.exe"
  • HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings
    GlobalUserOffline
    0x00000000
Processes Created
  • c:\Documents and Settings\test user\application data\kb00954719.exe
  • c:\windows\system32\cmd.exe
IP Connections
  • 110.234.150.163:8080
  • 123.49.61.59:8080
  • 173.203.96.79:8080
  • 184.106.189.124:8080
  • 190.81.107.70:8080
  • 202.143.147.35:8080
  • 203.172.252.26:8080
  • 203.172.252.29:8080
  • 203.217.147.52:8080
  • 211.44.250.173:8080
  • 41.168.5.140:8080
  • 83.238.208.55:8080
  • 89.111.176.87:8080
  • 91.121.103.143:8080
  • 95.142.167.193:8080
  • 97.74.75.172:8080

Example 3

File Information

Size
89K
SHA-1
6fdb8b6b79dfa19300d663d5c1f7f094f75faf26
MD5
5a51705c2be86bd8ea6155c894d76977
CRC-32
9015bb98
File type
Windows executable
First seen
2012-06-24

download Try Sophos products for free
Download now