Mal/Motsky-A

Category: Viruses and Spyware Protection available since:26 Mar 2008 15:27:21 (GMT)
Type: Malicious behavior Last Updated:26 Mar 2008 15:27:21 (GMT)
Prevalence: Small Number of Reports

Download Download our free Virus Removal Tool - Find and remove threats your antivirus missed

Examples of Mal/Motsky-A include:

Example 1

File Information

Size
114K
SHA-1
27fa77c425d89f7f5871fd0284004c1eba2c5a62
MD5
630d58dfab81aab86c7534af03a2459c
CRC-32
9deec158
File type
application/x-ms-dos-executable
First seen
2011-02-22

Runtime Analysis

Dropped Files
  • C:\WINDOWS\system32\klogon.vbs
    Size
    96
    SHA-1
    4cd1876c0b52a51b3bfb7e11aeb549f0036d8448
    MD5
    a3bf6ca95b1c1a6af1bf8568e777636f
    CRC-32
    f8bed13f
    File type
    application/octet-stream
    First seen
    2010-09-10
  • C:\WINDOWS\system32\kilogon.dll
    Size
    158K
    SHA-1
    ca934ab7aec7683c2e8ebf44ef03407ad9a1750d
    MD5
    eb4da5ecd8dcf818434074501179ed2a
    CRC-32
    0d594486
    File type
    application/x-ms-dos-executable
    First seen
    2010-12-14
Processes Created
  • c:\windows\system32\cmd.exe
  • c:\windows\system32\rundll32.exe
  • c:\windows\system32\wscript.exe

Example 2

File Information

Size
114K
SHA-1
516ceb1f2197bdb2353e57657a78443fd4b3d17f
MD5
60dd7074651d868fc8428e032e4975ce
CRC-32
4923e5da
File type
application/x-ms-dos-executable
First seen
2011-03-22

Runtime Analysis

Dropped Files
  • C:\WINDOWS\system32\kilogon.dll
    Size
    158K
    SHA-1
    a86e15b58c44ac9e483cee22bbb3624345822c1d
    MD5
    beebae3a351b3f796836ed221772babd
    CRC-32
    7edb784a
    File type
    application/x-ms-dos-executable
    First seen
    2011-01-14
  • C:\WINDOWS\system32\klogon.vbs
    Size
    96
    SHA-1
    4cd1876c0b52a51b3bfb7e11aeb549f0036d8448
    MD5
    a3bf6ca95b1c1a6af1bf8568e777636f
    CRC-32
    f8bed13f
    File type
    application/octet-stream
    First seen
    2010-09-10
Processes Created
  • c:\windows\system32\cmd.exe
  • c:\windows\system32\rundll32.exe
  • c:\windows\system32\wscript.exe

Example 3

File Information

Size
2.0M
SHA-1
0a11f616a07e268827a94d366d94e5a6de749d51
MD5
69dc77275fcdd18ecd59a3e8c58feeb2
CRC-32
03f66e09
File type
application/x-ms-dos-executable
First seen
2011-02-19

download Try Sophos products for free
Download now