Troj/Bredo-ACU exhibits the following characteristics:
File Information
- Size
- 56K
- SHA-1
- cff0a4483383aacfcca03357a03af8da685d955f
- MD5
- 77d42e71ba23ba45b42a7b1dcd648d31
- CRC-32
- e10dada1
- File type
- application/x-ms-dos-executable
- First seen
- 2012-10-05
Runtime Analysis
Copies Itself To
- c:\Documents and Settings\test user\Local Settings\Application Data\vghluwpu.exe
Dropped Files
- C:\sample.txt
- Size
- 5
- SHA-1
- c9589c81355baab345cd121a76dcd743d65e131c
- MD5
- 43fb2705d9766ea761f934981936503f
- CRC-32
- 0a181565
- File type
- A binary file with a very small filesize (too small to be malicious)
- First seen
- 2012-08-08
Processes Created
- c:\windows\system32\notepad.exe
- c:\windows\system32\svchost.exe
IP Connections
- 125.214.75.185:84
- 142.200.177.18:61420
- 178.77.103.54:8080
- 188.212.156.180:8080
- 202.169.224.202:8080
- 213.175.218.180:8080
- 213.175.218.181:8080
- 217.160.236.108:84
- 221.210.60.138:60290
- 46.105.121.86:8080
- 46.4.180.98:8080
- 50.22.136.150:8080
- 94.247.176.157:8080