Troj/Bredo-BE exhibits the following characteristics:
Other vendor detection
- Avira
- TR/Dldr.Fraudl.dfg
- Kaspersky
- Trojan-Downloader.Win32.Genome.ajvc
Runtime Analysis
Dropped Files
- C:\WINDOWS\Temp\_ex-08.exe
- C:\WINDOWS\Temp\_ex-68.exe
Processes Created
- c:\windows\system32\ntvdm.exe
HTTP Requests
- http://195.88.190.44/pr/pic/main.exe
- http://95.143.192.38/pr/pic/fixer_sdgareh_b.exe
IP Connections
- 195.88.190.44:80
- 95.143.192.38:80