Troj/Comame-E exhibits the following characteristics:
File Information
- Size
- 176K
- SHA-1
- c4e2036213666f84127edcdf4ec2252cb01747c4
- MD5
- 5a609d0179c8cd953eb3b829584b3fe7
- CRC-32
- 6784e429
- File type
- Windows executable
- First seen
- 2013-01-27
Runtime Analysis
Copies Itself To
- c:\Documents and Settings\test user\Local Settings\Temp\Del2.tmp
Dropped Files
- C:\WINDOWS\Tasks\conime.exe
- Size
- 15M
- SHA-1
- 363225cebd97cb705ffbc8fabf64dad3ce6d763b
- MD5
- 7a44e230e9b453ec3156a8445ab4cc80
- CRC-32
- 4728aa01
- File type
- Windows executable
- First seen
- 2013-01-27
- C:\WINDOWS\Tasks\svchost.exe
- Size
- 19K
- SHA-1
- c82b81d0d3c186c465814726523ee5461f48410e
- MD5
- 8863751434d7f8e125b392c50f854a98
- CRC-32
- e61fbb00
- File type
- Windows executable
- First seen
- 2013-01-27
Registry Keys Created
- HKCU\Software\Microsoft\Windows\CurrentVersion\Run
- taskday
- C:\WINDOWS\tasks\conime.exe
Processes Created
- c:\docume~1\support\locals~1\temp\del2.tmp
- c:\windows\system32\rundll32.exe
- c:\windows\tasks\conime.exe
- c:\windows\tasks\svchost.exe
HTTP Requests
- http://nssmc2013.4pu.com/a.asp
DNS Requests