Troj/DwnLdr-KOK exhibits the following characteristics:
File Information
- Size
- 36K
- SHA-1
- e90fa5864854f67c9b105811f46d9a294249dd11
- MD5
- 065b791431efe90944ff2074fd34e957
- CRC-32
- eacf73db
- File type
- Windows executable
- First seen
- 2011-09-04
Runtime Analysis
Copies Itself To
- c:\Documents and Settings\test user\Local Settings\Application Data\vpjmrfqr.exe
Dropped Files
- C:\sample.txt
- Size
- 6
- SHA-1
- 9d0d85cd2d7e3fe1742cd948a7c6b23d0a797513
- MD5
- e375f86b37557a771af04a6283e159b6
- CRC-32
- 3ecb94d5
- File type
- A binary file with a very small filesize (too small to be malicious)
- First seen
- 2013-01-30
Processes Created
- c:\windows\system32\notepad.exe
- c:\windows\system32\svchost.exe
IP Connections
- 173.255.203.178:8080
- 190.111.176.13:8080
- 202.153.132.24:8080
- 202.169.224.202:8080
- 217.11.63.194:8080
- 46.4.178.174:8080
- 66.232.145.174:6667
- 66.84.10.68:8080
- 77.79.81.166:8080
- 80.90.198.43:8080
- 81.93.248.152:8080
- 84.38.159.166:8080
- 85.186.22.146:8080
- 85.214.50.161:8080
- 89.19.20.202:8080
- 94.101.86.146:60000