Troj/DwnLdr-KOK

Category: Viruses and Spyware Protection available since:07 Feb 2013 13:13:39 (GMT)
Type: Trojan Last Updated:07 Feb 2013 13:13:39 (GMT)
Prevalence: Small Number of Reports

Download Download our free Virus Removal Tool - Find and remove threats your antivirus missed

Troj/DwnLdr-KOK exhibits the following characteristics:

File Information

Size
36K
SHA-1
e90fa5864854f67c9b105811f46d9a294249dd11
MD5
065b791431efe90944ff2074fd34e957
CRC-32
eacf73db
File type
Windows executable
First seen
2011-09-04

Runtime Analysis

Copies Itself To
  • c:\Documents and Settings\test user\Local Settings\Application Data\vpjmrfqr.exe
Dropped Files
  • C:\sample.txt
    Size
    6
    SHA-1
    9d0d85cd2d7e3fe1742cd948a7c6b23d0a797513
    MD5
    e375f86b37557a771af04a6283e159b6
    CRC-32
    3ecb94d5
    File type
    A binary file with a very small filesize (too small to be malicious)
    First seen
    2013-01-30
Processes Created
  • c:\windows\system32\notepad.exe
  • c:\windows\system32\svchost.exe
IP Connections
  • 173.255.203.178:8080
  • 190.111.176.13:8080
  • 202.153.132.24:8080
  • 202.169.224.202:8080
  • 217.11.63.194:8080
  • 46.4.178.174:8080
  • 66.232.145.174:6667
  • 66.84.10.68:8080
  • 77.79.81.166:8080
  • 80.90.198.43:8080
  • 81.93.248.152:8080
  • 84.38.159.166:8080
  • 85.186.22.146:8080
  • 85.214.50.161:8080
  • 89.19.20.202:8080
  • 94.101.86.146:60000

download Try Sophos products for free
Download now