Troj/Mdrop-ERL exhibits the following characteristics:
File Information
- Size
- 97K
- SHA-1
- bfeb0de4add7143291371c5e8954c9352100531d
- MD5
- 2aa3a2bb41c6bf1dccad03c144c1fd67
- CRC-32
- 5829dcde
- File type
- Windows executable
- First seen
- 2012-11-22
Runtime Analysis
Copies Itself To
- c:\Documents and Settings\test user\Application Data\WinDefender\WinDefender.Exe
Dropped Files
- c:\Documents and Settings\test user\Application Data\OykrR.vbs
- Size
- 437
- SHA-1
- e1b3b6d406867e7a3c7fa98b82683bbd14b40509
- MD5
- b86cd08bb087d7b301ed11e042b60f8f
- CRC-32
- cd08bca3
- File type
- Visual Basic Script
- First seen
- 2012-09-01
Registry Keys Created
- HKCU\Software\Microsoft\Windows\CurrentVersion\Run
- WinDefender
- "c:\Documents and Settings\test user\Application Data\WinDefender\WinDefender.Exe"
Registry Keys Modified
- HKCU\Software\Microsoft\Windows\CurrentVersion\Policies\System
- DisableTaskMgr
- 0x00000001
- HKCU\Software\Microsoft\Windows\CurrentVersion\Explorer\Advanced
- Hidden
- 0x00000002
Processes Created
- c:\windows\microsoft.net\framework\v2.0.50727\vbc.exe
- c:\windows\system32\wscript.exe
IP Connections