Troj/Mdrop-EWY exhibits the following characteristics:
File Information
- Size
- 187K
- SHA-1
- da65112645b479cdb50499b3938bd5713b64e0e0
- MD5
- 31e5e58dbdfad05175613e795298ebb5
- CRC-32
- a4973647
- File type
- Windows executable
- First seen
- 2011-11-05
Other vendor detection
- Avira
- TR/Dropper.Gen
- Kaspersky
- Trojan.Win32.Genome.xare
Runtime Analysis
Dropped Files
- c:\Documents and Settings\test user\Local Settings\Temp\svchost.exe
- Size
- 88K
- SHA-1
- 53be0518357b99231676e5ddda574fae8f899827
- MD5
- 11504971bb85cdacb8ef7d45e6e2aeb7
- CRC-32
- 938e43d9
- File type
- Windows executable
- First seen
- 2011-11-05
Registry Keys Created
- HKCU\Software\Microsoft\Windows NT\CurrentVersion\Windows
- load
- C:\DOCUME~1\support\LOCALS~1\Temp\svchost.exe
- HKCU\Software\WinRAR SFX
- C%%DOCUME~1%support%LOCALS~1%Temp
- C:\DOCUME~1\support\LOCALS~1\Temp
Processes Created
- c:\docume~1\support\locals~1\temp\svchost.exe
HTTP Requests
- http://202.39.61.136/default.html
- http://hostname.regicsgf.net/6885.asp
- http://hostname.regicsgf.net/6915.asp
- http://hostname.regicsgf.net/6934.asp
- http://hostname.regicsgf.net/6957.asp
- http://hostname.regicsgf.net/6980.asp
- http://hostname.regicsgf.net/7003.asp
- http://hostname.regicsgf.net/7026.asp
- http://hostname.regicsgf.net/7052.asp
- http://hostname.regicsgf.net/7075.asp
- http://hostname.regicsgf.net/7098.asp
- http://hostname.regicsgf.net/7150.asp
IP Connections
DNS Requests