Troj/Mdrop-EWY

Category: Viruses and Spyware Protection available since:06 Mar 2013 07:56:47 (GMT)
Type: Trojan Last Updated:06 Mar 2013 07:56:47 (GMT)
Prevalence: Small Number of Reports

Download Download our free Virus Removal Tool - Find and remove threats your antivirus missed

Troj/Mdrop-EWY exhibits the following characteristics:

File Information

Size
187K
SHA-1
da65112645b479cdb50499b3938bd5713b64e0e0
MD5
31e5e58dbdfad05175613e795298ebb5
CRC-32
a4973647
File type
Windows executable
First seen
2011-11-05

Other vendor detection

Avira
TR/Dropper.Gen
Kaspersky
Trojan.Win32.Genome.xare

Runtime Analysis

Dropped Files
  • c:\Documents and Settings\test user\Local Settings\Temp\svchost.exe
    Size
    88K
    SHA-1
    53be0518357b99231676e5ddda574fae8f899827
    MD5
    11504971bb85cdacb8ef7d45e6e2aeb7
    CRC-32
    938e43d9
    File type
    Windows executable
    First seen
    2011-11-05
Registry Keys Created
  • HKCU\Software\Microsoft\Windows NT\CurrentVersion\Windows
    load
    C:\DOCUME~1\support\LOCALS~1\Temp\svchost.exe
  • HKCU\Software\WinRAR SFX
    C%%DOCUME~1%support%LOCALS~1%Temp
    C:\DOCUME~1\support\LOCALS~1\Temp
Processes Created
  • c:\docume~1\support\locals~1\temp\svchost.exe
HTTP Requests
  • http://202.39.61.136/default.html
  • http://hostname.regicsgf.net/6885.asp
  • http://hostname.regicsgf.net/6915.asp
  • http://hostname.regicsgf.net/6934.asp
  • http://hostname.regicsgf.net/6957.asp
  • http://hostname.regicsgf.net/6980.asp
  • http://hostname.regicsgf.net/7003.asp
  • http://hostname.regicsgf.net/7026.asp
  • http://hostname.regicsgf.net/7052.asp
  • http://hostname.regicsgf.net/7075.asp
  • http://hostname.regicsgf.net/7098.asp
  • http://hostname.regicsgf.net/7150.asp
IP Connections
  • 202.39.61.136:80
DNS Requests
  • hostname.regicsgf.net

download Try Sophos products for free
Download now