Troj/Medfos-BH exhibits the following characteristics:
File Information
- Size
- 161K
- SHA-1
- c78300cc569a5f48f9f92034d42097e3535218d5
- MD5
- 34614d47031ae601e4efe445c4c4d971
- CRC-32
- bbf648f0
- File type
- Windows executable
- First seen
- 2012-11-17
Runtime Analysis
Dropped Files
- c:\Documents and Settings\test user\Application Data\npalmg.dll
- Size
- 161K
- SHA-1
- d00380a57cbea7121163e72bce63a944623bb570
- MD5
- 0129ff1b2d1693d19317b979c4fadc29
- CRC-32
- 24fb06b6
- File type
- Windows executable
- First seen
- 2012-11-18
Registry Keys Created
- HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Run
- npalmg
- rundll32.exe "c:\Documents and Settings\test user\Application Data\npalmg.dll",FInitializeRichEdit
Processes Created
- c:\windows\system32\rundll32.exe
HTTP Requests
- http://megaupload.com/upload/fid=BwCRAAEAhg8CAAEFCAAAAAAAAAAAAAAAAAAAAABnDAsPCwAAAKHze-niEWIwrLhxgiZvmW-__aZQAABVVVVVVVVVVVVVVVVVVVVVJcXNAWBrLS-GDwIAdHdzdHR4dX5zZwUGAQIDBAUGAQITkSInGkWqQwAAAAAAAQcAAAAHAAAANFYA
IP Connections
DNS Requests
- 11un9m1.cdn103.uploadetchosting.com