Troj/Ransom-MN exhibits the following characteristics:
File Information
- Size
- 49K
- SHA-1
- c420f667984c41370e34dfe97d46335fe7dac414
- MD5
- ff4979e644dd8106bbd5116897ea8991
- CRC-32
- 9e4590ef
- File type
- Windows executable
- First seen
- 2013-01-19
Runtime Analysis
Copies Itself To
- c:\Documents and Settings\test user\Zzppllmmq\ttlleepbvmu.exe
Registry Keys Created
- HKCU\Software\Microsoft\Windows\CurrentVersion\Run
- vjkubvmu
- c:\Documents and Settings\test user\Zzppllmmq\ttlleepbvmu.exe
Processes Created
- c:\docume~1\support\locals~1\temp\dbbjjpkkee.pre
- c:\windows\system32\ctfmon.exe
- c:\windows\system32\svchost.exe
HTTP Requests
- http://namelesscorn.net/UTP402HEAD.php
DNS Requests