Troj/Ransom-MO

Category: Viruses and Spyware Protection available since:19 Jan 2013 22:57:10 (GMT)
Type: Trojan Last Updated:19 Jan 2013 22:57:10 (GMT)
Prevalence: Small Number of Reports

Download Download our free Virus Removal Tool - Find and remove threats your antivirus missed

Troj/Ransom-MO exhibits the following characteristics:

File Information

Size
62K
SHA-1
f63e483d72b2a1e155e01bf05945b72cdafe6fd7
MD5
b7dff60470315bd590f4711988f32a24
CRC-32
20c3e86e
File type
Windows executable
First seen
2013-01-19

Runtime Analysis

Copies Itself To
  • c:\Documents and Settings\test user\Application Data\skype.dat
Dropped Files
  • c:\Documents and Settings\test user\Application Data\skype.ini
    Size
    4
    SHA-1
    02695ffd17a8b24609c680bb85b10ec299f2a6f9
    MD5
    617ae86b3f4dd8090c44beffc86d5df5
    CRC-32
    3ae67d20
    File type
    A binary file with a very small filesize (too small to be malicious)
    First seen
    2012-08-07
Registry Keys Modified
  • HKCU\Software\Microsoft\Windows NT\CurrentVersion\Winlogon
    Shell
    explorer.exe,c:\Documents and Settings\test user\Application Data\skype.dat
Processes Created
  • c:\windows\system32\svchost.exe
HTTP Requests
  • http://ckza.ru/pl-jvzv-yxpa-jheluqorjkwpmplihj_qtpt_lahjcn-eazr-qpzvzrcgvpjpfmuuitppgjhjgxcosyltpbsdyjzhrd-.php
  • http://efdp.su/nd-gkjkppphacuyqc-bwac-qcxs_opspdw-vqlg-cdmpqsfrrpsdstpvvkkkrqjtcetfqudurannygiicnkfyqvtzv-.php
DNS Requests
  • ckza.ru
  • efdp.su

download Try Sophos products for free
Download now