Troj/Ransom-MO exhibits the following characteristics:
File Information
- Size
- 62K
- SHA-1
- f63e483d72b2a1e155e01bf05945b72cdafe6fd7
- MD5
- b7dff60470315bd590f4711988f32a24
- CRC-32
- 20c3e86e
- File type
- Windows executable
- First seen
- 2013-01-19
Runtime Analysis
Copies Itself To
- c:\Documents and Settings\test user\Application Data\skype.dat
Dropped Files
- c:\Documents and Settings\test user\Application Data\skype.ini
- Size
- 4
- SHA-1
- 02695ffd17a8b24609c680bb85b10ec299f2a6f9
- MD5
- 617ae86b3f4dd8090c44beffc86d5df5
- CRC-32
- 3ae67d20
- File type
- A binary file with a very small filesize (too small to be malicious)
- First seen
- 2012-08-07
Registry Keys Modified
- HKCU\Software\Microsoft\Windows NT\CurrentVersion\Winlogon
- Shell
- explorer.exe,c:\Documents and Settings\test user\Application Data\skype.dat
Processes Created
- c:\windows\system32\svchost.exe
HTTP Requests
- http://ckza.ru/pl-jvzv-yxpa-jheluqorjkwpmplihj_qtpt_lahjcn-eazr-qpzvzrcgvpjpfmuuitppgjhjgxcosyltpbsdyjzhrd-.php
- http://efdp.su/nd-gkjkppphacuyqc-bwac-qcxs_opspdw-vqlg-cdmpqsfrrpsdstpvvkkkrqjtcetfqudurannygiicnkfyqvtzv-.php
DNS Requests