Troj/Reveton-BD exhibits the following characteristics:
File Information
- Size
- 258K
- SHA-1
- 13ceb4f0a0888cd9038a52d3b844d52b28d7c4c9
- MD5
- 13c5c4a0dc53db49941595c9b67894c2
- CRC-32
- 880da428
- File type
- Windows executable
- First seen
- 2007-07-11
Runtime Analysis
Dropped Files
- c:\Documents and Settings\test user\Start Menu\Programs\Startup\runctf.lnk
- Size
- 740
- SHA-1
- c4564dd71ad3f41939a866b33d004cc4d5321d01
- MD5
- 569118d0de14ba5cc5c280e21128a20d
- CRC-32
- c48e7f73
- File type
- Windows Shortcut file (.LNK)
- First seen
- 2012-12-11
- C:\Documents and Settings\All Users\Application Data\elpmas.pad
- Size
- 91M
- SHA-1
- c658996a0abfae36a445dbe8129591f09aede1af
- MD5
- 6dba20383fe7f4992ef7b4198c79d952
- CRC-32
- 57e44a83
- File type
- Unspecified binary - probably data
- First seen
- 2012-12-11
Registry Keys Created
- HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings\Zones\0
- 2500
- 0x00000003
- HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings\Zones\4
- 2500
- 0x00000003
- HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings\Zones\1
- 2500
- 0x00000003
- HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings\Zones\2
- 2500
- 0x00000003
- HKCU\Software\Microsoft\Internet Explorer\Main
- NoProtectedModeBanner
- 0x00000001
- HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings\Zones\3
- 2500
- 0x00000003
Registry Keys Modified
- HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings\Zones\4
- 1609
- 0x00000000
- HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings\Zones\0
- 1609
- 0x00000000
- HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings\Zones\1
- 1609
- 0x00000000
- HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings\Zones\2
- 1609
- 0x00000000
IP Connections