Examples of Troj/Rimecud-DG include:
Example 1
File Information
- Size
- 107K
- SHA-1
- 018111736ae946e1e48c617d582f050590f9c9da
- MD5
- 6a4863876d56e4050d9e0bef0c5cefaf
- CRC-32
- 348db931
- File type
- Windows executable
- First seen
- 2013-01-04
Example 2
File Information
- File type
- Windows executable
Runtime Analysis
Copies Itself To
- c:\Documents and Settings\test user\celp.exe
Registry Keys Created
- HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon
- Taskman
- c:\Documents and Settings\test user\celp.exe
Processes Created
- c:\windows\system32\svchost.exe
DNS Requests
- loca.betrule.com
- mutta.agesask.net
- uokwa.agesonest.com
Example 3
File Information
- Size
- 120K
- SHA-1
- 054b6e813daae2d032ecaff58f466e7598d1e8f3
- MD5
- ed0c6245051c24d96ed52ec8eb8438ef
- CRC-32
- 3659655a
- File type
- Windows executable
- First seen
- 2012-12-28
Runtime Analysis
Copies Itself To
- c:\Documents and Settings\test user\ttubyp.exe
Registry Keys Created
- HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon
- Taskman
- c:\Documents and Settings\test user\ttubyp.exe
Processes Created
- c:\windows\system32\svchost.exe
DNS Requests
- loca.betrule.com
- mutta.agesask.net
- uokwa.agesonest.com