Examples of Troj/Rimecud-DI include:
Example 1
File Information
- Size
- 73K
- SHA-1
- 00139e8c8f23454ff50d261bfaae3b5ad5032756
- MD5
- 7893fc0069358ab14d51f052ccf20576
- CRC-32
- b286a0de
- File type
- Windows executable
- First seen
- 2007-07-28
Runtime Analysis
Copies Itself To
- c:\Documents and Settings\test user\mqgka.exe
Registry Keys Created
- HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon
- Taskman
- c:\Documents and Settings\test user\mqgka.exe
Processes Created
- c:\windows\system32\svchost.exe
DNS Requests
- loca.betrule.com
- mutta.agesask.net
- uokwa.agesonest.com
Example 2
File Information
- Size
- 94K
- SHA-1
- 0058a517fb0ab2540c4de639a76acd51deab9cbf
- MD5
- 6e56c5a803a9c396475dc27dd14e490a
- CRC-32
- e3acf2c5
- File type
- Windows executable
- First seen
- 2013-02-04
Runtime Analysis
Copies Itself To
- c:\Documents and Settings\test user\yoboci.exe
Registry Keys Created
- HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon
- Taskman
- c:\Documents and Settings\test user\yoboci.exe
Processes Created
- c:\windows\system32\svchost.exe
DNS Requests
- loca.betrule.com
- mutta.agesask.net
- uokwa.agesonest.com
Example 3
File Information
- Size
- 73K
- SHA-1
- 009b35abe00013908754cc3d3c8884387d77cfcb
- MD5
- fe8e3967a2cbba2dd8a621b0e1424b75
- CRC-32
- 894609d4
- File type
- Windows executable
- First seen
- 2013-01-23
Runtime Analysis
Copies Itself To
- c:\Documents and Settings\test user\mqgka.exe
Registry Keys Created
- HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon
- Taskman
- c:\Documents and Settings\test user\mqgka.exe
Processes Created
- c:\windows\system32\svchost.exe
DNS Requests
- loca.betrule.com
- mutta.agesask.net
- uokwa.agesonest.com