Troj/Weels-D

Category: Viruses and Spyware Protection available since:11 Feb 2013 07:47:39 (GMT)
Type: Trojan Last Updated:11 Feb 2013 07:47:39 (GMT)
Prevalence: Small Number of Reports

Download Download our free Virus Removal Tool - Find and remove threats your antivirus missed

Troj/Weels-D exhibits the following characteristics:

File Information

Size
52K
SHA-1
81a122cd5a06675eb62829df2a9b8cddf6e7d1ae
MD5
b7b4a77f8d9812b2c07c68118df0b006
CRC-32
9578cea3
File type
Windows executable
First seen
2013-02-11

Runtime Analysis

Copies Itself To
  • c:\Documents and Settings\test user\Local Settings\Application Data\ojshuirt.exe
Dropped Files
  • C:\sample.txt
    Size
    6
    SHA-1
    9d0d85cd2d7e3fe1742cd948a7c6b23d0a797513
    MD5
    e375f86b37557a771af04a6283e159b6
    CRC-32
    3ecb94d5
    File type
    A binary file with a very small filesize (too small to be malicious)
    First seen
    2013-01-30
Processes Created
  • c:\windows\system32\notepad.exe
  • c:\windows\system32\svchost.exe
IP Connections
  • 173.255.203.178:8080
  • 190.111.176.13:8080
  • 202.153.132.24:8080
  • 202.169.224.202:8080
  • 217.11.63.194:8080
  • 46.4.178.174:8080
  • 66.232.145.174:6667
  • 66.84.10.68:8080
  • 77.79.81.166:8080
  • 80.90.198.43:8080
  • 81.93.248.152:8080
  • 84.38.159.166:8080
  • 85.186.22.146:8080
  • 85.214.50.161:8080
  • 89.19.20.202:8080
  • 94.101.86.146:60000

download Try Sophos products for free
Download now