Troj/Weels-D exhibits the following characteristics:
File Information
- Size
- 52K
- SHA-1
- 81a122cd5a06675eb62829df2a9b8cddf6e7d1ae
- MD5
- b7b4a77f8d9812b2c07c68118df0b006
- CRC-32
- 9578cea3
- File type
- Windows executable
- First seen
- 2013-02-11
Runtime Analysis
Copies Itself To
- c:\Documents and Settings\test user\Local Settings\Application Data\ojshuirt.exe
Dropped Files
- C:\sample.txt
- Size
- 6
- SHA-1
- 9d0d85cd2d7e3fe1742cd948a7c6b23d0a797513
- MD5
- e375f86b37557a771af04a6283e159b6
- CRC-32
- 3ecb94d5
- File type
- A binary file with a very small filesize (too small to be malicious)
- First seen
- 2013-01-30
Processes Created
- c:\windows\system32\notepad.exe
- c:\windows\system32\svchost.exe
IP Connections
- 173.255.203.178:8080
- 190.111.176.13:8080
- 202.153.132.24:8080
- 202.169.224.202:8080
- 217.11.63.194:8080
- 46.4.178.174:8080
- 66.232.145.174:6667
- 66.84.10.68:8080
- 77.79.81.166:8080
- 80.90.198.43:8080
- 81.93.248.152:8080
- 84.38.159.166:8080
- 85.186.22.146:8080
- 85.214.50.161:8080
- 89.19.20.202:8080
- 94.101.86.146:60000