Research Notes for bd618f92139641ac7a2800c9f895a2ce

Summary

Notes

2010-01-23

Executed on WinXPHomeSP2 running in VMware Server 1.0.0 build 28343. Installed an agent that started massive communications with a multitude of hosts on the Internet, primarily over port 80 but seeming to use encrypted channels.

Executed on Win2KSP0 running in VMware ESX Server 110271, OS complains that the file “is not a valid Win32 application”.

Links

 
techdocs/security/malware/9d64e6a0dc6a3353770916d53350c2ac.txt · Last modified: 2010/01/23 14:58 by earnoth
 
Recent changes RSS feed Creative Commons License Donate Powered by PHP Valid XHTML 1.0 Valid CSS Driven by DokuWiki