|
vitamin bombe v.1 (Undetected)
Malicious Trojan
Sends stolen data to
Quote:
Host Name IP Address
l6y.no-ip.info 173.32.229.23
Outgoing connection to remote server: l6y.no-ip.info TCP port 3174
|
Code:
• Windows Api Calls
PId Image Name Address Function ( Parameters ) | Return Value
0x724 C:\TEST\sample.exe 0x114aacd5 CopyFileA(lpExistingFileName: "C:\TEST\sample.exe", lpNewFileName: "C:\Documents and Settings\User\Application Data\Microsoft\svchost.exe", bFailIfExists: 0x0)|0x1
0x378 C:\DOCUME~1\User\LOCALS~1\Temp\server.exe 0x114aacd5 CopyFileA(lpExistingFileName: "C:\DOCUME~1\User\LOCALS~1\Temp\server.exe", lpNewFileName: "C:\Documents and Settings\User\Application Data\Microsoft\svchost.exe", bFailIfExists: 0x0)|0x1
• DNS Queries
DNS Query Text
l6y.no-ip.info IN A +
__________________
If I was helpful, Please +Rep Then Thank me!
Last edited by CampStaff; 11-13-2009 at 02:54 PM.
|