DarkMegi rootkit - sample (distributed via Blackhole)
Common Information
Type Value
UUID 5e0e4fce-3a48-4b7c-a3d7-7feddd4f7416
Fingerprint a81a617c16fb0c89
Analysis status DONE
Considered CTI value 2
Text language
Published April 18, 2012, 9:57 p.m.
Added to db Sept. 26, 2022, 9:30 a.m.
Last updated Nov. 17, 2024, 10:40 p.m.
Headline UNKNOWN
Title DarkMegi rootkit - sample (distributed via Blackhole)
Detected Hints/Tags/Attributes 32/2/35
Attributes
Details Type #Events CTI Value
Details Domain 30
www.msn.com
Details Domain 52
msn.com
Details Domain 1
w32.agent.77312.vc
Details File 1
c:\windows\system32\drivers\com32.sys
Details File 1
c:\windows\system32\drivers\rcx50e3.tmp
Details File 1
c:\windows\system32\rcx5b11.tmp
Details File 1
c:\windows\system32\del043.bat
Details File 3
c.gif
Details File 1
2fdefaultwpe3w.aspx
Details File 1
dec3f3d671e6cc76b09340612a38.jpg
Details File 1
defaultwpe3w.aspx
Details File 1
4b835e56ac3c8535db16275b4baf4.jpg
Details File 1
756a1c963a72e4afbc36501b512725.jpg
Details File 1
f757c6dff15796123fa81cf7dccf.jpg
Details File 2
qsonhs.aspx
Details File 1
440.swf
Details File 1
175.jpg
Details md5 1
6C8F9658A390C24A9F4551DC15063927
Details md5 1
4399b8a60977814197feae67c02a7ac2
Details md5 1
9f32c51764f579512810b7ab3de1a91a
Details md5 1
dd313b92f60bb66d3d613bc49c1ef35e
Details md5 1
25cfb72df8a30cbb7e6ee852bc31c50f
Details md5 1
2f00e0927c07bc44d9b79ccbe567f398
Details md5 1
1a1e7855edc0afa6624080d60da8bf44
Details md5 1
4571d83250544049bfc2ee88060f6bc8
Details md5 1
23A3C63D37E16EEA2397C50633E16E45
Details md5 1
6c8f9658a390c24a9f4551dc15063927
Details sha1 1
c1af1fa6937097762824d0db039777ff35577727
Details sha256 1
a2c176ef3cc343194207e33acc19d5f8cb083a3c387a0404bd8f9d6bd29cfd6f
Details IPv4 1
65.55.253.27
Details IPv4 1
192.168.254.192
Details IPv4 1
207.46.193.176
Details IPv4 1
65.55.239.146
Details Url 6
http://www.msn.com
Details Url 1
http://www.msn.com/defaultwpe3w.aspx