Threat Database Trojans Trojan.Downloader.FakeRean

Trojan.Downloader.FakeRean

By CagedTech in Trojans

Threat Scorecard

Threat Level: 80 % (High)
Infected Computers: 247
First Seen: November 30, 2010
OS(es) Affected: Windows

Aliases

15 security vendors flagged this file as malicious.

Antivirus Vendor Detection
AVG Crypt.YQS
Ikarus Trojan.Crypt
AhnLab-V3 Win-Trojan/Fakeav.166912.W
AntiVir TR/Agent.166400.3
Kaspersky Trojan.Win32.FraudPack.beuy
McAfee Generic.dx!tii
AVG SHeur3.ARJW
eTrust-Vet Win32/Tnega.SSE
BitDefender Trojan.Generic.KD.24776
Kaspersky Trojan.Win32.FraudPack.beqa
AVG Downloader.Generic10.JNO
Sunbelt Trojan.Win32.Generic.pak!cobra
AntiVir TR/Dldr.FakeAV.AX
BitDefender Trojan.Generic.KD.26359
Kaspersky Trojan.Win32.FraudPack.bfho

File System Details

Trojan.Downloader.FakeRean may create the following file(s):
# File Name MD5 Detections
1. Windows-Update-KB237643-x86-ENU.exe e41e357860759915fc9b352d70ac9cea 139
2. baka10.exe 8c58c1909bf8419e429b68118607073f 17
3. ~TM3CC2.tmp fecf32f92f476f06ebb6e9120715aefb 17
4. e.exe 1366649f38884a64e44c80065debe440 5
5. o.dat f5ce575dee661c7d8d648ddfce2aaaab 4
6. baka5.exe 48e6597f43f27dc7c42f79e60d0b1e06 4
7. exe.exe fe065252f32b02e2d02b5e0ff78de470 3
8. baka7.exe 23e80ffd5f952c35f7687a0d544df835 3
9. bbaka10.exe 3b85b7c46526fef8fdfc07603c89b07e 3
10. qgDs.exe 7944ab1dec13dd9c2dce8e321f3e387c 1
11. UmkK.exe 42000c480a09646f50cea37cddaebaae 1
12. 903305888175964.exe 187aeff5c35a8ee29d5a6419ce8bd4db 1
13. 360660,016536713.exe 192c323e0006e5811b5a7cb424f9a4c0 1
14. vIQm.exe a71863cea7fccaa23fca6d323681b4cb 1
15. rOgV.exe 2cb909faaf86066121b66d106a7674c9 1
16. Kias.exe e3f6a36a69f678b12cde3c3d05b3034b 1
17. msvcr71microsoft.exe d992ff836e00200b597b8d8d4b78265f 1
18. accessmicrosoft.exe a242d533df0ce40baac96f655e1c1751 1
19. quicktimeresourcesquicktimeresources .exe 576927fb443ea85f1a67d7d5a467f035 1
20. B9.tmp d7839861b6f5b6ecb02fa0f160fb1fac 1
21. bn2.tmp 8c59f0379ef8eb90d4dfe54b1ef3f6d6 1
22. pdfupd.exe 6fbeb65da9a4007b334b33d0ec6e2a60 1
23. transferarchiverlibrary.exe 9645911cf682943f8a72bc012315078c 1
24. ~TM31.tmp 5be4b708a68687cb5490fe2caea49c82 1
25. 0.4963503726991707.exe 49baecd50f9bdcc36ea350956922415f 1
26. googlefrissts.exe 6e18acf50078c7606777a5383c526d27 1
More files

Analysis Report

General information

Family Name: Rogue.FakeRean
Signature status: No Signature

Known Samples

MD5: 0604af7c52911b648819277aa11e2872
SHA1: 38b24c6e11a0e5a8d9dc7ef4dead9399d96543e7
SHA256: B599512AF4A79C574D397B1F3AD319B5912FD86C00F3C57A2224EA6D540FD11F
File Size: 393.22 KB, 393216 bytes
MD5: e3cb47ea02d2ff4cec014a3e4be1004e
SHA1: f240b4ed11c4a0e44876ce1185ddfebf7e5df0f2
SHA256: A41A998C482BA943BDCBE019AD9115C0D4BBA64D25CEF19B5377F99A437C2072
File Size: 2.79 MB, 2786304 bytes
MD5: 7684c3746b315e2ba8768771f8c88a0d
SHA1: b558fd80a32aef34ad0d1f408bf9afca62016651
SHA256: 12A24B74AF1C7C3F73382B10EC08C1FB10A4ABFF049E9DB425EDFE47A295FB15
File Size: 1.82 MB, 1818624 bytes

Windows Portable Executable Attributes

  • File doesn't have "Rich" header
  • File doesn't have debug information
  • File doesn't have exports table
  • File doesn't have relocations information
  • File doesn't have security information
  • File has TLS information
  • File is .NET application
  • File is 32-bit executable
  • File is either console or GUI application
  • File is GUI application (IMAGE_SUBSYSTEM_WINDOWS_GUI)
Show More
  • File is Native application (NOT .NET application)
  • File is not packed
  • IMAGE_FILE_DLL is not set inside PE header (Executable)
  • IMAGE_FILE_EXECUTABLE_IMAGE is set inside PE header (Executable Image)

File Icons

Windows PE Version Information

Name Value
Assembly Version 1.0.0.0
Comments MBM Converter
Company Name
  • Cequenze Technology Inc.
  • Luxtron
File Description
  • EasyMaker
  • MBM Converter Application
File Version
  • 1.00
  • 1.0.0.29
  • 1.0.0.0
Internal Name
  • EasyMaker.exe
  • MBMConverter
Legal Copyright Copyright © Luxtron 2010
Legal Trademarks Cequenze Technoloy Inc.
Original Filename
  • EasyMaker.exe
  • MBMConverter.exe
Product Name
  • EasyMaker
  • MBMConverter.exe
Product Version
  • 1.00
  • 1.0.0.0

File Traits

  • .NET
  • vb6
  • x86

Files Modified

File Attributes
c:\windows\appcompat\programs\amcache.hve Read Data,Read Control,Write Data
c:\windows\appcompat\programs\amcache.hve Write Attributes

Windows API Usage

Category API
Syscall Use
  • ntdll.dll!NtAccessCheck
  • ntdll.dll!NtAdjustPrivilegesToken
  • ntdll.dll!NtAlertThreadByThreadId
  • ntdll.dll!NtAlpcConnectPort
  • ntdll.dll!NtAlpcSendWaitReceivePort
  • ntdll.dll!NtApphelpCacheControl
  • ntdll.dll!NtAssociateWaitCompletionPacket
  • ntdll.dll!NtClearEvent
  • ntdll.dll!NtClose
  • ntdll.dll!NtConnectPort
Show More
  • ntdll.dll!NtCreateEvent
  • ntdll.dll!NtCreateFile
  • ntdll.dll!NtCreateIoCompletion
  • ntdll.dll!NtCreateKey
  • ntdll.dll!NtCreateMutant
  • ntdll.dll!NtCreateSection
  • ntdll.dll!NtCreateSemaphore
  • ntdll.dll!NtCreateTimer2
  • ntdll.dll!NtCreateWaitCompletionPacket
  • ntdll.dll!NtCreateWorkerFactory
  • ntdll.dll!NtDelayExecution
  • ntdll.dll!NtDeleteValueKey
  • ntdll.dll!NtDeviceIoControlFile
  • ntdll.dll!NtDuplicateObject
  • ntdll.dll!NtDuplicateToken
  • ntdll.dll!NtEnumerateKey
  • ntdll.dll!NtEnumerateValueKey
  • ntdll.dll!NtFreeVirtualMemory
  • ntdll.dll!NtFsControlFile
  • ntdll.dll!NtLoadKeyEx
  • ntdll.dll!NtMapViewOfSection
  • ntdll.dll!NtNotifyChangeKey
  • ntdll.dll!NtOpenDirectoryObject
  • ntdll.dll!NtOpenEvent
  • ntdll.dll!NtOpenFile
  • ntdll.dll!NtOpenKey
  • ntdll.dll!NtOpenKeyEx
  • ntdll.dll!NtOpenProcessToken
  • ntdll.dll!NtOpenProcessTokenEx
  • ntdll.dll!NtOpenSection
  • ntdll.dll!NtOpenSemaphore
  • ntdll.dll!NtOpenSymbolicLinkObject
  • ntdll.dll!NtOpenThread
  • ntdll.dll!NtOpenThreadToken
  • ntdll.dll!NtOpenThreadTokenEx
  • ntdll.dll!NtProtectVirtualMemory
  • ntdll.dll!NtQueryAttributesFile
  • ntdll.dll!NtQueryDefaultLocale
  • ntdll.dll!NtQueryDirectoryFileEx
  • ntdll.dll!NtQueryFullAttributesFile
  • ntdll.dll!NtQueryInformationFile
  • ntdll.dll!NtQueryInformationProcess
  • ntdll.dll!NtQueryInformationThread
  • ntdll.dll!NtQueryInformationToken
  • ntdll.dll!NtQueryKey
  • ntdll.dll!NtQueryLicenseValue
  • ntdll.dll!NtQueryPerformanceCounter
  • ntdll.dll!NtQuerySecurityAttributesToken
  • ntdll.dll!NtQuerySecurityObject
  • ntdll.dll!NtQuerySymbolicLinkObject
  • ntdll.dll!NtQuerySystemInformation
  • ntdll.dll!NtQuerySystemInformationEx
  • ntdll.dll!NtQueryValueKey
  • ntdll.dll!NtQueryVirtualMemory
  • ntdll.dll!NtQueryVolumeInformationFile
  • ntdll.dll!NtQueryWnfStateData
  • ntdll.dll!NtReadVirtualMemory
  • ntdll.dll!NtReleaseMutant
  • ntdll.dll!NtReleaseSemaphore
  • ntdll.dll!NtReleaseWorkerFactoryWorker
  • ntdll.dll!NtRequestWaitReplyPort
  • ntdll.dll!NtSetEvent
  • ntdll.dll!NtSetInformationKey
  • ntdll.dll!NtSetInformationProcess
  • ntdll.dll!NtSetInformationThread
  • ntdll.dll!NtSetInformationVirtualMemory
  • ntdll.dll!NtSetInformationWorkerFactory
  • ntdll.dll!NtSubscribeWnfStateChange
  • ntdll.dll!NtTestAlert
  • ntdll.dll!NtTraceControl
  • ntdll.dll!NtTraceEvent
  • ntdll.dll!NtUnmapViewOfSection
  • ntdll.dll!NtUnmapViewOfSectionEx
  • ntdll.dll!NtWaitForSingleObject
  • ntdll.dll!NtWaitForWorkViaWorkerFactory
  • ntdll.dll!NtWaitLowEventPair
  • ntdll.dll!NtWorkerFactoryWorkerReady
  • ntdll.dll!NtWriteFile
  • UNKNOWN
User Data Access
  • GetUserObjectInformation
Anti Debug
  • IsDebuggerPresent
Process Shell Execute
  • CreateProcess
Encryption Used
  • BCryptOpenAlgorithmProvider
Process Manipulation Evasion
  • ReadProcessMemory
Other Suspicious
  • SetWindowsHookEx

Shell Command Execution

C:\Windows\Microsoft.NET\Framework64\v2.0.50727\\dw20.exe dw20.exe -x -s 824

Related Posts

Trending

Most Viewed

Loading...