Virus Characteristics
| File Property | Property Value |
| FileName | !itw#812.exe |
| McAfee Artemis | Artemis!96b6ccef5e6c
|
| McAfee Detection | Generic PWS.ak |
| Length | 173,843 bytes |
| CRC | F626488B |
| MD5 | 96B6CCEF5E6C4095239AA638B1D7EF12
|
| SHA1 | 2363C6A429F62AB6B31BEA416B9AEEE49F1CB1B6
|
Other Common Detection Aliases
| Company Name | Detection Name |
| ahnlab | Win-Trojan/OnlineGameHack.173843
|
| avast | Win32:Kamso [Trj] |
| AVG (GriSoft) | SHeur2.BBPC |
| Avira | TR/Crypt.ZPACK.Gen |
| BitDefender | Worm.Generic.88956 |
| eSafe (Alladin) | Suspicious File [100]
|
| Eset | a variant of Win32/Pacex.Gen
|
| FortiNet | W32/Magania.S!tr |
| Kaspersky | Trojan-GameThief.Win32.Magania.cair
|
| microsoft | worm:win32/taterf.b |
| norman | w32/malware.dam |
| panda | Generic Worm |
| rising | Packer.Win32.Nodef.c
|
| Sophos | Mal/Generic-A |
| Symantec | W32.Gammima |
| Trend Micro | WORM_ONLINEG.AAS |
| V-Buster | Trojan.PWS.Magania.TAF
|
Avert® Labs has observed the following system activities:
| Activity | Risk Level |
Modifies memory of other processes
| Critical |
Enumerates running processes
| Medium |
Uses shared memory of other processes
| Low |
Writes executable in the windows folder
| Low |
Creates registry keys and data values to persist on OS reboot
| Informational |
| Registers DLLs | Informational |
Other detections that have been observed.
| FileName | McAfee Supported |
%WINDIR%\system32\bigmn0.dll
| Generic PWS.y!xg |
%WINDIR%\system32\bigie0.dll
| Generic PWS.ak |
%WINDIR%\system32\bigdoor.exe
| Generic PWS.ak |
System Changes
These are general defaults for typical path variables. (Although they may differ, these examples are common.):
%WinDir% = \WINDOWS (Windows 9x/ME/XP/Vista), \WINNT (Windows NT/2000)
%SystemDir% = \WINDOWS\SYSTEM (Windows 98/ME), \WINDOWS\SYSTEM32 (Windows XP/Vista), \WINNT\SYSTEM32 (Windows NT/2000)
%ProgramFiles% = \Program Files
The following files were analyzed:
%USERPROFILE%\local settings\temp\!itw#812.exe
The following files have been added to the system:
%WINDIR%\system32\bigdoor.exe%WINDIR%\system32\bigie0.dll%WINDIR%\system32\bigmn0.dll
The following registry elements have been created:
HKEY_LOCAL_MACHINE\software\classes\clsid\{238c32ab-955d-4707-aab9-c9b3ab8d4225}\- (default) = iehlprobj class
HKEY_LOCAL_MACHINE\software\classes\clsid\{238c32ab-955d-4707-aab9-c9b3ab8d4225}\inprocserver32\- (default) = c:\windows\system32\bigmn0.dll
- threadingmodel = apartment
HKEY_LOCAL_MACHINE\software\classes\clsid\{238c32ab-955d-4707-aab9-c9b3ab8d4225}\progid\- (default) = iehlprobj.iehlprobj.1
HKEY_LOCAL_MACHINE\software\classes\clsid\{238c32ab-955d-4707-aab9-c9b3ab8d4225}\versionindependentprogid\- (default) = iehlprobj.iehlprobj
HKEY_LOCAL_MACHINE\software\classes\iehlprobj.iehlprobj.1\- (default) = iehlprobj class
HKEY_LOCAL_MACHINE\software\classes\iehlprobj.iehlprobj.1\clsid\- (default) = {238c32ab-955d-4707-aab9-c9b3ab8d4225}
HKEY_LOCAL_MACHINE\software\classes\iehlprobj.iehlprobj\- (default) = iehlprobj class
HKEY_LOCAL_MACHINE\software\classes\iehlprobj.iehlprobj\curver\- (default) = iehlprobj.iehlprobj.1
HKEY_LOCAL_MACHINE\software\classes\interface\{238c32ac-955d-4707-aab9-c9b3ab8d4225}\HKEY_LOCAL_MACHINE\software\classes\interface\{238c32ac-955d-4707-aab9-c9b3ab8d4225}\proxystubclsid\- (default) = {00020424-0000-0000-c000-000000000046}
HKEY_LOCAL_MACHINE\software\classes\interface\{238c32ac-955d-4707-aab9-c9b3ab8d4225}\proxystubclsid32\- (default) = {00020424-0000-0000-c000-000000000046}
HKEY_LOCAL_MACHINE\software\classes\interface\{238c32ac-955d-4707-aab9-c9b3ab8d4225}\typelib\- (default) = {238c32a2-955d-4707-aab9-c9b3ab8d4225}
- version = 3157553
HKEY_LOCAL_MACHINE\software\classes\typelib\{238c32a2-955d-4707-aab9-c9b3ab8d4225}\1.0\- (default) = iehelper 1.0 type library
HKEY_LOCAL_MACHINE\software\classes\typelib\{238c32a2-955d-4707-aab9-c9b3ab8d4225}\1.0\0\win32\- (default) = c:\windows\system32\bigmn0.dll
HKEY_LOCAL_MACHINE\software\classes\typelib\{238c32a2-955d-4707-aab9-c9b3ab8d4225}\1.0\flags\HKEY_LOCAL_MACHINE\software\classes\typelib\{238c32a2-955d-4707-aab9-c9b3ab8d4225}\1.0\helpdir\- (default) = c:\windows\system32\
The following registry elements have been changed:
HKEY_CURRENT_USER\Software\Microsoft\Windows\currentversion\explorer\advanced\- hidden = 2
- showsuperhidden = 0
HKEY_CURRENT_USER\Software\Microsoft\Windows\currentversion\policies\explorer\HKEY_CURRENT_USER\Software\Microsoft\Windows\currentversion\run\- bigsoft = c:\windows\system32\bigdoor.exe
HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\currentversion\explorer\advanced\folder\hidden\showall\
The applications created the following network connection(s):
http- hxxp://172.16.199.200/1hg/********