CastleCops, Internet Crime Fighters
Need help? Click here to register for free! Absolutely zero advertisements on this site!

Donation/Premium
spacer
block bottom
Security Central
spacer
· Home
· PIRT/Fried Phish
· MIRT
· SIRT
· Deutsch
· Wiki
· Newsletter
· O16/ActiveX
· CLSID List
· Contest2007
· Downloads
· Feedback (send)
· Forums
· HijackThis
· Hijacktrend
· LSPs
· My Downloads
· O18
· O20
· O21
· O22
· O23
· O9
· Premium
· Private Messages
· Proxomitron
· Reviews
· Search
· StartupList
· Stories Archive
· Submit News
· WsIRT
· Your Account
· Acceptable Use Policy
block bottom
spacer spacer

MIRT(TM)

Malware Incident Reporting and Termination(TM) Squad

A global malware termination operation launched by CastleCops, the volunteer MIRT Squad is comprised of folks who report malware, investigate malware, and actively work on malware takedown and termination. MIRT is funded by CastleCops. Become a MIRT Squad terminator by reporting malware today!

[ How-To / FAQ ]

MIRT -> Confirmed Malware | Terminated Malware


status: confirmed malware

HTTP Response
19 Nov, 2008
01:56:11
HTTP/1.1 404 Not Found
ID7276 (termination link)
TitleTrojan-Dropper
Entry
MIRT Squad
Reporter
0
Timestamp07 Jan, 2008 @ 01:49:58
Topic ID213261 - Read/respond to MIRT commentary.
Handler Note:
19 Jan, 2008
07:22:55
tacktick: setup.exe at this location is malware known as Trojan-Dropper.Win32.Delf.anc (Kaspersky)

Scanning report:
Antivirus;Version;Last Update;Result
AhnLab-V3;2008.1.19.10;2008.01.18;Dropper/Xema.99413
AntiVir;7.6.0.48;2008.01.18;DR/Delphi.Gen
Avast;4.7.1098.0;2008.01.18;Win32:Inject-FD
CAT-QuickHeal;9.00;2008.01.19;TrojanDropper.Delf.ami
ClamAV;0.91.2;2008.01.18;Trojan.QQPass-66
DrWeb;4.44.0.09170;2008.01.18;BackDoor.Citadel
F-Prot;4.4.2.54;2008.01.19;W32/Trojan2.SXC
F-Secure;6.70.13260.0;2008.01.18;Trojan-Dropper.Win32.Delf.anc
Ikarus;T3.1.1.20;2008.01.19;Backdoor.Win32.GrayBird.lc
Kaspersky;7.0.0.125;2008.01.19;Trojan-Dropper.Win32.Delf.anc
Microsoft;1.3109;2008.01.18;TrojanDropper:Win32/Temcry
Norman;5.80.02;2008.01.18;W32/Suspicious_N.gen.dropper
Panda;9.0.0.4;2008.01.18;Suspicious file
Sophos;4.24.0;2008.01.19;Mal/Generic-A
TheHacker;6.2.9.191;2008.01.18;Trojan/Dropper.Delf.ami
VBA32;3.12.2.5;2008.01.15;Trojan.Win32.Inject.oi
Webwasher-Gateway;6.6.2;2008.01.18;Trojan.Dropper.Delphi.Gen

Additional information
File size: 99413 bytes
MD5: 0cfe1dabe62d76ba938848e84839037f
SHA1: d4ce0c439a39065ba18216be62c1744ab638967e
PEiD: BobSoft Mini Delphi -> BoB / BobSoft
packers: embedded
Handler Note:
19 Jan, 2008
07:24:17
tacktick: View CIDR AS4134 Report: http://www.cidr-report.org/cgi-bin/as-report?as=4134

"4134 | CN | apnic | 2002-08-01 | CHINANET-BACKBONE No.31,Jin-rong Street"

Handler Note:
19 Jan, 2008
07:24:17
tacktick: Extended information for AS4134:
State/Province:
Country: cn
Responsible Domain: chinanet.cn.net
Abuse Email: cncert@cert.org.cn
Handler Note:
19 Jan, 2008
07:28:26
tacktick: Generated and sent email malware alert to respective parties.

Report for at 07 Jan, 2008 @ 02:16:34


fetched page

at 07 Jan, 2008 @ 02:16:41
MD5 Fingerprint: 99bb904cacb29adee16a7ee542428afc
SHA1 Fingerprint: 7e3798430298e6978c08f9d4f231c40af1fa2a48
Version 1.0
spacer spacer