SonicALERT
Search

Sonicwall Signatures

 

Go to All Categories list.


  Virut.A_1191
Virut.A_1191 is a polymorphic file infector virus that target Microsoft Windows operating systems. It is known to infect files with .exe and .scr extensions on local drives, removable media, and network shares.

Mutexes created
  • Nothing to report


Directory level activity
    • Nothing to report


    File level activity
      • Nothing to report


      Registry level activity
      • write - registry - HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\stmwcysyycDescription


      Library level activity
      • load - library - SHELL32.dll
      • load - library - C:\DOCUME~1\TestMachine\LOCALS~1\Temp\3610b50776c92c2671d95585f33c752a.bin.dll
      • load - library - C:\WINDOWS\system32\uxtheme.dll
      • load - library - uxtheme.dll
      • load - library - NTDLL
      • load - library - KERNEL32.DLL
      • load - library - MFC42.DLL
      • load - library - MSVCRT.dll
      • load - library - ADVAPI32.dll
      • load - library - kernel32.dll
      • load - library - USER32.dll
      • load - library - mscoree.dll


      Process API calls used
      • NtCreateSection
      • ZwMapViewOfSection
      • ZwMapViewOfSection


      Registry API calls used
        • Nothing to report


        System API calls used
        • LdrLoadDll
        • LdrGetProcedureAddress
        • IsDebuggerPresent
        • LdrGetProcedureAddress


        Filesystem API calls used
        • NtOpenFile
        • FindFirstFileExW
        • NtQueryDirectoryFile
        • CopyFileA
        • NtSetInformationFile
        • NtQueryDirectoryFile

        Network

        UDP source >> destination
        • 192.168.30.9 >> 192.168.30.254
        • 192.168.30.9 >> 192.168.30.255
        • 192.168.30.9 >> 8.8.8.8


        TCP source >> destination



          Domains:
          • www.mieshabb.com with IP - 23.253.126.58

          DNS Request:
          • www.mieshabb.com

          HTTP Request:
          • NA

          DLL related data
          Number of DLL's imported = 1
          • KERNEL32.dll


          Relevant Information