Associated Malware Groups
The unsafe files using this name are associated with the malware groups:
- System Back Door
- Cloaked Malware
File Behavior
123.EXE has been seen to perform the following behavior:
- Adds a Registry Key (RUN) to auto start Programs on system start up
- Adds a Registry Key (RUNONCE) to auto start Programs on system start up
- The Process is packed and/or encrypted using a software packing process
- Executes Processes stored in Temporary Folders
- Writes to another Process's Virtual Memory (Process Hijacking)
- Can communicate with other computer systems using HTTP protocols
- Hooks the WININET.DLL function allowing it to read or copy Http and Https web page content and session information
- Executes a Process
- This process creates other processes on disk
- Injects code into other processes
- Performs DNS look ups to resolve URL IP addresses
- Creates new folders on the system
- Creates system tray popups, messages, errors and security warnings
- The Process is polymorphic and can change its structure
- Adds new menu items in the Internet Explorer Right Click menu
- Changes the Internet Explorer Search Page
- Creates a Toolbar Extension for Internet Explorer
- Creation and Registers a Browser Helper Object in Internet Explorer
- Changes to the file command map within the registry
123.EXE has been the subject of the following behavior:
- Added as a Registry auto start to load Program on Boot up
- Created as a process on disk
- Executed as a Process
- Has code inserted into its Virtual Memory space by other programs
- Copied to multiple locations on the system
- Deleted as a process from disk
- Registered as a Dynamic Link Library File
- Created by processes which appear to be checking for interception by security products
- Executed by Internet Explorer
Country Of Origin
The filename 123.EXE was first seen on May 19 2007 in the following geographical regions of the Webroot community:
- The United States on May 19 2007
- China on May 19 2007
- Spain on Oct 14 2007
- Germany on May 27 2009
- Vietnam on Jul 24 2010
- The United Kingdom on Jul 24 2010
File Name Aliases
123.EXE can also use the following file names:
- ALGESTEIYEI.EXE
- FF0B.EXE
- FZ8REQTP.EXE
- FLASH_DISINFECTOR.EXE
- FLASH DISINFECTOR.EXE
- 12F.EXE
- 22323HWI.EXE
- 3JZKO4F2.EXE
- 47IK5867.EXE
- 03607214.EXE
- 38331361.EXE
- 83087888.EXE
- 15328116.EXE
Filesizes
The following file size has been seen:
- 434,176 bytes
- 8,192 bytes
- 41,108 bytes
- 168,960 bytes
- 61,740 bytes
- 103,390 bytes
- 383,029 bytes
File Type
The filename 123.EXE is used by multiple object types including objects,executable programs,self extracting compressed files.
Network Activity
One or more files with the name 123.EXE performs the following network events:
- DNS Lookup217.164.22.109 Devil-111.no-ip.info
Website Activity
One or more files with the name 123.EXE interacts with the following web sites and pages. Web addresses have been deliberately modified to prevent unintentional use.
- TCP:217.164.22.109:3460 Port:13
Help the Webroot Community to fight cyber crime
We are always looking for ways to improve the quality and speed of research to help us protect you from malicious software and cyber crime.
PCMag.com Editors' Choice Award Logo is a trademark of Ziff Davis Publishing Holdings Inc. Used under license.