Associated Malware Groups
The filename is associated with the malware groups:
- Cloaked Malware
- Malware Dropper
- Malicious Software
File Behavior
UIPCAFN.EXE has been seen to perform the following behavior:
- Writes to another Process's Virtual Memory (Process Hijacking)
- Executes a Process
- Registers a Dynamic Link Library File
UIPCAFN.EXE has been the subject of the following behavior:
- Created as a process on disk
- Executed as a Process
- Has code inserted into its Virtual Memory space by other programs
Country Of Origin
The filename UIPCAFN.EXE was first seen on Nov 1 2009 in the following geographical regions of the Prevx community:
- URUGUAY on Nov 1 2009
- The EUROPEAN UNION on Nov 2 2009
- CROATIA on Nov 2 2009
- MOROCCO on Nov 18 2009
- GREAT BRITAIN on Nov 18 2009
File Name Aliases
UIPCAFN.EXE can also use the following file names:
- ILMVM.EXE
- NTQKKNQ.EXE
- SPVE.EXE
- DTIAT.EXE
- 19716034.EXE
- 55735933.EXE
Filesizes
The following file size has been seen:
- 101,172 bytes
- 206,336 bytes
- 171,520 bytes
- 100,660 bytes
- 169,984 bytes
File Type
The filename UIPCAFN.EXE refers to many versions of an executable program.
Network Activity
One or more files with the name UIPCAFN.EXE performs the following network events:
- DNS Lookup204.27.57.154 bfkq.com
- DNS Lookup173.45.105.218 jsactivity.com
- DNS Lookup173.45.105.218 173.45.105.218
- DNS Lookup204.27.57.154 204.27.57.154
- DNS Lookup66.96.221.101 66.96.221.101
- DNS Lookup127.0.0.1 0
- DNS Lookup204.27.57.210 204.27.57.210
- DNS Lookup search.toptravellingtips.com
- DNS Lookup208.43.250.167 search.toptravellingtips.com
- DNS Lookup sendfan.com
- DNS Lookup174.36.138.68 sendfan.com
Website Activity
One or more files with the name UIPCAFN.EXE interacts with the following web sites and pages. Web addresses have been deliberately modified to prevent unintentional use.
- TCP:127.0.0.1:1085 Port:15
- TCP:204.27.57.154:8392 Port:15
- TCP:173.45.105.218:8392 Port:15
- TCP:66.96.221.101:8392 Port:15
- Port 80 IP:173.45.105.218
- Port 80 IP:204.27.57.210
- TCP:127.0.0.1:1094 Port:20
- Port 80 IP:208.43.250.167
- TCP:127.0.0.1:1106 Port:20
- Port 80 IP:174.36.138.68
- TCP:204.27.57.154:8392 Port:15
PCMag.com Editors' Choice Award Logo is a trademark of Ziff Davis Publishing Holdings Inc. Used under license.