Associated Malware Groups
The filename is associated with the malware groups:
- Banking Info Stealer
- Malicious Software
File Behavior
NKORF.EXE has been seen to perform the following behavior:
- Writes to another Process's Virtual Memory (Process Hijacking)
- Executes a Process
- Registers a Dynamic Link Library File
- This process creates other processes on disk
- Found on infected systems and resists interrogation by security products
- Uses low level functions to hide itself from the user and from system/security processes
- Can communicate with other computer systems using HTTP protocols
- Downloads program file(s) and other content from the web
- Injects code into other processes
- Terminates Processes
NKORF.EXE has been the subject of the following behavior:
- Executed as a Process
- Created as a process on disk
- Has code inserted into its Virtual Memory space by other programs
- Terminated as a Process
- Registered as a Dynamic Link Library File
Country Of Origin
The filename NKORF.EXE was first seen on Feb 6 2010 in the following geographical regions of the Prevx community:
- Thailand on Feb 6 2010
- Morocco on Feb 6 2010
- Turkey on Feb 6 2010
- Poland on Feb 7 2010
- The United Kingdom on Feb 7 2010
- Belgium on Feb 9 2010
- Luxembourg on Feb 9 2010
File Name Aliases
NKORF.EXE can also use the following file names:
- BRHPXF.EXE
- SDRA64.EXE
- LNSXGH.EXE
- VQADPJ.EXE
- TVFCLIJFTD[1].HTM
- BHHIVMNN[1].HTM
- APLAYOJL.EXE
- IMJMQDX.EXE
- OIXHEROBY[1].HTM
- PFUNL.EXE
- NFQKX.EXE
- QJXCAE.EXE
- UBCQAQI.EXE
- VORYVQO.EXE
- LCUUQNCY.EXE
- VESITA.EXE
- VSWRYYH.EXE
Filesizes
The following file size has been seen:
- 37,376 bytes
- 108,032 bytes
- 232,448 bytes
- 175,104 bytes
- 205,824 bytes
- 262,656 bytes
File Type
The filename NKORF.EXE refers to many versions of an executable program.
PCMag.com Editors' Choice Award Logo is a trademark of Ziff Davis Publishing Holdings Inc. Used under license.