Associated Malware Groups
The filename is associated with the malware groups:
- Cloaked Malware
- Malicious Software
File Behavior
_EX-08.EXE has been seen to perform the following behavior:
- The Process is packed and/or encrypted using a software packing process
- Adds a Registry Key (RUN) to auto start Programs on system start up
- Writes to another Process's Virtual Memory (Process Hijacking)
- Automatically changes your firewall settings to allow itself or other programs to communicate over the internet
- Creates a TCP port which listens and is available for communication initiated by other computers
- Can communicate with other computer systems using HTTP protocols
- Executes a Process
- Registers a Dynamic Link Library File
- This process creates other processes on disk
- Creates or uses a background service to access the Internet using HTTP protocols
- Modifies firewall settings, without user permission so it is not blocked from accessing the Internet
- Injects code into other processes
- Reads your outlook address book
_EX-08.EXE has been the subject of the following behavior:
- Added as a Registry auto start to load Program on Boot up
- Executed as a Process
- Created as a process on disk
- Has code inserted into its Virtual Memory space by other programs
- Terminated as a Process
- Registered as a Dynamic Link Library File
Country Of Origin
The filename _EX-08.EXE was first seen on Jul 21 2009 in the following geographical regions of the Prevx community:
- Europe on Jul 21 2009
- on Oct 20 2009
- The United Kingdom on Nov 19 2009
- Bulgaria on Dec 8 2009
- The United States on Jan 10 2010
File Name Aliases
_EX-08.EXE can also use the following file names:
- 02937319.EXE
- 84962836.EXE
- 05749892.EXE
- 84798729.EXE
Filesizes
The following file size has been seen:
- 517,632 bytes
- 416,256 bytes
- 716,329 bytes
- 414,208 bytes
- 417,792 bytes
- 418,304 bytes
File Type
The filename _EX-08.EXE refers to many versions of an executable program.
PCMag.com Editors' Choice Award Logo is a trademark of Ziff Davis Publishing Holdings Inc. Used under license.