Associated Malware Groups
The filename is associated with the malware groups:
- Banking Info Stealer
- Malicious Software
File Behavior
RDR_1257265435.EXE has been seen to perform the following behavior:
- The Process is packed and/or encrypted using a software packing process
- Adds a Registry Key (RUN) to auto start Programs on system start up
- This process creates other processes on disk
- Writes to another Process's Virtual Memory (Process Hijacking)
- Executes a Process
- This Process Deletes Other Processes From Disk
- Injects code into other processes
- Can communicate with other computer systems using HTTP protocols
- Found on infected systems and resists interrogation by security products
RDR_1257265435.EXE has been the subject of the following behavior:
- Executed as a Process
- Created as a process on disk
- Added as a Registry auto start to load Program on Boot up
- Has code inserted into its Virtual Memory space by other programs
- Deleted as a process from disk
- Terminated as a Process
Country Of Origin
The filename RDR_1257265435.EXE was first seen on Nov 3 2009 in the following geographical regions of the Prevx community:
- Europe on Nov 3 2009
- The United States on Nov 3 2009
File Name Aliases
RDR_1257265435.EXE can also use the following file names:
- RDR_1257337856.EXE
- RDR_1257383886.EXE
- RDR_1257269903.EXE
- RDR_1257278953.EXE
- RDR_1257276642.EXE
- RDR_1257308063.EXE
- RDR_1257320190.EXE
- RDR_1257360224.EXE
- COMI0001.EXE
- PP.12[1].EXE
- PP12.EXE
- PP[1].12.EXE
- PP.12.EXE
- PP.12_009.EXE
- PP.12_019.EXE
- PP.12_001.EXE
- PP.12_003.EXE
- PP.12_002.EXE
- PP.12_004.EXE
- PP.12_006.EXE
- PP.12_005.EXE
- PP.12_007.EXE
- PP.12_011.EXE
- PP.12_013.EXE
- PP.12_012.EXE
- PP.12_014.EXE
- PP.12_010.EXE
- PP.12_016.EXE
- PP.12_018.EXE
- PP.12_020.EXE
- PP.12_021.EXE
- PP.12_022.EXE
- PP.12_017.EXE
- PP.12_015.EXE
- PP.12_023.EXE
- PP.12_024.EXE
- PP.12_008.EXE
Filesizes
This file has been seen with the following file size:
File Type
The filename RDR_1257265435.EXE refers to an executable program.
PCMag.com Editors' Choice Award Logo is a trademark of Ziff Davis Publishing Holdings Inc. Used under license.