Examples of Mal/EncPk-AFO include:
Example 1
File Information
- Size
- 234K
- SHA-1
- 213a9262f9e0fc686a32a23d87f164228eff8de0
- MD5
- 101d3eab42b06b5618b45de11f3ccbc6
- CRC-32
- ffc0f76d
- File type
- Windows executable
- First seen
- 2012-04-30
Example 2
File Information
- Size
- 98K
- SHA-1
- 26f297b2b9377ab3ccd7fbdd16569de6d4a39ed1
- MD5
- 90304b07ea9b8a02859ed4793a194c23
- CRC-32
- bcb3415a
- File type
- Windows executable
- First seen
- 2012-06-17
Example 3
File Information
- Size
- 117K
- SHA-1
- 40cbecd9e0dbef19394e03749ff0691dee921178
- MD5
- 144c085d70568dd323c25786ccee92fa
- CRC-32
- 1104ee5e
- File type
- Windows executable
- First seen
- 2011-01-27
Runtime Analysis
Copies Itself To
- c:\Documents and Settings\test user\Local Settings\Temp\4.tmp
Dropped Files
- C:\WINDOWS\Temp\6.tmp
- Size
- 117K
- SHA-1
- 7f73a581c1cea062c0d03c57c14d0ec2f47bf26a
- MD5
- 317248e89ffb5990b8ff14a6ffcc3e89
- CRC-32
- 0b4be443
- File type
- Windows executable
- First seen
- 2011-01-27
Registry Keys Created
- HKEY_USERS\.DEFAULT\Software\Microsoft\Internet Explorer\international
- acceptlanguage
- en-gb
- HKEY_USERS\.DEFAULT\Software\Microsoft\Windows\CurrentVersion\Internet Settings
- enablehttp1_1
- 0x00000001
- HKEY_USERS\S-1-5-18\Software\Microsoft\Windows\CurrentVersion\Internet Settings
- maxhttpredirects
- 0x000022b8
- HKLM\SOFTWARE\Microsoft\DirectDraw\MostRecentApplication
- Name
- spoolsv.exe
Registry Keys Modified
- HKEY_USERS\.DEFAULT\Software\Microsoft\Windows\CurrentVersion\Internet Settings\Zones\3
- 1601
- 0x00000000
- HKEY_USERS\S-1-5-18\Software\Microsoft\Windows\CurrentVersion\Internet Settings\Zones\3
- CurrentLevel
- 0x00000000
- HKLM\SOFTWARE\Microsoft\DirectDraw\MostRecentApplication
- ID
- 0x48025ce1
Processes Created
- c:\windows\system32\spoolsv.exe