Troj/Agent-GKG exhibits the following characteristics:
Runtime Analysis
Registry Keys Created
- HKLM\SYSTEM\CurrentControlSet\Services\runtime
- ImagePath
- \??\C:\WINDOWS\System32\drivers\runtime.sys
- HKLM\SYSTEM\CurrentControlSet\Services\Secdrv\Enum
- Count
- 0x00000000
HTTP Requests
- http://-/40e8001430303030303030303030303030303030303031306c0000015166000000007600000002
IP Connections