Examples of Troj/Agent-OUY include:
Example 1
Runtime Analysis
Registry Keys Created
- HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Run
- Microsoft Outlook
- C:\WINDOWS\system32\wincsrss.exe
- HKLM\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\StandardProfile\AuthorizedApplications\List
- C:\WINDOWS\system32\spoolcv.exe
- C:\WINDOWS\system32\spoolcv.exe:*:Enabled:Spoolsv Component
- HKCU\Software\Microsoft\Windows\CurrentVersion\Run
- Microsoft Outlook
- C:\WINDOWS\system32\wincsrss.exe
Example 2
File Information
- Size
- 204K
- SHA-1
- a63c857855fc7e706c5728a8842655ac46fd1170
- MD5
- 28a392b41381e4adf3ee762858c0f12a
- CRC-32
- 57d5316b
- File type
- application/x-ms-dos-executable
- First seen
- 2011-02-17