Examples of Troj/Agent-YBO include:
Example 1
File Information
- Size
- 464K
- SHA-1
- 038efce132bf80f814487fa96217585ac455b037
- MD5
- 5cbeb26a1e41dfbc150c305776554b01
- CRC-32
- 825526fe
- File type
- Windows executable
- First seen
- 2012-10-04
Runtime Analysis
Registry Keys Created
- HKCU\Software\Microsoft\Windows\CurrentVersion\RunOnce
- 7F9735FDC3FC769F00607F96D5DDED3E
- C:\Documents and Settings\All Users\Application Data\7F9735FDC3FC769F00607F96D5DDED3E\7F9735FDC3FC769F00607F96D5DDED3E.exe
HTTP Requests
- http://175.41.28.157/api/urls/
IP Connections
Example 2
File Information
- Size
- 464K
- SHA-1
- 05012e336866bb367363a69623b01324106915f4
- MD5
- e1bcd9b7d1f9fdcfe5b390672b39da41
- CRC-32
- b01e905e
- File type
- Windows executable
- First seen
- 2012-10-02
Runtime Analysis
Registry Keys Created
- HKCU\Software\Microsoft\Windows\CurrentVersion\RunOnce
- 7F9735FDC3FC769F00607F96D5DDED3E
- C:\Documents and Settings\All Users\Application Data\7F9735FDC3FC769F00607F96D5DDED3E\7F9735FDC3FC769F00607F96D5DDED3E.exe
HTTP Requests
- http://175.41.28.157/api/urls/
IP Connections
Example 3
File Information
- Size
- 464K
- SHA-1
- 081d21bd1162fbfc988304762d841b4af8ab2867
- MD5
- 8c3b02fc8818172af6bd54f3299c578a
- CRC-32
- 6178674a
- File type
- Windows executable
- First seen
- 2012-10-04
Runtime Analysis
Registry Keys Created
- HKCU\Software\Microsoft\Windows\CurrentVersion\RunOnce
- 7F9735FDC3FC769F00607F96D5DDED3E
- C:\Documents and Settings\All Users\Application Data\7F9735FDC3FC769F00607F96D5DDED3E\7F9735FDC3FC769F00607F96D5DDED3E.exe
HTTP Requests
- http://175.41.28.157/api/urls/
IP Connections