Troj/Agent-YFA exhibits the following characteristics:
File Information
- Size
- 65K
- SHA-1
- 64f12372d3383fe304554279d7899eda2b0906ef
- MD5
- a1469208d2bf251c7eb8074aab828fc1
- CRC-32
- 05c02bea
- File type
- Windows executable
- First seen
- 2012-10-11
Runtime Analysis
Dropped Files
- c:\Documents and Settings\test user\Local Settings\Temp\937e_appcompat.txt
- c:\Documents and Settings\test user\Local Settings\Temp\7fd6_appcompat.txt
- c:\Documents and Settings\test user\Local Settings\Temp\2f79_appcompat.txt
Registry Keys Created
- HKCU_Classes\CLSID\{fbeb8a05-beee-4442-804e-409d6c4515e9}\inprocserver32
- (Default)
- C:\DOCUME~1\support\LOCALS~1\Temp\\tcrcfg\rcjxyn:weaeml.
- HKCU\Software\Classes\CLSID\{fbeb8a05-beee-4442-804e-409d6c4515e9}\inprocserver32
- (Default)
- C:\DOCUME~1\support\LOCALS~1\Temp\\tcrcfg\rcjxyn:weaeml.
Processes Created
- c:\windows\system32\svchost.exe
HTTP Requests
- http://37.220.36.44/logum.php
IP Connections