Troj/Agent-ZFR exhibits the following characteristics:
File Information
- Size
- 1.2M
- SHA-1
- 531b4fdfb336b9a8af71cfdab205be9c529bef28
- MD5
- 274f0a5640f138002b08ffebf2828620
- CRC-32
- a26f0c08
- File type
- Windows executable
- First seen
- 2012-12-08
Runtime Analysis
Dropped Files
- c:\Documents and Settings\test user\Local Settings\Temp\westernunion.jpg
- Size
- 42K
- SHA-1
- 0fdea728368ed72413f33637133706cb3fff9243
- MD5
- 9350f1ace17270deb3ccb80a923d5e23
- CRC-32
- d321d6ef
- File type
- JPEG Interchange Format
- First seen
- 2012-08-31
Registry Keys Created
- HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Run
- donx
- C:\Documents and Settings\All Users\Common Files\donx.exe
Processes Created
- c:\windows\system32\cmd.exe
- c:\windows\system32\rundll32.exe
- c:\windows\system32\taskkill.exe