Troj/Agent-ZPI exhibits the following characteristics:
File Information
- Size
- 133K
- SHA-1
- bb0ca52d1da97e8c8502ea9b5bac75087af0d6e7
- MD5
- aff240e496d458a83242173cb4b9872c
- CRC-32
- 95cff48a
- File type
- Windows executable
- First seen
- 2013-01-12
Other vendor detection
- Avira
- TR/Crypt.ULPM.Gen
- Trend
- PAK_Generic.005
Runtime Analysis
Dropped Files
- C:\WINDOWS\system32\drivers\etc\hosts
- Size
- 766
- SHA-1
- 3c7640696a3f0b76b350677ac4d63ae01a799579
- MD5
- b73d34bb4f4a11828b0e689be5808361
- CRC-32
- 3916fdd0
- File type
- ASCII text / 8-bit Unicode Transformation Format
- First seen
- 2012-09-05
- c:\Documents and Settings\test user\Local Settings\Temp\VnrYne173.exe
- Size
- 81M
- SHA-1
- cd0bda9cfb91ec8da436af27e9324a590cba2f1e
- MD5
- 9d2cfd74c0537f2209500472fd2945c6
- CRC-32
- 594e0004
- File type
- Windows executable
- First seen
- 2013-01-12
Modified Files
- %SYSTEM%\drivers\etc\hosts
- Changed the file contents