Troj/Agent-ZTO exhibits the following characteristics:
File Information
- Size
- 52K
- SHA-1
- 9b71d9b8dffa8e3504bfc00ae228cb6f2fe4097f
- MD5
- f3826facbc72766ccc7fdee65e730e35
- CRC-32
- fc7c9e24
- File type
- Windows executable
- First seen
- 2013-01-30
Runtime Analysis
Copies Itself To
- c:\Documents and Settings\test user\Application Data\Wwopj\gccfbvmu.exe
Registry Keys Created
- HKCU\Software\Microsoft\Windows\CurrentVersion\Run
- vjkubvmu
- c:\Documents and Settings\test user\Application Data\Wwopj\gccfbvmu.exe
Processes Created
- c:\docume~1\support\locals~1\temp\irivycfsll.pre
- c:\windows\system32\ctfmon.exe
- c:\windows\system32\svchost.exe
HTTP Requests
- http://kcrio-oum.com/typo3.php
DNS Requests