Examples of Troj/Cutwail-Y include:
Example 1
File Information
- Size
- 36K
- SHA-1
- 147fb3c7be7853c5959d05baffa8bcc10bd91789
- MD5
- ab7b1218c8d16103960acaf036b70890
- CRC-32
- afc504d2
- File type
- Windows executable
- First seen
- 2013-02-06
Other vendor detection
- Avira
- TR/Crypt.XPACK.Gen
Example 2
File Information
- Size
- 40K
- SHA-1
- 2a38e4809d712e437040e2ef7ab9e2343542b6fb
- MD5
- 4f75c9e3f0eff69d181f8196192a761b
- CRC-32
- ee0f42dc
- File type
- Windows executable
- First seen
- 2012-12-27
Other vendor detection
- Avira
- TR/Crypt.XPACK.Gen
Runtime Analysis
Copies Itself To
- c:\Documents and Settings\test user\xozeavokhijo.exe
Registry Keys Created
- HKCU\Software\Microsoft\Windows\CurrentVersion
- xozeavokhijozap
- □j□ □□□□□`□□□□□□)□@3□□=□
- HKCU\Software\Microsoft\Windows\CurrentVersion\Run
- xozeavokhijo
- c:\Documents and Settings\test user\xozeavokhijo.exe
DNS Requests
- 0handicap.at
- 4darabians.nl
- 4etoiles.fr
- 4everandever.de
- 4everflashlight.de
- 4everkids.de
- 4everphp.de
- 4every1.cz
- 4everyware.nl
- accounting.ee
- smtp.live.com
Example 3
File Information
- Size
- 35K
- SHA-1
- 86d31dfa227b0c49e28709f152be180accbc3d2f
- MD5
- 3dc75a477837f4b56b168050d2f3389b
- CRC-32
- 571addbc
- File type
- Windows executable
- First seen
- 2013-02-05
Other vendor detection
- Avira
- TR/Crypt.XPACK.Gen
Runtime Analysis
DNS Requests
- 0daymusic.biz
- 4dbabamozi.hu
- 4estates.eu
- 4etoiles.fr
- 4ever-hosting.de
- 4everdreams.nl
- 4everweb.nl
- 9online.fr
- 9vad4r95bfux.sy
- smtp.live.com