Troj/Inject-ACV exhibits the following characteristics:
File Information
- Size
- 102K
- SHA-1
- 6dd1e1933fe8c35d36af40c8e4ba531eb3344889
- MD5
- b670996fd508559204456fa0f74625cc
- CRC-32
- 7d1c5931
- File type
- Windows executable
- First seen
- 2013-01-22
Runtime Analysis
Copies Itself To
- c:\Documents and Settings\test user\Local Settings\Application Data\fawhcbbn.exe
Dropped Files
- C:\sample.txt
- Size
- 175
- SHA-1
- af9e3e882d554b5d75d9ce11d6bb56b14f647997
- MD5
- 6df96747865541d31b550ecb76b0f76b
- CRC-32
- c025c59a
- File type
- Unspecified binary - probably data
- First seen
- 2012-12-31
Processes Created
- c:\windows\system32\notepad.exe
- c:\windows\system32\svchost.exe
IP Connections
- 109.75.184.192:8080
- 118.97.15.13:8080
- 173.255.203.178:8080
- 190.111.176.13:8080
- 202.169.224.202:8080
- 217.11.63.194:8080
- 46.105.98.86:8081
- 46.163.77.229:8080
- 46.4.178.174:8080
- 66.84.10.68:8080
- 80.90.198.43:8080
- 81.93.248.152:8080
- 82.113.204.228:8080
- 85.197.78.70:8080
- 85.214.22.38:8080
- 88.40.201.187:8080