Examples of Troj/Inject-UY include:
Example 1
File Information
- Size
- 84K
- SHA-1
- 80cfdb31fedcf1d685dde12afa13260971f84843
- MD5
- 2d80499b5944f6c6388638ce6a39550d
- CRC-32
- 2ae025f9
- File type
- Windows executable
- First seen
- 2012-05-16
Other vendor detection
- Avira
- TR/Crypt.ZPACK.Gen
Runtime Analysis
Dropped Files
- c:\Documents and Settings\test user\ODBC.INI
- Size
- 2.2K
- SHA-1
- 2334d7e8ec7591779ec100c9d5759a040d7ed548
- MD5
- 28c485ae49f3d9e827e1abd41e4a88bb
- CRC-32
- 37508106
- File type
- Unspecified binary - probably data
- First seen
- 2012-05-17
HTTP Requests
- http://-http://wei.netserver100.com:80/400034363031663736396600007320616E64203400000000000000340000000000000000000000000000000000000000000000000000000000000050430031663736396600007320616E642053657474696E67735C737570706F72737570706F7274006600007320616E6457696E646F7773205850007320616E64
- http://-http://wei.netserver100.com:80/400034363031663736396600747320616E64203400000000000000340000000000000000000000000000000000000000000000000000000000000050430031663736396600747320616E642053657474696E67735C737570706F72737570706F7274006600747320616E6457696E646F7773205850007320616E64
DNS Requests
Example 2
File Information
- Size
- 84K
- SHA-1
- ab3c7427c3c6d64c839c15b8e2f2f395f5377a7a
- MD5
- 27219a3b9668a9a8a7666f7828aa0b2d
- CRC-32
- 0004249c
- File type
- Windows executable
- First seen
- 2012-05-14
Runtime Analysis
Dropped Files
- c:\Documents and Settings\test user\ODBC.INI
- Size
- 2.2K
- SHA-1
- 5b59c5db204b7782b47c5f05e4c42f8bda14b6fc
- MD5
- d82ea783903d0752349590a23e225913
- CRC-32
- 154003d0
- File type
- Unspecified binary - probably data
- First seen
- 2012-05-14
HTTP Requests
- http://-http://wei.netserver100.com:80/400035363031663736396600007320616E64203500000000000000350000000000000000000000000000000000000000000000000000000000000050430031663736396600007320616E642053657474696E67735C737570706F72737570706F7274006600007320616E6457696E646F7773205850007320616E64
- http://-http://wei.netserver100.com:80/400035363031663736396600747320616E64203500000000000000350000000000000000000000000000000000000000000000000000000000000050430031663736396600747320616E642053657474696E67735C737570706F72737570706F7274006600747320616E6457696E646F7773205850007320616E64
DNS Requests