Troj/Karagan-AN exhibits the following characteristics:
File Information
- Size
- 98K
- SHA-1
- 773fc4c2ddf22a74d87e2490a5c369583674838c
- MD5
- b333ccb16027f0e168ff1846ea913a58
- CRC-32
- 4860303e
- File type
- Windows executable
- First seen
- 2012-11-14
Runtime Analysis
Copies Itself To
- c:\Documents and Settings\test user\Local Settings\Application Data\Microsoft\Windows\863\TapiSysprep.exe
Dropped Files
- c:\Documents and Settings\test user\Local Settings\Application Data\Microsoft\Windows\863\d28264df
- Size
- 32
- SHA-1
- d1fc5d4c936a0e5d39492b8d8871a3ec551915a9
- MD5
- 37c6390dd905b3159cc5be0b513360df
- CRC-32
- 9865cdcf
- File type
- Unspecified binary - probably data
- First seen
- 2012-07-07
Registry Keys Created
- HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings
- GlobalUserOffline
- 0x00000000
- HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Run
- TapiSysprep
- c:\Documents and Settings\test user\Local Settings\Application Data\Microsoft\Windows\863\TapiSysprep.exe
Processes Created
- c:\windows\system32\wuauclt.exe
DNS Requests