Examples of Troj/Killav-IB include:
Example 1
File Information
- Size
- 32K
- SHA-1
- 5deb07503e212e23e1f6d23b7fd93289da20061f
- MD5
- d542fd20caac2c34bbec498c05b0d828
- CRC-32
- 51104854
- File type
- Windows executable
- First seen
- 2012-11-23
Example 2
File Information
- Size
- 280K
- SHA-1
- 7d53c1b883391da8d2d9b28c4a255fbcfec7cce1
- MD5
- b286f1b7b6b27977b7a8c161e4ae6a02
- CRC-32
- 41f38d33
- File type
- Windows executable
- First seen
- 2012-11-29
Other vendor detection
- Avira
- TR/Dropper.Gen
Runtime Analysis
Dropped Files
- C:\servicesc.exe
- Size
- 32K
- SHA-1
- 5deb07503e212e23e1f6d23b7fd93289da20061f
- MD5
- d542fd20caac2c34bbec498c05b0d828
- CRC-32
- 51104854
- File type
- Windows executable
- First seen
- 2012-11-23
- c:\Documents and Settings\test user\Local Settings\Temp\~DF330C.tmp
- c:\Documents and Settings\test user\Local Settings\Temp\~DF16BF.tmp
Registry Keys Created
- HKCU\Software\Microsoft\Internet Explorer\International\CpMRU
- Factor
- 0x00000014
Processes Created
HTTP Requests
- http://c.cnzz.com/cnzz_core.php
- http://c.l7l73.net.cn/test/ku62.asp
- http://hzs17.cnzz.com/stat.htm
- http://s17.cnzz.com/stat.php
- http://uu.wangbagou.com/tongji.asp
- http://www.hao123.com/
DNS Requests
- c.cnzz.com
- c.l7l73.net.cn
- hzs17.cnzz.com
- s17.cnzz.com
- uu.wangbagou.com
- www.hao123.com