Examples of Troj/Spy-XR include:
Example 1
File Information
- Size
- 76K
- SHA-1
- 1a847ed28da912dd43ecff8a9c95e9305e9dffec
- MD5
- dbf455f29260b59b21b8407c55b6ebfb
- CRC-32
- 93670d13
- File type
- application/x-ms-dos-executable
- First seen
- 2011-08-08
Example 2
File Information
- Size
- 108K
- SHA-1
- 540a885ba1bb3815b2b2040bc792127c34760409
- MD5
- 92153915eef1405dfcf5556a5977f224
- CRC-32
- 135f04c1
- File type
- Windows executable
- First seen
- 2011-06-03
Runtime Analysis
Dropped Files
- C:\WINDOWS\ime\wmimachine2.dll
- Size
- 76K
- SHA-1
- d8b91a7d5758af9c164dcef25945250be3052b7e
- MD5
- 5e4253897f74ece84df9229cdd66d345
- CRC-32
- e7639ad5
- File type
- Windows executable
- First seen
- 2011-06-03
Registry Keys Created
- HKLM\SYSTEM\CurrentControlSet\Services\6to4
- Start
- 0x00000002
- HKLM\SYSTEM\CurrentControlSet\Services\6to4\Parameters
- ServiceDll
- C:\WINDOWS\ime\wmimachine2.dll
- HKLM\SYSTEM\CurrentControlSet\Services\6to4\Enum
- Count
- 0x00000001
DNS Requests
Example 3
File Information
- Size
- 76K
- SHA-1
- d8b91a7d5758af9c164dcef25945250be3052b7e
- MD5
- 5e4253897f74ece84df9229cdd66d345
- CRC-32
- e7639ad5
- File type
- Windows executable
- First seen
- 2011-06-03