Examples of Troj/VB-GJR include:
Example 1
File Information
- Size
- 113K
- SHA-1
- 38f2c25e9d5f877f531f5f6307677987ecf7d6da
- MD5
- 1a7667d93e81a5b54d6af3675e5c0eda
- CRC-32
- d157189a
- File type
- Windows executable
- First seen
- 2012-11-22
Runtime Analysis
Dropped Files
- c:\Documents and Settings\test user\Application Data\Microsoft\Protect\S-1-5-21-1202660629-1454471165-1275210071-1003\a09383ed-5ec2-4d84-ba4a-e55a68e76c3a
- Size
- 388
- SHA-1
- f5859c20bb683a2b93e473cb6c541a483ae537c2
- MD5
- d274b4908440547afe94e25228f7f5e9
- CRC-32
- 1357cd32
- File type
- Unspecified binary - probably data
- First seen
- 2012-11-22
- c:\Documents and Settings\test user\Application Data\Microsoft\Crypto\RSA\S-1-5-21-1202660629-1454471165-1275210071-1003\4589b4f51c4660c3639a98ff8d04f157_26c19984-2a01-45b5-a7b3-a568af60c200
- Size
- 72
- SHA-1
- 021f012a9c08ad71fbf6ed63e4a64fd2db198fd1
- MD5
- eab3df5f55f08816dfb13e32f59243b2
- CRC-32
- 94425bee
- File type
- Unspecified binary - probably data
- First seen
- 2012-10-23
- C:\Offset_Funcional.txt
Modified Files
- %PROFILE%\Application Data\Microsoft\Protect\S-1-5-21-1202660629-1454471165-1275210071-1003\Preferred
Example 2
File Information
- Size
- 113K
- SHA-1
- 62d1194a35c740123ab68042a8a6cda74898aa96
- MD5
- 07faf0346c55701568bdb5079bc2440e
- CRC-32
- f48303b9
- File type
- Windows executable
- First seen
- 2012-11-30
Example 3
File Information
- Size
- 113K
- SHA-1
- 885548f033f2d00596509d8cf770f6950b9ee479
- MD5
- 52483869cbfef2119b340cfda55d2d52
- CRC-32
- b58d2108
- File type
- Windows executable
- First seen
- 2012-11-22
Runtime Analysis
Dropped Files
- c:\Documents and Settings\test user\Application Data\Microsoft\Crypto\RSA\S-1-5-21-1202660629-1454471165-1275210071-1003\4589b4f51c4660c3639a98ff8d04f157_26c19984-2a01-45b5-a7b3-a568af60c200
- Size
- 72
- SHA-1
- 021f012a9c08ad71fbf6ed63e4a64fd2db198fd1
- MD5
- eab3df5f55f08816dfb13e32f59243b2
- CRC-32
- 94425bee
- File type
- Unspecified binary - probably data
- First seen
- 2012-10-23
- C:\Offset_Funcional.txt
- c:\Documents and Settings\test user\Application Data\Microsoft\Protect\S-1-5-21-1202660629-1454471165-1275210071-1003\a13d9b64-fc8e-4f0b-818b-1515c94137bb
- Size
- 388
- SHA-1
- 17e28f24a3dd1253f8d7541a0c602141a178d263
- MD5
- e97c99e5fab8637190a1a26180a3a78d
- CRC-32
- fac9e89e
- File type
- Unspecified binary - probably data
- First seen
- 2012-11-23
Modified Files
- %PROFILE%\Application Data\Microsoft\Protect\S-1-5-21-1202660629-1454471165-1275210071-1003\Preferred