Examples of Troj/Vundo-AN include:
Example 1
File Information
- File type
- Windows executable
Runtime Analysis
Dropped Files
- c:\Documents and Settings\test user\Application Data\hgrwx.exe
Registry Keys Created
- HKCU\Software\Microsoft\Windows\CurrentVersion\Run
- o8t3
- c:\Documents and Settings\test user\Application Data\hgrwx.exe
Processes Created
- c:\Documents and Settings\test user\application data\hgrwx.exe
HTTP Requests
- http://lcogum.net/344/748.html
- http://lcogum.net/48/53.html
- http://lcogum.net/533/619.html
- http://lcogum.net/79/865.html
- http://mkkuei4kdsz.com/283/950.html
- http://mkkuei4kdsz.com/325/912.html
- http://ow5dirasuek.com/138/196.html
DNS Requests
- lcogum.net
- mkkuei4kdsz.com
- ow5dirasuek.com
Example 2
File Information
- File type
- Windows executable
Runtime Analysis
Dropped Files
- c:\Documents and Settings\test user\Application Data\ogaq95.exe
Registry Keys Created
- HKCU\Software\Microsoft\Windows\CurrentVersion\Run
- ardyses5k
- c:\Documents and Settings\test user\Application Data\ogaq95.exe
Processes Created
- c:\Documents and Settings\test user\application data\ogaq95.exe
HTTP Requests
- http://lcogum.net/372/737.html
- http://lcogum.net/726/208.html
- http://lcogum.net/81/98.html
- http://lcogum.net/874/166.html
- http://mkkuei4kdsz.com/450/687.html
- http://mkkuei4kdsz.com/462/970.html
- http://ow5dirasuek.com/780/320.html
DNS Requests
- lcogum.net
- mkkuei4kdsz.com
- ow5dirasuek.com