Examples of Troj/ZBot-EBJ include:
Example 1
File Information
- Size
- 355K
- SHA-1
- 5d3ec00fd32900229af4cf34f2d0745e01ad85ed
- MD5
- 0a2bc96c6cb22f5c4548d09a2509dd67
- CRC-32
- 2881a5c4
- File type
- Windows executable
- First seen
- 2013-02-28
Runtime Analysis
Registry Keys Created
- HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon\SpecialAccounts\UserList
- DHCP
- 0x00000000
- HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings
- GlobalUserOffline
- 0x00000000
Registry Keys Modified
- HKLM\SYSTEM\CurrentControlSet\Services\SAVAdminService
- Start
- 0x00000004
- HKLM\SYSTEM\CurrentControlSet\Services\SAVService
- Start
- 0x00000004
Processes Created
- c:\windows\system32\net.exe
- c:\windows\system32\net1.exe
Example 2
File Information
- Size
- 238K
- SHA-1
- e203a927b2458ee04f5816e3efd09bc79f16bee4
- MD5
- 98fb8d4aa544a328a4dda9ff427fa572
- CRC-32
- e666fb76
- File type
- Windows executable
- First seen
- 2013-02-27