Troj/Zbot-DEG exhibits the following characteristics:
File Information
- Size
- 361K
- SHA-1
- cd905850f63b855b02ffc90b7a2d18bdfa6ba304
- MD5
- 87c290f9f57e5daebad4bd2446ddc2f7
- CRC-32
- 99ab5121
- File type
- Windows executable
- First seen
- 2012-12-05
Runtime Analysis
Modified Files
- %PROFILE%\Local Settings\Application Data\Identities\{E2564744-A8ED-497D-924B-A548B20CA034}\Microsoft\Outlook Express\Inbox.dbx
- %PROFILE%\Local Settings\Application Data\Identities\{E2564744-A8ED-497D-924B-A548B20CA034}\Microsoft\Outlook Express\Offline.dbx
- %PROFILE%\Local Settings\Application Data\Identities\{E2564744-A8ED-497D-924B-A548B20CA034}\Microsoft\Outlook Express\Folders.dbx
Registry Keys Created
- HKCU\Software\Microsoft\Internet Explorer\Privacy
- CleanCookies
- 0x00000000
- HKCU\Software\Microsoft\Evyp
- Nuduypyh
- □'□□□□`□□□□□ □□□□□□□□□□□□□□□□□□□□□Y□ N□□□□□□□0□□p□□□/□pm□□@□□'□□□□□□□□□□PL□ □□Pt□□□□`□□□J□□□□□h□□D□□q□□□□□\□□□□□j□`□□□□□□□□□□□p□□□{□P□□□□□p□□pQ□ □□@7□0q□□□□□r□□i□□□□□□□□□□@I□
- HKCU\Identities
- Identity Login
- 0x00098053
- HKCU\Software\Microsoft\Windows\CurrentVersion\Run
- {92228FA9-4936-93A3-50E9-0C292876A1F1}
- "c:\Documents and Settings\test user\Application Data\Detipe\ywlet.exe"
Registry Keys Modified
- HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings\Zones\0
- 1609
- 0x00000000
- HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings\Zones\2
- 1609
- 0x00000000
- HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings\Zones\4
- 1609
- 0x00000000
- HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings\Zones\1
- 1609
- 0x00000000
- HKCU\Software\Microsoft\Windows\CurrentVersion\UnreadMail\user@example.com
- TimeStamp
- 3e 62 83 2b c3 d2 cd 01
- HKCU\Identities\{E2564744-A8ED-497D-924B-A548B20CA034}\Software\Microsoft\Outlook Express\5.0
- Compact Check Count
- 0x00000007
Processes Created
- c:\Documents and Settings\test user\application data\detipe\ywlet.exe
- c:\windows\system32\cmd.exe
- c:\windows\system32\ipconfig.exe
HTTP Requests
- http://208.98.15.15/indexes/setns.bin
- http://www.google.bg/webhp
- http://www.google.com/webhp
IP Connections
DNS Requests
- www.google.bg
- www.google.com