Examples of Troj/Zbot-DPI include:
Example 1
File Information
- Size
- 48K
- SHA-1
- e61384746dc632bb93e3a0dc0d34829273f71f0e
- MD5
- bcb6700ad62b406a7dba571e0bdf6964
- CRC-32
- f084c2de
- File type
- Windows executable
- First seen
- 2011-09-04
Other vendor detection
- Trend
- PAK_Generic.001
Runtime Analysis
Copies Itself To
- c:\Documents and Settings\test user\Local Settings\Application Data\hemvmnfp.exe
Dropped Files
- C:\sample.txt
- Size
- 175
- SHA-1
- af9e3e882d554b5d75d9ce11d6bb56b14f647997
- MD5
- 6df96747865541d31b550ecb76b0f76b
- CRC-32
- c025c59a
- File type
- Unspecified binary - probably data
- First seen
- 2012-12-31
Processes Created
- c:\windows\system32\notepad.exe
- c:\windows\system32\svchost.exe
IP Connections
- 173.255.203.178:8080
- 178.77.103.54:8080
- 184.106.214.159:8080
- 202.169.224.202:8080
- 46.4.178.174:8080
- 50.57.135.154:8080
- 66.232.145.174:6667
- 66.84.10.68:8080
- 74.208.111.15:8080
- 88.191.123.128:8080
Example 2
File Information
- Size
- 85K
- SHA-1
- f67860b427a2df70b2b82c589039c1a4b0cb0f4d
- MD5
- 1e645ca969d6c6f905c267264a0403ff
- CRC-32
- 3cd19c25
- File type
- Windows executable
- First seen
- 2013-01-16