Troj/Zbot-DPI

Category: Viruses and Spyware Protection available since:16 Jan 2013 21:01:07 (GMT)
Type: Trojan Last Updated:16 Jan 2013 21:01:07 (GMT)
Prevalence: Small Number of Reports

Download Download our free Virus Removal Tool - Find and remove threats your antivirus missed

Examples of Troj/Zbot-DPI include:

Example 1

File Information

Size
48K
SHA-1
e61384746dc632bb93e3a0dc0d34829273f71f0e
MD5
bcb6700ad62b406a7dba571e0bdf6964
CRC-32
f084c2de
File type
Windows executable
First seen
2011-09-04

Other vendor detection

Trend
PAK_Generic.001

Runtime Analysis

Copies Itself To
  • c:\Documents and Settings\test user\Local Settings\Application Data\hemvmnfp.exe
Dropped Files
  • C:\sample.txt
    Size
    175
    SHA-1
    af9e3e882d554b5d75d9ce11d6bb56b14f647997
    MD5
    6df96747865541d31b550ecb76b0f76b
    CRC-32
    c025c59a
    File type
    Unspecified binary - probably data
    First seen
    2012-12-31
Processes Created
  • c:\windows\system32\notepad.exe
  • c:\windows\system32\svchost.exe
IP Connections
  • 173.255.203.178:8080
  • 178.77.103.54:8080
  • 184.106.214.159:8080
  • 202.169.224.202:8080
  • 46.4.178.174:8080
  • 50.57.135.154:8080
  • 66.232.145.174:6667
  • 66.84.10.68:8080
  • 74.208.111.15:8080
  • 88.191.123.128:8080

Example 2

File Information

Size
85K
SHA-1
f67860b427a2df70b2b82c589039c1a4b0cb0f4d
MD5
1e645ca969d6c6f905c267264a0403ff
CRC-32
3cd19c25
File type
Windows executable
First seen
2013-01-16

download Try Sophos products for free
Download now