Examples of Troj/Agent-AMOI include:
Example 1
File Information
- Size
- 60K
- SHA-1
- 029c224de3982dffee70733e0f777275a475f6b5
- MD5
- 9a7ac379fefcc2efb5eede25d4dd2994
- CRC-32
- 3525e1c2
- File type
- Windows executable
- First seen
- 2015-04-15
Runtime Analysis
Dropped Files
- c:\Documents and Settings\test user\Local Settings\Temp\sample.rtf
- Size
- 3.5K
- SHA-1
- 5972e80cc00e89be846692540921c5dfeac5d017
- MD5
- 9fce3b0133ad2796442f5a0e18b681a5
- CRC-32
- d2659ba7
- File type
- Rich Text Format (RTF)
- First seen
- 2015-04-15
- c:\Documents and Settings\test user\Local Settings\Temp\mipexa.cab
- Size
- 967
- SHA-1
- 54e6692e98033e3d56a2298ae7c51362a6948f07
- MD5
- 4c78a169f217a4801917284ddfe16dd3
- CRC-32
- 31fef5e9
- File type
- Microsoft CAB archive
- First seen
- 2015-04-15
Processes Created
- c:\program files\windows nt\accessories\wordpad.exe
Example 2
File Information
- Size
- 60K
- SHA-1
- 04845183afc74df64e496d8f1fbdaa2c92ab686b
- MD5
- eaf064b5f74a9275e37a8d46f8392e95
- CRC-32
- aa932a61
- File type
- Windows executable
- First seen
- 2015-04-15
Runtime Analysis
Dropped Files
- c:\Documents and Settings\test user\Local Settings\Temp\hygu.cab
- Size
- 967
- SHA-1
- 54e6692e98033e3d56a2298ae7c51362a6948f07
- MD5
- 4c78a169f217a4801917284ddfe16dd3
- CRC-32
- 31fef5e9
- File type
- Microsoft CAB archive
- First seen
- 2015-04-15
- c:\Documents and Settings\test user\Local Settings\Temp\sample.rtf
- Size
- 3.5K
- SHA-1
- 5972e80cc00e89be846692540921c5dfeac5d017
- MD5
- 9fce3b0133ad2796442f5a0e18b681a5
- CRC-32
- d2659ba7
- File type
- Rich Text Format (RTF)
- First seen
- 2015-04-15
Processes Created
- c:\program files\windows nt\accessories\wordpad.exe
Example 3
File Information
- Size
- 56K
- SHA-1
- 085c994dbd6ce862dd248d99d0687607bb57008f
- MD5
- c152846fd405cb6dde4592d450378ccd
- CRC-32
- c82377ff
- File type
- Windows executable
- First seen
- 2015-04-15
Runtime Analysis
Dropped Files
- c:\Documents and Settings\test user\Local Settings\Temp\nuleb.cab
- Size
- 967
- SHA-1
- 54e6692e98033e3d56a2298ae7c51362a6948f07
- MD5
- 4c78a169f217a4801917284ddfe16dd3
- CRC-32
- 31fef5e9
- File type
- Microsoft CAB archive
- First seen
- 2015-04-15
- c:\Documents and Settings\test user\Local Settings\Temp\sample.rtf
- Size
- 3.5K
- SHA-1
- 5972e80cc00e89be846692540921c5dfeac5d017
- MD5
- 9fce3b0133ad2796442f5a0e18b681a5
- CRC-32
- d2659ba7
- File type
- Rich Text Format (RTF)
- First seen
- 2015-04-15
Processes Created
- c:\program files\windows nt\accessories\wordpad.exe