Threat Database Trojans Win32/RDPdoor

Win32/RDPdoor

By LoneStar in Trojans

Threat Scorecard

Popularity Rank: 958
Threat Level: 10 % (Normal)
Infected Computers: 44,620
First Seen: March 25, 2013
Last Seen: November 24, 2025
OS(es) Affected: Windows

Win32/RDPdoor is a backdoor Trojan, which uses TeamViewer as a backdoor component to manually transfer money on targeted PCs. Win32/RDPdoor is included in the TeamSpy targeted attack, which affects government services and companies. TeamSpy uses modified components of the TeamViewer software product. Win32/RDPdoor uses legal software in an effort to establish a remote connection with a compromised PC. Win32/RDPdoor makes some changes to the legitimate components of the affected computer. Win32/RDPdoor uses the TeamViewer 5.0 standalone component to begin remote control of the contaminated computer.

Analysis Report

General information

Family Name: PUP.RDPWrap
Signature status: Self Signed

Known Samples

MD5: 997c1dc68532351333a0a43a774743f3
SHA1: 6c6951fb8e4909811805a4d7c6f8974750a2d71d
SHA256: 21E3D2BC0A6F3DBFE4569448145A347557A2B1C220A633AEE2C79C915DA130C7
File Size: 6.96 MB, 6955768 bytes

Windows Portable Executable Attributes

  • File doesn't have "Rich" header
  • File doesn't have debug information
  • File doesn't have exports table
  • File doesn't have relocations information
  • File is 32-bit executable
  • File is either console or GUI application
  • File is GUI application (IMAGE_SUBSYSTEM_WINDOWS_GUI)
  • File is Native application (NOT .NET application)
  • File is not packed
  • IMAGE_FILE_DLL is not set inside PE header (Executable)
Show More
  • IMAGE_FILE_EXECUTABLE_IMAGE is set inside PE header (Executable Image)

File Icons

Windows PE Version Information

Name Value
Comments Created with AutoPlay Media Studio (www.indigorose.com)
Company Name Octanium Software
File Description www.octaniumsw.site
File Version 1.0.0.0
Internal Name ams_runtime
Original Filename autorun.exe
Private Build 7
Product Name RDP Wrapper Config Updater
Product Version 1.0.0.0

Digital Signatures

Signer Root Status
Octanium Software Octanium Software Self Signed

File Traits

  • AMS
  • HighEntropy
  • x86

Block Information

Total Blocks: 16,432
Potentially Malicious Blocks: 564
Whitelisted Blocks: 14,944
Unknown Blocks: 924

Visual Map

0 0 ? 0 ? 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 x 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 x 0 x ? 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 ? ? x ? 0 0 0 0 ? x x x x x x ? x ? 0 0 0 0 ? ? 0 0 0 ? x 0 0 x ? x x ? x ? ? x ? 0 0 0 0 0 0 ? 0 0 0 0 0 0 0 0 ? 0 0 x 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 ? x 0 0 0 ? ? 0 0 0 0 0 ? 0 0 0 0 0 0 0 ? ? ? 0 0 ? ? ? ? ? ? 0 ? ? 0 ? 0 ? ? ? x 0 0 ? ? ? 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 ? 0 ? ? 0 0 0 0 0 0 0 ? 0 ? ? 0 x 0 0 ? 0 0 ? ? ? 0 0 0 0 0 ? 0 ? ? ? x ? ? 0 0 ? ? x 0 0 0 0 ? 0 0 0 ? 0 0 ? ? 0 0 0 0 0 ? 0 0 0 0 ? ? ? ? ? ? ? ? 0 ? 0 ? 0 0 0 0 ? 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 ? 0 0 0 ? 0 0 0 ? 0 0 ? 0 0 0 x 0 0 0 0 ? 0 ? ? ? ? ? ? ? 0 ? ? 0 0 ? ? ? 0 0 0 0 0 ? ? ? ? ? ? ? ? 0 x 0 0 0 x 0 x ? 0 ? 0 x x 0 x x 0 x x x x 0 0 0 ? x 0 ? ? ? ? 0 0 x x x x ? ? ? ? 0 ? 0 0 ? 0 ? ? 0 ? ? ? ? 0 ? ? 0 ? 0 x x ? ? ? ? ? ? ? 0 0 0 0 0 0 0 0 0 0 ? 0 ? ? 0 ? ? ? ? ? 0 ? 0 ? ? ? 0 ? 0 ? ? ? 0 0 0 ? 0 0 ? 0 ? 0 ? ? 0 0 0 0 0 0 0 0 ? 0 0 0 0 x 0 0 0 0 0 0 0 0 0 ? 0 0 0 0 0 ? 0 0 0 0 ? ? ? ? ? ? 0 0 0 0 0 0 0 ? 0 ? ? ? ? ? ? ? ? ? ? ? ? ? ? ? ? ? ? ? ? ? ? ? ? ? ? ? ? ? ? 0 ? ? ? ? ? ? ? ? x x 0 0 0 x 0 0 0 0 0 0 0 0 0 ? ? ? 0 0 x x x x x 0 x 0 0 0 x 0 0 x 0 0 0 0 x 0 0 x ? ? ? ? ? ? ? ? ? x x 0 0 ? 0 0 0 ? 0 0 ? x ? 0 ? x ? 0 ? ? 0 0 x x ? ? ? ? 0 0 0 ? ? ? 0 0 0 x x 0 0 0 x x x x x 0 x x 0 x x x 0 0 ? ? 0 ? ? x 0 ? 0 0 ? ? ? ? ? 0 x x x 0 0 0 0 ? x x 0 0 0 ? 0 ? x 0 x 0 0 x x x x 0 0 0 ? ? 0 0 0 ? 0 0 ? 0 0 x 0 0 x 0 0 x x x x x 0 0 0 0 0 0 0 x x 0 0 0 ? 0 0 0 0 ? 0 0 0 x 0 0 0 0 0 x 0 0 x x x x x x 0 x x 0 0 0 x x 0 0 0 x 0 ? x x 0 0 ? ? 0 ? 0 0 0 0 ? ? ? ? 0 ? ? ? 0 0 0 0 1 ? 0 ? ? ? ? x x 0 0 0 x x x x ? ? ? ? ? ? ? ? ? 0 0 0 0 0 0 ? ? ? 0 x ? 0 0 0 ? ? ? ? ? ? ? ? ? 0 0 0 0 0 0 ? ? 0 0 0 0 0 x 0 0 0 0 0 x x x x x ? 0 0 ? x x ? x 0 x x x x 0 x 0 x x 0 x x 0 x x x x x ? ? ? x ? x x 0 x x 0 ? ? 0 ? 0 ? ? 0 0 0 ? ? x x x x 0 0 0 0 0 0 x x x ? x x 0 0 0 x x x x x x 0 x ? 0 ? ? 0 x 0 x x 0 x 0 x x x x x x x ? ? 0 0 0 ? x x 0 ? x 0 0 ? 0 0 0 0 x x 0 0 0 0 x 0 0 0 x 0 x 0 x x x 0 x x x x x x x x x 0 0 x 0 0 x x x x 0 ? ? 0 0 0 x 0 x x x 0 x ? ? ? ? 0 ? ? x ? ? ? 0 0 x x x x x x x 0 0 ? 0 0 0 ? 0 ? ? ? ? x 0 ? ? 0 ? 0 ? ? ? 0 0 0 0 ? 0 ? ? 0 0 x x x 0 ? 0 0 0 ? 0 0 0 ? 0 ? 0 0 0 ? ? ? ? ? ? 0 0 0 0 ? ? ? ? ? 0 0 0 0 0 0 ? x 0 0 0 0 0 0 0 0 0 0 0 x ? ? ? ? ? 0 ? ? 0 0 x ? ? x 0 x x 0 x 0 x x x x x x x 0 ? 0 0 ? ? ? ? x x 0 x x x x ? 0 0 ? ? ? 0 ? ? ? ? ? ? ? ? ? x ? 0 ? 0 ? ? x ? 0 ? ? 0 0 0 0 0 0 0 0 0 x ? ? ? x x ? ? 0 ? ? 0 ? ? 0 ? ? 0 ? 0 0 0 ? ? 0 0 0 0 0 0 ? ? ? ? 0 0 0 0 x x x x 0 0 0 0 0 ? 0 0 0 0 0 0 0 0 0 0 ? ? 0 ? ? ? ? ? 0 ? ? ? ? ? 0 0 ? 0 ? ? ? ? ? ? 0 0 ? ? 0 0 ? ? x ? ? ? ? 0 ? ? 0 ? ? ? ? ? ? ? 0 0 ? ? ? 0 0 0 ? ? ? 0 ? x x 0 ? 0 x ? ? ? ? ? 0 ? x x x 0 ? ? 0 ? x 0 ? ? ? 0 0 0 0 0 ? ? x x x x ? x x x 0 0 x 0 0 x x 0 ? 0 0 ? ? ? ? ? ? ? 0 ? ? ? ? ? ? ? ? ? ? ? ? ? ? ? ? ? ? ? ? 0 0 1 0 0 0 ? ? x x x x x x x x x x x x x x x x ? ? 0 0 0 0 x x 0 ? ? ? ? ? ? ? 0 x x x x x x ? ? ? ? ? ? ? ? ? ? ? ? 0 ? 0 ? ? ? ? 0 ? ? 0 ? ? ? 0 ? 0 ? ? 0 ? x ? ? ? 0 0 0 0 1 0 0 0 0 0 ? 0 ? x ? 0 x x 0 ? ? ? ? 0 0 0 ? ? ? ? ? ? ? ? ? ? 0 ? 0 ? ? ? x ? 0 ? ? ? 0 0 0 ? ? 0 0 0 ? ? 0 ? ? 0 ? ? 0 ? ? ? ? ? ? ? 0 ? ? ? ? ? ? ? ? ? ? ? ? 0 ? ? ? ? ? ? 0 ? x ? ? ? ? 0 x ? ? ? ? x x ? ? 0 ? ? ? ? ? 0 ? ? ? ? ? ? ? ? 0 0 0 0 ? 0 0 ? ? 0 ? ? 0 0 0 0 0 0 x ? 0 ? 0 ? ? 0 0 0 0 ? ? ? 0 ? ? ? ? 0 0 ? x 0 0 ? ? ? ? ? ? ? ? ? ? x x 0 0 0 0 0 ? 0 0 0 0 0 ? ? 0 0 0 0 ? ? ? 0 ? x 0 ? ? ? 0 0 0 0 ? 0 x x 0 0 0 ? ? 0 0 0 ? 0 ? 0 0 0 ? 0 ? ? ? ? ? ? 0 0 ? ? ? 0 ? 0 ? 0 0 x ? ? ? ? ? ? 0 0 0 0 0 0 0 0 0 0 0 0 0 ? ? 0 0 0 ? 0 ? ? ? ? 0 ? 0 0 0 ? 0 ? ? ? ? ? ? ? ? 0 0 0 ? ? ? 0 0 x 0 0 0 x 0 ? ? 0 0 0 0 0 0 x 0 0 0 0 x 0 ? 0 0 ? x ? ? x 0 0 0 0 0 x ? 0 ? ? x x x 0 0 0 0 0 0 0 0 x 0 0 x 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 ? 0 0 0 0 0 0 0 ? x x ? x 0 ? ? ? ? 0 0 0 0 0 ? ? 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 x 0 0 0 0 0 0 0 0 ? 0 0 0 0 0 0 0 0 0 x x 0 x x x x 0 0 0 0 ? 0 x x 0 0 0 0 x x 0 0 0 0 0 x ? x 0 x 0 0 0 0 0 0 0 0 0 ? x ? ? 0 0 0 ? x x 0 0 0 0 ? ? x ? ? ? 0 x x x x ? x x x 0 0 0 x ? 0 0 0 0 0 x x ? x x 0 x ? 0 ? ? 0 x 0 x 0 ? x 0 0 ? 0 x x 0 x 0 0 0 0 x x 0 x 0 ? ? 0 ? ? x ? ? ? ? ? ? 0 ? ? 0 ? ? ? ? 0 0 ? x ? 0 0 0 ? ? ? ? ? 0 0 0 0 ? ? ? ? 0 0 0 0 0 0 0 0 0
... Data truncated
0 - Probable Safe Block
? - Unknown Block
x - Potentially Malicious Block

Trending

Most Viewed

Loading...