Threat Database Backdoors Backdoor.Agent.OISF

Backdoor.Agent.OISF

By CagedTech in Backdoors

Analysis Report

General information

Family Name: Backdoor.Agent.OISF
Signature status: No Signature

Known Samples

MD5: 565a23ef26d673800d6d0cc1602c17c8
SHA1: a12d19a61516785077b84483a434e7732cc4c532
SHA256: AFB377E5F6E71EF9BEC4114E1C86E44B14624B15392B0E2C9DFB1CCCA6950CD1
File Size: 135.68 KB, 135680 bytes

Windows Portable Executable Attributes

  • File doesn't have "Rich" header
  • File doesn't have security information
  • File has exports table
  • File is 32-bit executable
  • File is either console or GUI application
  • File is GUI application (IMAGE_SUBSYSTEM_WINDOWS_GUI)
  • File is Native application (NOT .NET application)
  • File is not packed
  • IMAGE_FILE_DLL is not set inside PE header (Executable)
  • IMAGE_FILE_EXECUTABLE_IMAGE is set inside PE header (Executable Image)

Windows PE Version Information

Name Value
Comments Scanned Administered Disk scanner
Company Name ConfigEstate
Company Short Name ConfigEstate
File Description Administered Disk Preset
File Version 2.1.52.3025
Internal Name Administered Disk
Legal Copyright Copyright © 2018-2021 ConfigEstate. All rights reserved.
Legal Trademarks Administered Disk is a trademark of ConfigEstate.
Original Filename AdministeredDiskExperiment.exe
Product Name Administered Disk
Product Short Name AdministeredDisk
Product Version 14.20.3120.4837

File Traits

  • HighEntropy
  • x86

Block Information

Total Blocks: 46
Potentially Malicious Blocks: 40
Whitelisted Blocks: 6
Unknown Blocks: 0

Visual Map

x x x x 0 x x x x x x x x x 0 x x x x x x x x x x x x 0 0 x x x x x 0 x 0 x x x x x x x x x
0 - Probable Safe Block
? - Unknown Block
x - Potentially Malicious Block

Similar Families

  • Agent.OISD
  • Agent.OISF

Trending

Most Viewed

Loading...