Threat Database Backdoors Backdoor.Agent.XBL

Backdoor.Agent.XBL

By CagedTech in Backdoors

Analysis Report

General information

Family Name: Backdoor.Agent.XBL
Signature status: No Signature

Known Samples

MD5: 9f1b33cae58ba54610ef87498b1dd835
SHA1: 83a02b1fd7ac423a05d77363b570d36732dfded6
SHA256: DCBE0940EA22ADAC4E6F0285483BE719E5EC8C490CE56304E851378751C5A099
File Size: 7.00 MB, 6997504 bytes
MD5: d822d9762e6ab3db12b901d7d6c3cfe9
SHA1: 0169cfe8846a979a293dd97e795e3e1e3d8bbf63
SHA256: 4718B555A78307DBF8EDB975D5C174A9EAD53D38F9759A44C99A7E8FE7EB6ADD
File Size: 816.64 KB, 816640 bytes

Windows Portable Executable Attributes

  • File doesn't have "Rich" header
  • File doesn't have exports table
  • File doesn't have relocations information
  • File doesn't have security information
  • File has exports table
  • File is 64-bit executable
  • File is either console or GUI application
  • File is GUI application (IMAGE_SUBSYSTEM_WINDOWS_GUI)
  • File is Native application (NOT .NET application)
  • File is not packed
Show More
  • IMAGE_FILE_DLL is not set inside PE header (Executable)
  • IMAGE_FILE_EXECUTABLE_IMAGE is set inside PE header (Executable Image)

File Icons

Windows PE Version Information

Name Value
Company Name
  • Element Ether Intelligence
  • UninstallerSeminar
Company Short Name
  • Element
  • UninstallerSeminar
File Description
  • Print Library Explorer
  • Professional encryption decryption tool for media producers
File Version
  • 7.15.70.4382
  • 5.13.4536.23
Internal Name
  • MakRealAppEngine
  • Print Library
Legal Copyright
  • Copyright © 2012-2020 Element Ether Intelligence. Worldwide rights reserved.
  • Copyright © 2015-2020 UninstallerSeminar. All rights reserved.
Original Filename
  • MakRealApp_util.exe
  • PrintLibraryTrial.exe
Product Name
  • Maker RealTime
  • Print Library
Product Short Name
  • MakRealApp
  • PrintLibrary
Product Version
  • 7.15.70.4382
  • 5.13.4536.23

File Traits

  • HighEntropy
  • Installer Version
  • x64

Block Information

Total Blocks: 50
Potentially Malicious Blocks: 15
Whitelisted Blocks: 16
Unknown Blocks: 19

Visual Map

x x ? ? ? ? ? ? ? 0 ? ? ? 0 x x 0 ? x ? x x x x 0 0 0 0 0 ? 0 0 ? 0 0 0 ? ? ? x x 0 ? 0 x 0 x x x ?
0 - Probable Safe Block
? - Unknown Block
x - Potentially Malicious Block

Similar Families

  • Agent.XBL

Windows API Usage

Category API
Syscall Use
  • ntdll.dll!NtFreeVirtualMemory
  • ntdll.dll!NtProtectVirtualMemory
  • ntdll.dll!NtQueryInformationProcess
  • ntdll.dll!NtQueryInformationThread
  • ntdll.dll!NtQueryVirtualMemory
  • ntdll.dll!NtSetEvent
  • ntdll.dll!NtSetInformationProcess
  • ntdll.dll!NtSetInformationWorkerFactory
  • ntdll.dll!NtTestAlert
  • ntdll.dll!NtWaitLowEventPair
Show More
  • ntdll.dll!NtWriteFile
  • ntdll.dll!NtWriteVirtualMemory
  • UNKNOWN
  • win32u.dll!NtUserGetKeyboardLayout
  • win32u.dll!NtUserGetThreadState

Trending

Most Viewed

Loading...