Threat Database Backdoors Backdoor.CsgoHack.GAI

Backdoor.CsgoHack.GAI

By CagedTech in Backdoors

Analysis Report

General information

Family Name: Backdoor.CsgoHack.GAI
Signature status: No Signature

Known Samples

MD5: f5c29984821e29f3e27ad7dbcfffb783
SHA1: af64848c5867825beb6cad7a166f7912517a8085
File Size: 145.41 KB, 145408 bytes
MD5: 4af59e971fb8e99d767f833d6f50662c
SHA1: 4c6c7f8f6160e88b5e8a1b68c2dd69d3503da619
SHA256: 56F4D8DE36F96F55FDF52ED3FB5AD7AFC410A0261837618FE1C576C44C75B97D
File Size: 73.73 KB, 73728 bytes
MD5: 5f1eff251c4b85c3fc21868cecc8f9fb
SHA1: f2b113ceff188094fa67f377082287c2ff99f595
SHA256: 552EAF414521E65FCFDF0983FA68C2F3332B5AA00ED65F2EF1FFFD3553B60DB2
File Size: 81.41 KB, 81408 bytes
MD5: 849dc22eab339f285f2cbab98dcb8c86
SHA1: ec1e38ee572643cb3710842fba4ba37a84cb3303
SHA256: 9B6D1735F5072044449694AA96334B7C70FE755FED6CCAEED8DB5B4DBBE40A62
File Size: 72.19 KB, 72192 bytes
MD5: a68da135b87c0aaf34ddccc6a358fae1
SHA1: a73d2b583447ece9086a9810379034a56d2b1bde
SHA256: 71CB4FFBBF285B9CFA10480E77B47FA221FF45F7AFE1C662DABC9D0D62FB24EC
File Size: 72.70 KB, 72704 bytes
Show More
MD5: a443f8de3fce9a4b700f077260af9484
SHA1: fd9fe514116f5c940a03bd8229137cf896b4e214
SHA256: 49DAA542E7A076C72CFFFC6084E865421DF10BD7BB082B63DB10A5BA1F0E4D1F
File Size: 119.30 KB, 119296 bytes

Windows Portable Executable Attributes

  • File doesn't have "Rich" header
  • File doesn't have exports table
  • File doesn't have security information
  • File is 32-bit executable
  • File is console application (IMAGE_SUBSYSTEM_WINDOWS_CUI)
  • File is either console or GUI application
  • File is Native application (NOT .NET application)
  • File is not packed
  • IMAGE_FILE_DLL is not set inside PE header (Executable)
  • IMAGE_FILE_EXECUTABLE_IMAGE is set inside PE header (Executable Image)

File Traits

  • 2+ executable sections
  • JMC
  • No Version Info
  • x86

Block Information

Total Blocks: 353
Potentially Malicious Blocks: 12
Whitelisted Blocks: 335
Unknown Blocks: 6

Visual Map

0 0 0 0 0 0 0 ? 0 0 x 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 ? 0 0 0 x 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 x 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 ? ? ? 0 0 0 0 0 0 0 0 0 0 x 0 0 0 0 0 0 0 0 0 0 0 0 x 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 x x 0 0 0 0 0 0 0 0 0 0 0 0 x 0 0 x 0 x x 0 0 0 x 0 ? 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 2 1 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0
0 - Probable Safe Block
? - Unknown Block
x - Potentially Malicious Block

Similar Families

  • CsgoHack.GAI
  • Injector.DFD
  • Injector.KNE
  • Keylogger.QB
  • Trojan.Kryptik.Gen.AZP

Trending

Most Viewed

Loading...