Threat Database Backdoors Backdoor.Dorkbot.ADDA

Backdoor.Dorkbot.ADDA

By CagedTech in Backdoors

Threat Scorecard

Popularity Rank: 21,123
Threat Level: 60 % (Medium)
Infected Computers: 6
First Seen: November 28, 2022
Last Seen: March 1, 2026
OS(es) Affected: Windows

Analysis Report

General information

Family Name: Backdoor.Dorkbot.ADDA
Signature status: No Signature

Known Samples

MD5: 5862d5491756469d6aa60276af1ff75b
SHA1: d77d2b8edcc10451750a5d0ce3d4c71c5edd5143
SHA256: 675399D5D63A84240089BBBF67C0B133A128A38A8251E4B923D026B30DD1169A
File Size: 389.12 KB, 389120 bytes
MD5: 511891a7a129e2756a2d50134fc09aa2
SHA1: 43c6f853ae938eb2d484fbbe8452c149eb50aac5
SHA256: 1EA362EF4651F429034BE2DFA27F68FF36714EF3DE9541F65A9C2A5E909A0A97
File Size: 166.91 KB, 166912 bytes

Windows Portable Executable Attributes

  • File doesn't have "Rich" header
  • File doesn't have debug information
  • File doesn't have exports table
  • File doesn't have relocations information
  • File doesn't have security information
  • File has exports table
  • File is 32-bit executable
  • File is console application (IMAGE_SUBSYSTEM_WINDOWS_CUI)
  • File is either console or GUI application
  • File is GUI application (IMAGE_SUBSYSTEM_WINDOWS_GUI)
Show More
  • File is Native application (NOT .NET application)
  • File is not packed
  • IMAGE_FILE_DLL is not set inside PE header (Executable)
  • IMAGE_FILE_EXECUTABLE_IMAGE is set inside PE header (Executable Image)

File Icons

Windows PE Version Information

Name Value
Company Name
  • Delcam
  • Microsoft Corporation
File Description IE 7.0 Unattended Install Utility
File Version
  • 8.00.7601.17514 (win7sp1_rtm.101119-1850)
  • 1, 3, 0, 0
Internal Name
  • ArtSpool
  • IEUNATT
Legal Copyright
  • Copyright © Delcam 2007
  • © Microsoft Corporation. All rights reserved.
Original Filename
  • ArtSpool
  • IEUNATT.EXE
Product Name
  • ArtSpool Application
  • Windows® Internet Explorer
Product Version
  • 8.00.7601.17514
  • 1, 3, 0, 0

File Traits

  • 2+ executable sections
  • HighEntropy
  • Installer Manifest
  • Installer Version
  • x86

Block Information

Total Blocks: 548
Potentially Malicious Blocks: 1
Whitelisted Blocks: 546
Unknown Blocks: 1

Visual Map

0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 2 2 0 0 0 2 3 1 0 1 1 0 0 0 0 2 0 0 0 0 0 1 0 0 0 1 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 1 0 0 0 0 1 0 0 0 0 0 0 0 0 0 0 0 0 2 2 0 2 0 0 2 0 0 0 2 2 2 2 2 0 0 0 0 0 1 1 0 1 0 0 0 1 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 1 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 1 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 1 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 1 0 0 1 0 0 0 2 2 2 2 2 2 2 2 2 2 2 2 2 2 2 2 2 2 2 2 2 2 2 2 2 2 2 2 2 2 2 2 2 2 2 2 2 2 2 2 2 2 2 0 2 2 2 2 2 2 2 2 2 2 2 2 2 2 2 2 2 2 2 2 2 2 2 2 2 2 2 2 2 2 2 2 2 2 2 2 2 2 2 2 2 2 2 2 2 2 2 2 2 2 2 2 2 2 2 2 2 2 2 2 2 2 2 2 2 2 2 2 2 2 2 2 2 2 2 2 2 2 2 2 2 2 2 2 2 2 2 2 2 2 2 2 2 2 2 2 2 2 2 2 2 2 2 2 2 2 2 2 2 2 1 2 2 2 2 2 2 2 2 2 2 2 2 2 2 2 2 2 2 2 2 0 0 0 0 1 0 1 0 1 0 0 0 0 1 0 0 0 0 1 1 3 1 1 1 0 1 0 1 1 0 0 0 1 0 0 0 0 0 0 0 0 0 0 0 1 0 1 1 0 0 0 0 0 0 ? x
0 - Probable Safe Block
? - Unknown Block
x - Potentially Malicious Block

Similar Families

  • Agent.AE
  • Agent.HGG
  • Agent.MAJ
  • Injector.MFA
  • Phorpiex.O
Show More
  • Trojan.Kryptik.Gen.AYK

Files Modified

File Attributes
c:\windows\panther\unattendgc\diagerr.xml Generic Read,Write Data,Write Attributes,Write extended,Append data
c:\windows\panther\unattendgc\diagwrn.xml Generic Read,Write Data,Write Attributes,Write extended,Append data
c:\windows\panther\unattendgc\setupact.log Generic Read,Write Data,Write Attributes,Write extended,Append data
c:\windows\panther\unattendgc\setuperr.log Generic Read,Write Data,Write Attributes,Write extended,Append data

Registry Modifications

Key::Value Data API Name
HKLM\system\controlset001\services\sharedaccess\parameters\firewallpolicy\standardprofile\authorizedapplications\list::c:\users\user\downloads\d77d2b8edcc10451750a5d0ce3d4c71c5edd5143_0000389120 c:\users\user\downloads\d77d2b8edcc10451750a5d0ce3d4c71c5edd5143_0000389120:*:enabled:@shell32.dll,-1 RegNtPreCreateKey
HKLM\system\controlset001\services\sharedaccess\parameters\firewallpolicy\standardprofile\authorizedapplications\list::c:\users\user\downloads\43c6f853ae938eb2d484fbbe8452c149eb50aac5_0000166912 c:\users\user\downloads\43c6f853ae938eb2d484fbbe8452c149eb50aac5_0000166912:*:enabled:@shell32.dll,-1 RegNtPreCreateKey

Windows API Usage

Category API
Anti Debug
  • IsDebuggerPresent

Trending

Most Viewed

Loading...