Threat Database Backdoors Backdoor.MSIL.DllInject.RRD

Backdoor.MSIL.DllInject.RRD

By CagedTech in Backdoors

Analysis Report

General information

Family Name: Backdoor.MSIL.DllInject.RRD
Signature status: No Signature

Known Samples

MD5: c7dc7029951de199f227e372571df4de
SHA1: afb93ea1cb208f724b9ee746d80763c10434578c
SHA256: FBAE417109184F06AD2A1E581572EE38AFCAAC990EF6E704F5FEB8596CF16131
File Size: 1.03 MB, 1030656 bytes
MD5: 7652135719a0e206684cf4f1e245bf3d
SHA1: c39678edc95063eb183644a406776c8c806af4f3
SHA256: 7D220FE532FAC59A575944544E3F5287DC9EA9AB1E568C7CD798CD2878F5EA9D
File Size: 1.30 MB, 1302016 bytes
MD5: 11b4c7939b1db53d482d9275bbbba7d7
SHA1: 8ab22367c3b304601968e467fb6974b81a3f523e
SHA256: 8FBB4742A2200CEE2558E429E3FC71264225DF009C65F40CB932EF2BC8672B52
File Size: 1.07 MB, 1073664 bytes
MD5: 18237e4bc9fbcd6600148950c433445e
SHA1: c249726df7cd0b05c8b2d2e031e3b7a047b82ffa
SHA256: 826393C36B77FE4F9FE3511F5C92E1927FFEB19AF84F7D678C6981266708DD1C
File Size: 1.06 MB, 1058304 bytes

Windows Portable Executable Attributes

  • File doesn't have "Rich" header
  • File doesn't have exports table
  • File doesn't have security information
  • File is .NET application
  • File is 32-bit executable
  • File is either console or GUI application
  • File is GUI application (IMAGE_SUBSYSTEM_WINDOWS_GUI)
  • File is not packed
  • IMAGE_FILE_DLL is not set inside PE header (Executable)
  • IMAGE_FILE_EXECUTABLE_IMAGE is set inside PE header (Executable Image)

File Icons

Windows PE Version Information

Name Value
Assembly Version 1.0.0.0
Company Name china
File Description Ido_Update
File Version 1.0.0.0
Internal Name Ido_Update.exe
Legal Copyright Copyright © china 2018
Original Filename Ido_Update.exe
Product Name Ido_Update
Product Version 1.0.0.0

File Traits

  • .NET
  • x86

Block Information

Total Blocks: 30
Potentially Malicious Blocks: 22
Whitelisted Blocks: 8
Unknown Blocks: 0

Visual Map

x 0 x x x x x x x x x x x x x x x x x x x x 0 0 x 0 0 0 0 0
0 - Probable Safe Block
? - Unknown Block
x - Potentially Malicious Block

Similar Families

  • MSIL.DllInject.RHK
  • MSIL.DllInject.RRD

Windows API Usage

Category API
User Data Access
  • GetUserDefaultLocaleName
  • GetUserObjectInformation
Anti Debug
  • IsDebuggerPresent
  • NtQuerySystemInformation

Trending

Most Viewed

Loading...