Threat Database Backdoors Backdoor.MSIL.DllInject.WAB

Backdoor.MSIL.DllInject.WAB

By CagedTech in Backdoors

Analysis Report

General information

Family Name: Backdoor.MSIL.DllInject.WAB
Signature status: No Signature

Known Samples

MD5: ccc808d98836022acf9be7ff0dc92766
SHA1: d0703a0bb2e7d1ecf9b98e722036521daf226df5
SHA256: E3F066BF2612C50DAC6C2FAC8A00DC35A8F465A7B9DBC599FD32B81617222C2F
File Size: 4.98 MB, 4977510 bytes

Windows Portable Executable Attributes

  • File doesn't have "Rich" header
  • File doesn't have debug information
  • File doesn't have exports table
  • File doesn't have relocations information
  • File doesn't have security information
  • File is 32-bit executable
  • File is either console or GUI application
  • File is GUI application (IMAGE_SUBSYSTEM_WINDOWS_GUI)
  • File is Native application (NOT .NET application)
  • File is not packed
Show More
  • IMAGE_FILE_DLL is not set inside PE header (Executable)
  • IMAGE_FILE_EXECUTABLE_IMAGE is set inside PE header (Executable Image)

File Icons

Windows PE Version Information

Name Value
Company Name Microsoft
File Version 1.00
Internal Name Win
Original Filename Win.exe
Product Name Win
Product Version 1.00

File Traits

  • .NET
  • Agile.net
  • Fody
  • HighEntropy
  • x64

Windows API Usage

Category API
Other Suspicious
  • SetWindowsHookEx

Trending

Most Viewed

Loading...