Threat Database Backdoors Backdoor.MSIL.Spy.Agent.GAB

Backdoor.MSIL.Spy.Agent.GAB

By CagedTech in Backdoors

Threat Scorecard

Threat Level: 60 % (Medium)
Infected Computers: 561
First Seen: March 31, 2023
Last Seen: March 29, 2026
OS(es) Affected: Windows

The detection of Backdoor.MSIL.Spy.Agent.GAB on your system indicates a potential security threat that requires immediate attention. This backdoor threat is designed to secretly allow unauthorized access to your computer, which can lead to a range of serious consequences, including data theft, malware distribution, and further system compromise. It is essential to understand the nature of this threat and take prompt action to remove it and secure your system.

What Is Backdoor.MSIL.Spy.Agent.GAB?

Backdoor.MSIL.Spy.Agent.GAB is identified as a backdoor threat, which means it is a type of malware that opens a secret portal or "back door" on your computer, allowing hackers to remotely access and control your system without your knowledge or consent. This can happen through various means, such as exploiting vulnerabilities in software or tricking users into installing malicious programs. The "MSIL" part of the name suggests that the malware is written in Microsoft Intermediate Language, which is a platform-agnostic intermediate representation of the .NET Common Intermediate Language (CIL).

How Backdoor.MSIL.Spy.Agent.GAB Operates

Once installed on your system, Backdoor.MSIL.Spy.Agent.GAB can operate in stealth mode, making it difficult to detect without proper security tools. It can communicate with its command and control servers to receive instructions, which might include downloading additional malware, stealing sensitive information, or using your computer as a botnet to distribute spam or launch attacks on other systems. The exact operation can vary, but the primary goal is to maintain unauthorized access to your computer for malicious purposes.

Symptoms of Infection

Symptoms of a Backdoor.MSIL.Spy.Agent.GAB infection can be subtle and may not always be immediately apparent. However, you might notice unusual system behavior, such as unexpected changes to your computer settings, unfamiliar programs running in the background, or an increase in suspicious network activity. Your system might also become slower, or you might experience frequent crashes or freezes. Since backdoors are designed to be stealthy, some infections might not exhibit noticeable symptoms at all, making regular system monitoring and security scans crucial.

How to Remove Backdoor.MSIL.Spy.Agent.GAB

  1. Boot your computer into Safe Mode with Networking to prevent the malware from loading and to give you a cleaner environment to work in.
  2. Use a reputable anti-malware tool, such as SpyHunter, to perform a full scan of your system. This can help detect and remove the backdoor and any associated malware.
  3. Uninstall any suspicious programs that you do not recognize or that were installed around the time the malware was detected.
  4. Reset your web browsers (Chrome, Firefox, Edge, etc.) to their default settings to remove any malicious extensions or settings changes made by the malware.
  5. Reboot your computer and perform another scan with your anti-malware tool to ensure that the threat has been fully removed.

Conclusion

The removal of Backdoor.MSIL.Spy.Agent.GAB requires careful and immediate action to prevent further damage to your system and to protect your personal data. By following the steps outlined above and maintaining good security practices, such as keeping your software up to date, using strong antivirus protection, and being cautious with emails and downloads, you can significantly reduce the risk of future infections. Remember, vigilance and proactive security measures are key to safeguarding your digital environment.

Analysis Report

General information

Family Name: Backdoor.MSIL.Spy.Agent.GAB
Signature status: No Signature

Known Samples

MD5: 67b2d6ea4f0fc26b11cc2acf648f97be
SHA1: 93fae789011b68a7f1465c2012958b28d25b13fd
SHA256: 058EE10051DC65C4C5B59CBECA66B1281BF00353504F2B34E8C7318C6D856720
File Size: 1.50 MB, 1501184 bytes

Windows Portable Executable Attributes

  • File doesn't have "Rich" header
  • File doesn't have debug information
  • File doesn't have exports table
  • File doesn't have security information
  • File is .NET application
  • File is 32-bit executable
  • File is either console or GUI application
  • File is GUI application (IMAGE_SUBSYSTEM_WINDOWS_GUI)
  • File is not packed
  • IMAGE_FILE_DLL is not set inside PE header (Executable)
Show More
  • IMAGE_FILE_EXECUTABLE_IMAGE is set inside PE header (Executable Image)

Windows PE Version Information

Name Value
File Version 5.15.2.0
Original Filename libGLESv2.dll
Product Name libGLESv2
Product Version 5.15.2.0

File Traits

  • .NET
  • x86

Block Information

Total Blocks: 1,069
Potentially Malicious Blocks: 238
Whitelisted Blocks: 830
Unknown Blocks: 1

Visual Map

0 0 0 0 0 0 0 0 0 0 0 0 0 x 0 x 0 0 0 0 0 0 0 x 0 x x x 0 x 0 0 x x x 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 x x x x x x x 0 0 x 0 0 x 0 x x x 0 x 0 0 0 x x x x x x x 0 x x x x x x x x x x x x x x x x x x x x x x x x x x x x x x x x x x x x x x x x x x x x x x x x x x x x x x x x x x x x x x x x x x x x 0 0 x x x x x 0 x x 0 0 x x x x x x x x x x x 0 x x x x x x x x x x x x x x x x x x x x x x x x x x x x x 0 x ? x 0 x x x x x x x x x x x x x x x x x x x x x x x x 0 x x x x x x x x x x x x x x 0 x 0 0 0 x x x x x x x x 0 x x x x x x 0 x x x x x x x x x x x 0 0 x x 0 0 x x x 0 x x x x x 0 x x 0 x x x 0 x x x 0 x x x x x x x x x 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0
0 - Probable Safe Block
? - Unknown Block
x - Potentially Malicious Block

Similar Families

  • MSIL.Spy.Agent.GAB

Files Modified

File Attributes
c:\program files (x86)\windowspowershell\modules\pester\3.3.5\en-us\cd89ddd3d81b06 Generic Write,Read Attributes
c:\program files (x86)\windowspowershell\modules\pester\3.3.5\en-us\tiworker.exe Generic Read,Write Data,Write Attributes,Write extended,Append data,Delete,LEFT 262144
c:\program files\windows nt\f3b6ecef712a24 Generic Write,Read Attributes
c:\program files\windows nt\spoolsv.exe Generic Read,Write Data,Write Attributes,Write extended,Append data,Delete,LEFT 262144
c:\program files\windows nt\tabletextservice\en-us\9e8d7a4ca61bd9 Generic Write,Read Attributes
c:\program files\windows nt\tabletextservice\en-us\runtimebroker.exe Generic Read,Write Data,Write Attributes,Write extended,Append data,Delete,LEFT 262144
c:\recovery\oem\9aa6b00bbc395a Generic Write,Read Attributes
c:\recovery\oem\sandboxtool.exe Generic Read,Write Data,Write Attributes,Write extended,Append data,Delete,LEFT 262144
c:\sandbox_local\088424020bedd6 Generic Write,Read Attributes
c:\sandbox_local\conhost.exe Generic Read,Write Data,Write Attributes,Write extended,Append data,Delete,LEFT 262144
Show More
c:\sandbox_stage\mnt\9e8d7a4ca61bd9 Generic Write,Read Attributes
c:\sandbox_stage\mnt\runtimebroker.exe Generic Read,Write Data,Write Attributes,Write extended,Append data,Delete,LEFT 262144
c:\windows\system32\drivers\etc\hosts Generic Write,Read Attributes

Registry Modifications

Key::Value Data API Name
HKLM\software\microsoft\tracing\rasapi32::enablefiletracing RegNtPreCreateKey
HKLM\software\microsoft\tracing\rasapi32::enableautofiletracing RegNtPreCreateKey
HKLM\software\microsoft\tracing\rasapi32::enableconsoletracing RegNtPreCreateKey
HKLM\software\microsoft\tracing\rasapi32::filetracingmask ￿ RegNtPreCreateKey
HKLM\software\microsoft\tracing\rasapi32::consoletracingmask ￿ RegNtPreCreateKey
HKLM\software\microsoft\tracing\rasapi32::maxfilesize  RegNtPreCreateKey
HKLM\software\microsoft\tracing\rasapi32::filedirectory %windir%\tracing RegNtPreCreateKey
HKLM\software\microsoft\tracing\rasmancs::enablefiletracing RegNtPreCreateKey
HKLM\software\microsoft\tracing\rasmancs::enableautofiletracing RegNtPreCreateKey
HKLM\software\microsoft\tracing\rasmancs::enableconsoletracing RegNtPreCreateKey
Show More
HKLM\software\microsoft\tracing\rasmancs::filetracingmask ￿ RegNtPreCreateKey
HKLM\software\microsoft\tracing\rasmancs::consoletracingmask ￿ RegNtPreCreateKey
HKLM\software\microsoft\tracing\rasmancs::maxfilesize  RegNtPreCreateKey
HKLM\software\microsoft\tracing\rasmancs::filedirectory %windir%\tracing RegNtPreCreateKey
HKCU\software\68b76ccb9f797241714e26ebf84d7dd1::68b76ccb9f797241714e26ebf84d7dd1 h�l˟yrAqN&�M}� RegNtPreCreateKey
HKCU\software\microsoft\windows\currentversion\run::runtimebroker "C:\Program Files\Windows NT\TableTextService\en-US\RuntimeBroker.exe" RegNtPreCreateKey
HKLM\software\microsoft\windows\currentversion\run::runtimebroker "C:\Program Files\Windows NT\TableTextService\en-US\RuntimeBroker.exe" RegNtPreCreateKey
HKLM\software\microsoft\windows nt\currentversion\winlogon::shell explorer.exe, "C:\Program Files\Windows NT\TableTextService\en-US\RuntimeBroker.exe" RegNtPreCreateKey
HKCU\software\microsoft\windows\currentversion\run::conhost "C:\sandbox_local\conhost.exe" RegNtPreCreateKey
HKLM\software\microsoft\windows\currentversion\run::conhost "C:\sandbox_local\conhost.exe" RegNtPreCreateKey
HKLM\software\microsoft\windows nt\currentversion\winlogon::shell explorer.exe, "C:\Program Files\Windows NT\TableTextService\en-US\RuntimeBroker.exe", "C:\sandbox_local\conhost.exe" RegNtPreCreateKey
HKCU\software\microsoft\windows\currentversion\run::spoolsv "C:\Program Files\windows nt\spoolsv.exe" RegNtPreCreateKey
HKLM\software\microsoft\windows\currentversion\run::spoolsv "C:\Program Files\windows nt\spoolsv.exe" RegNtPreCreateKey
HKLM\software\microsoft\windows nt\currentversion\winlogon::shell explorer.exe, "C:\Program Files\Windows NT\TableTextService\en-US\RuntimeBroker.exe", "C:\sandbox_local\conhost.exe", "C:\Progra RegNtPreCreateKey
HKCU\software\microsoft\windows\currentversion\run::sandboxtool "C:\Recovery\OEM\SandboxTool.exe" RegNtPreCreateKey
HKLM\software\microsoft\windows\currentversion\run::sandboxtool "C:\Recovery\OEM\SandboxTool.exe" RegNtPreCreateKey
HKLM\software\microsoft\windows nt\currentversion\winlogon::shell explorer.exe, "C:\Program Files\Windows NT\TableTextService\en-US\RuntimeBroker.exe", "C:\sandbox_local\conhost.exe", "C:\Progra RegNtPreCreateKey
HKCU\software\microsoft\windows\currentversion\run::runtimebroker "C:\sandbox_stage\mnt\RuntimeBroker.exe" RegNtPreCreateKey
HKLM\software\microsoft\windows\currentversion\run::runtimebroker "C:\sandbox_stage\mnt\RuntimeBroker.exe" RegNtPreCreateKey
HKLM\software\microsoft\windows nt\currentversion\winlogon::shell explorer.exe, "C:\Program Files\Windows NT\TableTextService\en-US\RuntimeBroker.exe", "C:\sandbox_local\conhost.exe", "C:\Progra RegNtPreCreateKey
HKCU\software\microsoft\windows\currentversion\run::tiworker "C:\Program Files (x86)\WindowsPowerShell\Modules\Pester\3.3.5\en-US\TiWorker.exe" RegNtPreCreateKey
HKLM\software\microsoft\windows\currentversion\run::tiworker "C:\Program Files (x86)\WindowsPowerShell\Modules\Pester\3.3.5\en-US\TiWorker.exe" RegNtPreCreateKey
HKLM\software\microsoft\windows nt\currentversion\winlogon::shell explorer.exe, "C:\Program Files\Windows NT\TableTextService\en-US\RuntimeBroker.exe", "C:\sandbox_local\conhost.exe", "C:\Progra RegNtPreCreateKey
HKCU\software\d4358a9d2d3e5c9ec281a1763cbfb0ffa2f70a57::a54080a8d58debdcc17f33c6314d5d090910db29 WyJjOlxcdXNlcnNcXHVzZXJcXGRvd25sb2Fkc1xcOTNmYWU3ODkwMTFiNjhhN2YxNDY1YzIwMTI5NThiMjhkMjViMTNmZF8wMDAxNTAxMTg0IiwiQzpcXFByb2dyYW0g RegNtPreCreateKey
HKLM\system\controlset001\services\bam\state\usersettings\s-1-5-21-3119368278-1123331430-659265220-1001::\device\harddiskvolume2\windows\system32\conhost.exe 舥✄ǜ RegNtPreCreateKey
HKLM\system\controlset001\services\bam\state\usersettings\s-1-5-21-3119368278-1123331430-659265220-1001::\device\harddiskvolume2\windows\system32\conhost.exe 舥✄ǜ RegNtPreCreateKey
HKLM\system\controlset001\services\bam\state\usersettings\s-1-5-21-3119368278-1123331430-659265220-1001::\device\harddiskvolume2\windows\system32\conhost.exe 䳏舨✄ǜ RegNtPreCreateKey
HKLM\system\controlset001\services\bam\state\usersettings\s-1-5-21-3119368278-1123331430-659265220-1001::\device\harddiskvolume2\windows\system32\conhost.exe 꿪航✄ǜ RegNtPreCreateKey
HKLM\system\controlset001\services\bam\state\usersettings\s-1-5-21-3119368278-1123331430-659265220-1001::\device\harddiskvolume2\windows\system32\conhost.exe ᅮ舭✄ǜ RegNtPreCreateKey
HKLM\system\controlset001\services\bam\state\usersettings\s-1-5-21-3119368278-1123331430-659265220-1001::\device\harddiskvolume2\windows\system32\conhost.exe 玳舯✄ǜ RegNtPreCreateKey
HKLM\system\controlset001\services\bam\state\usersettings\s-1-5-21-3119368278-1123331430-659265220-1001::\device\harddiskvolume2\windows\system32\conhost.exe 役舻✄ǜ RegNtPreCreateKey
HKLM\system\controlset001\services\bam\state\usersettings\s-1-5-21-3119368278-1123331430-659265220-1001::\device\harddiskvolume2\windows\system32\conhost.exe 蚥艂✄ǜ RegNtPreCreateKey
HKLM\system\controlset001\services\bam\state\usersettings\s-1-5-21-3119368278-1123331430-659265220-1001::\device\harddiskvolume2\windows\system32\conhost.exe ࿝艌✄ǜ RegNtPreCreateKey
HKLM\system\controlset001\services\bam\state\usersettings\s-1-5-21-3119368278-1123331430-659265220-1001::\device\harddiskvolume2\windows\system32\conhost.exe 饉艕✄ǜ RegNtPreCreateKey
HKLM\system\controlset001\services\bam\state\usersettings\s-1-5-21-3119368278-1123331430-659265220-1001::\device\harddiskvolume2\windows\system32\conhost.exe 갲艨✄ǜ RegNtPreCreateKey
HKLM\system\controlset001\services\bam\state\usersettings\s-1-5-21-3119368278-1123331430-659265220-1001::\device\harddiskvolume2\windows\system32\conhost.exe 뻫艻✄ǜ RegNtPreCreateKey
HKLM\system\controlset001\services\bam\state\usersettings\s-1-5-21-3119368278-1123331430-659265220-1001::\device\harddiskvolume2\windows\system32\conhost.exe 㑉芑✄ǜ RegNtPreCreateKey
HKLM\system\controlset001\services\bam\state\usersettings\s-1-5-21-3119368278-1123331430-659265220-1001::\device\harddiskvolume2\windows\system32\conhost.exe 芡✄ǜ RegNtPreCreateKey
HKLM\system\controlset001\services\bam\state\usersettings\s-1-5-21-3119368278-1123331430-659265220-1001::\device\harddiskvolume2\windows\system32\conhost.exe 芴✄ǜ RegNtPreCreateKey
HKLM\system\controlset001\services\bam\state\usersettings\s-1-5-21-3119368278-1123331430-659265220-1001::\device\harddiskvolume2\windows\system32\conhost.exe 洄苊✄ǜ RegNtPreCreateKey

Windows API Usage

Category API
Syscall Use
  • ntdll.dll!NtAccessCheck
  • ntdll.dll!NtAlertThreadByThreadId
  • ntdll.dll!NtAlpcConnectPort
  • ntdll.dll!NtAlpcConnectPortEx
  • ntdll.dll!NtAlpcCreatePortSection
  • ntdll.dll!NtAlpcCreateSectionView
  • ntdll.dll!NtAlpcCreateSecurityContext
  • ntdll.dll!NtAlpcDeleteSecurityContext
  • ntdll.dll!NtAlpcQueryInformation
  • ntdll.dll!NtAlpcQueryInformationMessage
Show More
  • ntdll.dll!NtAlpcSendWaitReceivePort
  • ntdll.dll!NtAlpcSetInformation
  • ntdll.dll!NtApphelpCacheControl
  • ntdll.dll!NtAssociateWaitCompletionPacket
  • ntdll.dll!NtCancelTimer2
  • ntdll.dll!NtCancelWaitCompletionPacket
  • ntdll.dll!NtClearEvent
  • ntdll.dll!NtClose
  • ntdll.dll!NtCompareSigningLevels
  • ntdll.dll!NtConnectPort
  • ntdll.dll!NtCreateEvent
  • ntdll.dll!NtCreateFile
  • ntdll.dll!NtCreateIoCompletion
  • ntdll.dll!NtCreateKey
  • ntdll.dll!NtCreateMutant
  • ntdll.dll!NtCreatePrivateNamespace
  • ntdll.dll!NtCreateSection
  • ntdll.dll!NtCreateSemaphore
  • ntdll.dll!NtCreateThreadEx
  • ntdll.dll!NtCreateTimer
  • ntdll.dll!NtCreateTimer2
  • ntdll.dll!NtCreateWaitCompletionPacket
  • ntdll.dll!NtCreateWorkerFactory
  • ntdll.dll!NtDelayExecution
  • ntdll.dll!NtDeviceIoControlFile
  • ntdll.dll!NtDuplicateObject
  • ntdll.dll!NtDuplicateToken
  • ntdll.dll!NtEnumerateKey
  • ntdll.dll!NtEnumerateValueKey
  • ntdll.dll!NtFlushProcessWriteBuffers
  • ntdll.dll!NtFreeVirtualMemory
  • ntdll.dll!NtGetCachedSigningLevel
  • ntdll.dll!NtGetCompleteWnfStateSubscription
  • ntdll.dll!NtGetContextThread
  • ntdll.dll!NtGetWriteWatch
  • ntdll.dll!NtMapViewOfSection
  • ntdll.dll!NtNotifyChangeKey
  • ntdll.dll!NtOpenDirectoryObject
  • ntdll.dll!NtOpenEvent
  • ntdll.dll!NtOpenFile
  • ntdll.dll!NtOpenKey
  • ntdll.dll!NtOpenKeyEx
  • ntdll.dll!NtOpenProcess
  • ntdll.dll!NtOpenProcessToken
  • ntdll.dll!NtOpenSection
  • ntdll.dll!NtOpenSemaphore
  • ntdll.dll!NtOpenThread
  • ntdll.dll!NtOpenThreadToken
  • ntdll.dll!NtProtectVirtualMemory
  • ntdll.dll!NtQueryAttributesFile
  • ntdll.dll!NtQueryDefaultLocale
  • ntdll.dll!NtQueryDirectoryFileEx
  • ntdll.dll!NtQueryFullAttributesFile
  • ntdll.dll!NtQueryInformationFile
  • ntdll.dll!NtQueryInformationJobObject
  • ntdll.dll!NtQueryInformationProcess
  • ntdll.dll!NtQueryInformationThread
  • ntdll.dll!NtQueryInformationToken
  • ntdll.dll!NtQueryKey
  • ntdll.dll!NtQueryLicenseValue
  • ntdll.dll!NtQueryPerformanceCounter
  • ntdll.dll!NtQuerySecurityAttributesToken
  • ntdll.dll!NtQuerySecurityObject
  • ntdll.dll!NtQuerySystemInformation
  • ntdll.dll!NtQuerySystemInformationEx
  • ntdll.dll!NtQueryValueKey
  • ntdll.dll!NtQueryVirtualMemory
  • ntdll.dll!NtQueryVolumeInformationFile
  • ntdll.dll!NtQueryWnfStateData
  • ntdll.dll!NtQueueApcThread
  • ntdll.dll!NtQueueApcThreadEx2
  • ntdll.dll!NtReadFile
  • ntdll.dll!NtReadVirtualMemory
  • ntdll.dll!NtReleaseMutant
  • ntdll.dll!NtReleaseSemaphore
  • ntdll.dll!NtReleaseWorkerFactoryWorker
  • ntdll.dll!NtRequestWaitReplyPort
  • ntdll.dll!NtResetWriteWatch
  • ntdll.dll!NtResumeThread
  • ntdll.dll!NtSetEvent
  • ntdll.dll!NtSetInformationKey
  • ntdll.dll!NtSetInformationProcess
  • ntdll.dll!NtSetInformationThread
  • ntdll.dll!NtSetInformationVirtualMemory
  • ntdll.dll!NtSetInformationWorkerFactory
  • ntdll.dll!NtSetTimer2
  • ntdll.dll!NtSetTimerEx
  • ntdll.dll!NtSetValueKey
  • ntdll.dll!NtSubscribeWnfStateChange
  • ntdll.dll!NtSuspendThread

40 additional items are not displayed above.

User Data Access
  • GetComputerName
  • GetUserDefaultLocaleName
  • GetUserName
  • GetUserObjectInformation
  • OpenClipboard
Other Suspicious
  • AdjustTokenPrivileges
Encryption Used
  • BCryptOpenAlgorithmProvider
  • CryptAcquireContext
Anti Debug
  • IsDebuggerPresent
  • NtQuerySystemInformation
Network Winsock2
  • WSAConnect
  • WSASocket
  • WSAStartup
  • WSAttemptAutodialName
Network Winsock
  • closesocket
  • freeaddrinfo
  • getaddrinfo
  • recv
  • send
  • setsockopt
Network Winhttp
  • WinHttpOpen
Network Info Queried
  • GetAdaptersAddresses
  • GetNetworkParams
Process Shell Execute
  • CreateProcess

Shell Command Execution

"powershell" -Command Add-MpPreference -ExclusionPath 'C:/'
"powershell" -Command Add-MpPreference -ExclusionPath 'C:/$Recycle.Bin/'
"powershell" -Command Add-MpPreference -ExclusionPath 'C:/$WinREAgent/'
"powershell" -Command Add-MpPreference -ExclusionPath 'C:/Documents and Settings/'
"powershell" -Command Add-MpPreference -ExclusionPath 'C:/PerfLogs/'
Show More
"powershell" -Command Add-MpPreference -ExclusionPath 'C:/Program Files/'
"powershell" -Command Add-MpPreference -ExclusionPath 'C:/Program Files (x86)/'
"powershell" -Command Add-MpPreference -ExclusionPath 'C:/ProgramData/'
"powershell" -Command Add-MpPreference -ExclusionPath 'C:/Recovery/'
"powershell" -Command Add-MpPreference -ExclusionPath 'C:/sandbox_live/'
"powershell" -Command Add-MpPreference -ExclusionPath 'C:/sandbox_local/'
"powershell" -Command Add-MpPreference -ExclusionPath 'C:/sandbox_stage/'
"powershell" -Command Add-MpPreference -ExclusionPath 'C:/startup_test/'
"powershell" -Command Add-MpPreference -ExclusionPath 'C:/System Volume Information/'
"powershell" -Command Add-MpPreference -ExclusionPath 'C:/Users/'
"powershell" -Command Add-MpPreference -ExclusionPath 'C:/Windows/'

Related Posts

Trending

Most Viewed

Loading...