Threat Database Backdoors Backdoor.Simbot.C

Backdoor.Simbot.C

By CagedTech in Backdoors

Threat Scorecard

Popularity Rank: 14,209
Threat Level: 60 % (Medium)
Infected Computers: 41
First Seen: June 1, 2019
Last Seen: August 7, 2026
OS(es) Affected: Windows

Analysis Report

General information

Family Name: Backdoor.Simbot.C
Signature status: No Signature

Known Samples

MD5: 77f455d8080a654f2a98bda13113f082
SHA1: 98d242cb9200dfab99bd733673f0c618cd8d188f
SHA256: 9FC26C77AC81D3BEA0C64A6BD2F05185A789D9BD4D5ED5A2B1B51EF82E45382E
File Size: 32.77 KB, 32768 bytes

Windows Portable Executable Attributes

  • File doesn't have "Rich" header
  • File doesn't have debug information
  • File doesn't have relocations information
  • File doesn't have security information
  • File has exports table
  • File is 32-bit executable
  • File is either console or GUI application
  • File is GUI application (IMAGE_SUBSYSTEM_WINDOWS_GUI)
  • File is Native application (NOT .NET application)
  • File is not packed
Show More
  • IMAGE_FILE_DLL is not set inside PE header (Executable)
  • IMAGE_FILE_EXECUTABLE_IMAGE is set inside PE header (Executable Image)

Windows PE Version Information

Name Value
Company Name Adobe Systems, Inc.
File Description Adobe? Flash? Player Installer/Uninstaller 10.1 r53
File Version 10,1,53,64
Internal Name Adobe? Flash? Player Installer/Uninstaller 10.1
Legal Copyright Copyright ? 1996-2010 Adobe, Inc.
Legal Trademarks Adobe? Flash? Player
Original Filename FlashUtil.exe
Product Name Flash? Player Installer/Uninstaller
Product Version 10,1,53,64

File Traits

  • HighEntropy
  • Installer Version
  • x86

Block Information

Total Blocks: 23
Potentially Malicious Blocks: 12
Whitelisted Blocks: 9
Unknown Blocks: 2

Visual Map

x x x x x x 0 0 ? x x 0 x ? x x x 0 0 0 0 1 1
0 - Probable Safe Block
? - Unknown Block
x - Potentially Malicious Block

Similar Families

  • Clicker.Small.A

Files Modified

File Attributes
\device\namedpipe\gmdasllogger Generic Write,Read Attributes
c:\users\user\appdata\local\mapsbroker.exe Generic Read,Write Data,Write Attributes,Write extended,Append data
c:\users\user\appdata\local\mapsbroker.exe Generic Read,Write Data,Write Attributes,Write extended,Append data,Delete,LEFT 262144
c:\users\user\appdata\local\mapsbroker.exe Synchronize,Write Data
c:\users\user\appdata\local\rcx3001.tmp Generic Read,Write Data,Write Attributes,Write extended,Append data
c:\users\user\appdata\local\temp\~da3000.tmp Synchronize,Write Data
c:\users\user\appdata\local\temp\~dfds3.reg Generic Read,Write Data,Write Attributes,Write extended,Append data
c:\users\user\appdata\roaming\microsoft\crypto\rsa\s-1-5-21-3119368278-1123331430-659265220-1001\ad85b89389a00dfe9034f6cd719fd54f_bfeb5820-9643-42ad-a79f-071dff4d8e64 Generic Write,Read Attributes

Registry Modifications

Key::Value Data API Name
HKCU\software\microsoft\windows\currentversion\run::mapsbroker C:\Users\Enyjfjvr\AppData\Local\MapsBroker.exe RegNtPreCreateKey
HKLM\system\controlset001\control\session manager::pendingfilerenameoperations *1\??\C:\Windows\SystemTemp\MicrosoftEdgeUpdate.exe.old5af52*1\??\C:\Windows\SystemTemp\CopilotUpdate.exe.old5af62*1\??\C:\P RegNtPreCreateKey

Windows API Usage

Category API
Service Control
  • OpenSCManager
Encryption Used
  • BCryptOpenAlgorithmProvider
  • CryptAcquireContext
Process Manipulation Evasion
  • NtUnmapViewOfSection
Process Shell Execute
  • WinExec

Shell Command Execution

regedit.exe /s C:\Users\Enyjfjvr\AppData\Local\Temp\~dfds3.reg