Threat Database Backdoors Backdoor.Zegost.AO

Backdoor.Zegost.AO

By CagedTech in Backdoors

Threat Scorecard

Popularity Rank: 8,866
Threat Level: 60 % (Medium)
Infected Computers: 183
First Seen: January 11, 2022
Last Seen: October 26, 2025
OS(es) Affected: Windows

Analysis Report

General information

Family Name: Backdoor.Zegost.AO
Signature status: No Signature

Known Samples

MD5: ef059956b38a7721def2f44b8d690298
SHA1: 22998b791e81a4d3decf8449206defffd0f6baf4
SHA256: B4695F6F2FCAC60CDF65C417C7245C0A478D7C926B0A304B7C069EBBEC9CDF67
File Size: 2.07 MB, 2067019 bytes

Windows Portable Executable Attributes

  • File doesn't have "Rich" header
  • File doesn't have debug information
  • File doesn't have exports table
  • File doesn't have relocations information
  • File doesn't have security information
  • File is 32-bit executable
  • File is either console or GUI application
  • File is GUI application (IMAGE_SUBSYSTEM_WINDOWS_GUI)
  • File is Native application (NOT .NET application)
  • File is not packed
Show More
  • IMAGE_FILE_DLL is not set inside PE header (Executable)
  • IMAGE_FILE_EXECUTABLE_IMAGE is set inside PE header (Executable Image)

File Icons

File Traits

  • .adata
  • 2+ executable sections
  • big overlay
  • HighEntropy
  • No Version Info
  • x86

Block Information

Total Blocks: 19
Potentially Malicious Blocks: 10
Whitelisted Blocks: 4
Unknown Blocks: 5

Visual Map

0 x x 0 0 0 x x x x x x x x ? ? ? ? ?
0 - Probable Safe Block
? - Unknown Block
x - Potentially Malicious Block

Similar Families

  • Zegost.AO
  • Zegost.SC

Files Modified

File Attributes
c:\users\user\appdata\local\.# Synchronize,Write Attributes
c:\users\user\appdata\local\.#\mbx@1c0@3ca1890.### Generic Write,Read Attributes
c:\users\user\downloads\22998b791e81a4d3decf8449206defffd0f6baf4_0002067019-up.txt Generic Write,Read Attributes

Trending

Most Viewed

Loading...