Threat Database Backdoors Backdoor.Zegost.BA

Backdoor.Zegost.BA

By CagedTech in Backdoors

Threat Scorecard

Threat Level: 60 % (Medium)
Infected Computers: 12
First Seen: September 16, 2018
Last Seen: May 14, 2021
OS(es) Affected: Windows

Analysis Report

General information

Family Name: Backdoor.Zegost.BA
Packers: UPX
Signature status: No Signature

Known Samples

MD5: 1953c97029337ec04a8d4b69911d843f
SHA1: 0d2e61439f901e60851d7f4c17dae9b8439f0e66
SHA256: CD8C11EC94B74FD3357E4B9ED00DFB2C1D94D9B1BBA9F6FC4D6C415AA8437B96
File Size: 46.59 KB, 46592 bytes

Windows Portable Executable Attributes

  • File doesn't have "Rich" header
  • File doesn't have debug information
  • File doesn't have exports table
  • File doesn't have relocations information
  • File doesn't have security information
  • File has been packed
  • File is 32-bit executable
  • File is either console or GUI application
  • File is GUI application (IMAGE_SUBSYSTEM_WINDOWS_GUI)
  • File is Native application (NOT .NET application)
Show More
  • IMAGE_FILE_DLL is not set inside PE header (Executable)
  • IMAGE_FILE_EXECUTABLE_IMAGE is set inside PE header (Executable Image)

Windows PE Version Information

Name Value
Company Name Microsoft Corporation
File Description .NET Runtime Optimization Service
File Version 3.0.50727.3053
Internal Name mscorsvw
Legal Copyright Microsoft Corporation. All rights reserved.
Original Filename mscorsvw.exe
Private Build 20150830.01
Product Name Microsoft .NET Framework
Product Version 3.0.50727.3053

File Traits

  • packed
  • x86

Block Information

Total Blocks: 16
Potentially Malicious Blocks: 8
Whitelisted Blocks: 3
Unknown Blocks: 5

Visual Map

x ? ? x x x x ? x ? 0 ? x x 0 0
0 - Probable Safe Block
? - Unknown Block
x - Potentially Malicious Block

Similar Families

  • Zegost.B

Files Modified

File Attributes
c:\windows\microsoft.net\framework\v3.5\mscorsvw.exe Generic Read,Write Data,Write Attributes,Write extended,Append data,Delete,LEFT 262144
c:\windows\microsoft.net\framework\v3.5\mscorsvw.exe Generic Write,Read Attributes
c:\windows\syswow64\10479781.bak Synchronize,Write Data

Registry Modifications

Key::Value Data API Name
HKLM\software\policies\microsoft\windows defender::disableantispyware  RegNtPreCreateKey
HKCU\software\microsoft\windows\currentversion\internet settings\zonemap::proxybypass  RegNtPreCreateKey
HKCU\software\microsoft\windows\currentversion\internet settings\zonemap::intranetname  RegNtPreCreateKey
HKCU\software\microsoft\windows\currentversion\internet settings\zonemap::uncasintranet  RegNtPreCreateKey
HKCU\software\microsoft\windows\currentversion\internet settings\zonemap::autodetect RegNtPreCreateKey
HKCU\software\microsoft\windows\currentversion\internet settings\zonemap::proxybypass  RegNtPreCreateKey
HKCU\software\microsoft\windows\currentversion\internet settings\zonemap::intranetname  RegNtPreCreateKey
HKCU\software\microsoft\windows\currentversion\internet settings\zonemap::uncasintranet  RegNtPreCreateKey
HKCU\software\microsoft\windows\currentversion\internet settings\zonemap::autodetect RegNtPreCreateKey
HKLM\system\controlset001\services\bam\state\usersettings\s-1-5-21-3119368278-1123331430-659265220-1001::\device\harddiskvolume2\windows\system32\conhost.exe ፮征≋ǝ RegNtPreCreateKey
Show More
HKLM\system\controlset001\services\bam\state\usersettings\s-1-5-21-3119368278-1123331430-659265220-1001::\device\harddiskvolume2\windows\system32\conhost.exe 썟徑≋ǝ RegNtPreCreateKey
HKLM\system\controlset001\services\bam\state\usersettings\s-1-5-21-3119368278-1123331430-659265220-1001::\device\harddiskvolume2\windows\system32\conhost.exe 㛝忆≋ǝ RegNtPreCreateKey
HKLM\system\controlset001\services\bam\state\usersettings\s-1-5-21-3119368278-1123331430-659265220-1001::\device\harddiskvolume2\windows\system32\conhost.exe 顆忧≋ǝ RegNtPreCreateKey
HKLM\system\controlset001\services\bam\state\usersettings\s-1-5-21-3119368278-1123331430-659265220-1001::\device\harddiskvolume2\windows\system32\conhost.exe Ṧ怯≋ǝ RegNtPreCreateKey
HKLM\system\controlset001\services\bam\state\usersettings\s-1-5-21-3119368278-1123331430-659265220-1001::\device\harddiskvolume2\windows\system32\conhost.exe ܺ恹≋ǝ RegNtPreCreateKey
HKLM\system\controlset001\services\bam\state\usersettings\s-1-5-21-3119368278-1123331430-659265220-1001::\device\harddiskvolume2\windows\system32\conhost.exe 跭惀≋ǝ RegNtPreCreateKey
HKLM\software\policies\microsoft\windows\ipsec\policy\local\ipsecisakmppolicy{5caea1ff-4947-42b4-8372-7cc94cf7cf72}::classname ipsecISAKMPPolicy RegNtPreCreateKey
HKLM\software\policies\microsoft\windows\ipsec\policy\local\ipsecisakmppolicy{5caea1ff-4947-42b4-8372-7cc94cf7cf72}::name ipsecISAKMPPolicy{5caea1ff-4947-42b4-8372-7cc94cf7cf72} RegNtPreCreateKey
HKLM\software\policies\microsoft\windows\ipsec\policy\local\ipsecfilter{1f01df2a-e3a6-40a4-b818-619ae6efe74d}::classname ipsecFilter RegNtPreCreateKey
HKLM\software\policies\microsoft\windows\ipsec\policy\local\ipsecfilter{1f01df2a-e3a6-40a4-b818-619ae6efe74d}::name ipsecFilter{1f01df2a-e3a6-40a4-b818-619ae6efe74d} RegNtPreCreateKey
HKLM\software\policies\microsoft\windows\ipsec\policy\local\ipsecfilter{1f01df2a-e3a6-40a4-b818-619ae6efe74d}::ipsecname Filter1 RegNtPreCreateKey
HKLM\software\policies\microsoft\windows\ipsec\policy\local\ipsecfilter{1f01df2a-e3a6-40a4-b818-619ae6efe74d}::ipsecid {1f01df2a-e3a6-40a4-b818-619ae6efe74d} RegNtPreCreateKey
HKLM\software\policies\microsoft\windows\ipsec\policy\local\ipsecfilter{1f01df2a-e3a6-40a4-b818-619ae6efe74d}::ipsecdatatype Ā RegNtPreCreateKey
HKLM\software\policies\microsoft\windows\ipsec\policy\local\ipsecfilter{1f01df2a-e3a6-40a4-b818-619ae6efe74d}::ipsecdata ₵胜⻈ᇑ麨ꀀ贤ℰ RegNtPreCreateKey
HKLM\software\policies\microsoft\windows\ipsec\policy\local\ipsecfilter{1f01df2a-e3a6-40a4-b818-619ae6efe74d}::whenchanged 橮 RegNtPreCreateKey
HKLM\software\policies\microsoft\windows\ipsec\policy\local\ipsecfilter{1f01df2a-e3a6-40a4-b818-619ae6efe74d}::classname ipsecFilter RegNtPreCreateKey
HKLM\software\policies\microsoft\windows\ipsec\policy\local\ipsecfilter{1f01df2a-e3a6-40a4-b818-619ae6efe74d}::name ipsecFilter{1f01df2a-e3a6-40a4-b818-619ae6efe74d} RegNtPreCreateKey
HKLM\software\policies\microsoft\windows\ipsec\policy\local\ipsecfilter{1f01df2a-e3a6-40a4-b818-619ae6efe74d}::ipsecname Filter1 RegNtPreCreateKey
HKLM\software\policies\microsoft\windows\ipsec\policy\local\ipsecfilter{1f01df2a-e3a6-40a4-b818-619ae6efe74d}::ipsecid {1f01df2a-e3a6-40a4-b818-619ae6efe74d} RegNtPreCreateKey
HKLM\software\policies\microsoft\windows\ipsec\policy\local\ipsecfilter{1f01df2a-e3a6-40a4-b818-619ae6efe74d}::ipsecdatatype Ā RegNtPreCreateKey
HKLM\software\policies\microsoft\windows\ipsec\policy\local\ipsecfilter{1f01df2a-e3a6-40a4-b818-619ae6efe74d}::ipsecdata ₵胜⻈ᇑ麨ꀀ贤ℰF⿝唪ϔ䧌ꊾ뇲ᆰ䎈￿￿‹ RegNtPreCreateKey
HKLM\software\policies\microsoft\windows\ipsec\policy\local\ipsecfilter{1f01df2a-e3a6-40a4-b818-619ae6efe74d}::whenchanged 橮 RegNtPreCreateKey
HKLM\software\policies\microsoft\windows\ipsec\policy\local\ipsecfilter{1f01df2a-e3a6-40a4-b818-619ae6efe74d}::classname ipsecFilter RegNtPreCreateKey
HKLM\software\policies\microsoft\windows\ipsec\policy\local\ipsecfilter{1f01df2a-e3a6-40a4-b818-619ae6efe74d}::name ipsecFilter{1f01df2a-e3a6-40a4-b818-619ae6efe74d} RegNtPreCreateKey
HKLM\software\policies\microsoft\windows\ipsec\policy\local\ipsecfilter{1f01df2a-e3a6-40a4-b818-619ae6efe74d}::ipsecname Filter1 RegNtPreCreateKey
HKLM\software\policies\microsoft\windows\ipsec\policy\local\ipsecfilter{1f01df2a-e3a6-40a4-b818-619ae6efe74d}::ipsecid {1f01df2a-e3a6-40a4-b818-619ae6efe74d} RegNtPreCreateKey
HKLM\software\policies\microsoft\windows\ipsec\policy\local\ipsecfilter{1f01df2a-e3a6-40a4-b818-619ae6efe74d}::ipsecdatatype Ā RegNtPreCreateKey
HKLM\software\policies\microsoft\windows\ipsec\policy\local\ipsecfilter{1f01df2a-e3a6-40a4-b818-619ae6efe74d}::ipsecdata ₵胜⻈ᇑ麨ꀀ贤ℰŒ⿝唪ϔ䧌ꊾ뇲ᆰ䎈￿￿‹䂫敜꬯䄲瞝䩟ꮱ￿￿ƽ RegNtPreCreateKey
HKLM\software\policies\microsoft\windows\ipsec\policy\local\ipsecfilter{1f01df2a-e3a6-40a4-b818-619ae6efe74d}::whenchanged 橮 RegNtPreCreateKey
HKLM\software\policies\microsoft\windows defender::disableantispyware  RegNtPreCreateKey
HKLM\system\controlset001\control\session manager::pendingfilerenameoperations *1\??\C:\Windows\SystemTemp\MicrosoftEdgeUpdate.exe.old5af52*1\??\C:\Windows\SystemTemp\CopilotUpdate.exe.old5af62*1\??\C:\P RegNtPreCreateKey
HKLM\software\microsoft\windows nt\currentversion\notifications\data::418a073aa3bc3475 �� * �/��Y�d�kP~� ��ރ�p��^�o�ee�Vs}3kP~3��1��7 ���ﺃdB F eHe��(P��1n��fe��i RegNtPreCreateKey

Windows API Usage

Category API
Anti Debug
  • IsDebuggerPresent
  • NtQuerySystemInformation
User Data Access
  • GetUserObjectInformation
Process Manipulation Evasion
  • NtUnmapViewOfSection
Process Shell Execute
  • ShellExecute
Syscall Use
  • ntdll.dll!NtAccessCheck
  • ntdll.dll!NtAlertThreadByThreadId
  • ntdll.dll!NtAlpcSendWaitReceivePort
  • ntdll.dll!NtApphelpCacheControl
  • ntdll.dll!NtClearEvent
  • ntdll.dll!NtClose
  • ntdll.dll!NtConnectPort
  • ntdll.dll!NtCreateEvent
  • ntdll.dll!NtCreateFile
  • ntdll.dll!NtCreateMutant
Show More
  • ntdll.dll!NtCreateSection
  • ntdll.dll!NtCreateSemaphore
  • ntdll.dll!NtDuplicateObject
  • ntdll.dll!NtDuplicateToken
  • ntdll.dll!NtEnumerateValueKey
  • ntdll.dll!NtFreeVirtualMemory
  • ntdll.dll!NtMapViewOfSection
  • ntdll.dll!NtOpenFile
  • ntdll.dll!NtOpenKey
  • ntdll.dll!NtOpenKeyEx
  • ntdll.dll!NtOpenProcessToken
  • ntdll.dll!NtOpenProcessTokenEx
  • ntdll.dll!NtOpenSection
  • ntdll.dll!NtOpenSemaphore
  • ntdll.dll!NtOpenThreadTokenEx
  • ntdll.dll!NtProtectVirtualMemory
  • ntdll.dll!NtQueryAttributesFile
  • ntdll.dll!NtQueryInformationProcess
  • ntdll.dll!NtQueryInformationThread
  • ntdll.dll!NtQueryInformationToken
  • ntdll.dll!NtQueryKey
  • ntdll.dll!NtQueryPerformanceCounter
  • ntdll.dll!NtQuerySecurityAttributesToken
  • ntdll.dll!NtQueryValueKey
  • ntdll.dll!NtQueryVirtualMemory
  • ntdll.dll!NtQueryVolumeInformationFile
  • ntdll.dll!NtQueryWnfStateData
  • ntdll.dll!NtReleaseMutant
  • ntdll.dll!NtReleaseSemaphore
  • ntdll.dll!NtReleaseWorkerFactoryWorker
  • ntdll.dll!NtRequestWaitReplyPort
  • ntdll.dll!NtSetEvent
  • ntdll.dll!NtSetInformationProcess
  • ntdll.dll!NtSetInformationVirtualMemory
  • ntdll.dll!NtSetInformationWorkerFactory
  • ntdll.dll!NtSubscribeWnfStateChange
  • ntdll.dll!NtTestAlert
  • ntdll.dll!NtTraceControl
  • ntdll.dll!NtUnmapViewOfSection
  • ntdll.dll!NtUnmapViewOfSectionEx
  • ntdll.dll!NtWaitForAlertByThreadId
  • ntdll.dll!NtWaitForSingleObject
  • ntdll.dll!NtWaitForWorkViaWorkerFactory
  • ntdll.dll!NtWaitLowEventPair
  • ntdll.dll!NtWorkerFactoryWorkerReady
  • ntdll.dll!NtWriteFile
  • UNKNOWN
Network Winsock2
  • WSAStartup
Service Control
  • OpenSCManager
  • OpenService
  • StartService
Encryption Used
  • BCryptOpenAlgorithmProvider
Process Terminate
  • TerminateProcess

Shell Command Execution

open netsh.exe advfirewall firewall add rule name="Microsoft.Net" dir=out program="C:\Windows\Microsoft.NET\Framework\v3.5\mscorsvw.exe" action=allow
open netsh.exe advfirewall firewall add rule name="Microsoft.Net" dir=in program="C:\Windows\Microsoft.NET\Framework\v3.5\mscorsvw.exe" action=allow
open netsh.exe ipsec static add policy name=Block
open netsh.exe ipsec static add filterlist name=Filter1
open netsh.exe ipsec static add filter filterlist=Filter1 srcaddr=any dstaddr=Me dstport=135 protocol=TCP
Show More
open netsh.exe ipsec static add filter filterlist=Filter1 srcaddr=any dstaddr=Me dstport=139 protocol=TCP
open netsh.exe ipsec static add filter filterlist=Filter1 srcaddr=any dstaddr=Me dstport=445 protocol=TCP
open netsh.exe ipsec static add filteraction name=FilteraAtion1 action=block
open netsh.exe ipsec static add rule name=Rule1 policy=Block filterlist=Filter1 filteraction=FilteraAtion1
open netsh.exe ipsec static set policy name=Block assign=y