Threat Database Backdoors Backdoor.Zegost.CP

Backdoor.Zegost.CP

By CagedTech in Backdoors

Threat Scorecard

Popularity Rank: 8,236
Threat Level: 60 % (Medium)
Infected Computers: 58
First Seen: December 16, 2022
Last Seen: July 12, 2026
OS(es) Affected: Windows

The detection of Backdoor.Zegost.CP on your system indicates a potential security threat that requires immediate attention. This backdoor threat can compromise your system's security and allow unauthorized access to your data. It is essential to understand the nature of this threat and take prompt action to remove it and prevent future infections.

What Is Backdoor.Zegost.CP?

Backdoor.Zegost.CP is a type of malware that creates a secret entrance to your system, allowing hackers to access and control your computer remotely. This backdoor can be used to steal sensitive information, install additional malware, or use your system for malicious activities. The name Backdoor.Zegost.CP suggests that it is a backdoor threat, but the exact nature and behavior of this malware can vary.

How Backdoor.Zegost.CP Operates

Backdoor.Zegost.CP operates by creating a covert communication channel between your system and a remote server controlled by the attackers. This channel can be used to transmit stolen data, receive instructions, or upload additional malware. The backdoor can be installed on your system through various means, such as exploited vulnerabilities, infected software downloads, or phishing attacks. Once installed, the backdoor can remain dormant, waiting for instructions from the attackers, or it can start transmitting data immediately.

Symptoms of Infection

The symptoms of a Backdoor.Zegost.CP infection can be subtle, but they may include unusual system behavior, such as slow performance, unexpected crashes, or unfamiliar programs running in the background. You may also notice suspicious network activity, such as unusual outgoing connections or data transfers. In some cases, the backdoor may not exhibit any noticeable symptoms, making it difficult to detect without proper security tools.

  • Unexplained changes to system settings or configuration
  • Appearance of unfamiliar programs or icons
  • Increased system crashes or instability
  • Unusual network activity or data transfers

How to Remove Backdoor.Zegost.CP

  1. Boot your system in Safe Mode with Networking to prevent the backdoor from loading and to allow for easier removal.
  2. Perform a full scan of your system using a reputable anti-malware tool, such as SpyHunter, to detect and remove the backdoor and any associated malware.
  3. Uninstall any suspicious programs or applications that may be related to the backdoor.
  4. Reset your web browsers, such as Chrome, Firefox, or Edge, to their default settings to remove any malicious extensions or add-ons.
  5. Reboot your system and perform another full scan to ensure that the backdoor and any associated malware have been completely removed.

Conclusion

Removing Backdoor.Zegost.CP from your system requires careful attention to detail and a thorough understanding of the removal process. By following the steps outlined above and using reputable security tools, you can help ensure the complete removal of the backdoor and prevent future infections. It is essential to remain vigilant and continue to monitor your system for any signs of malicious activity, as the threat landscape is constantly evolving. By taking proactive measures to protect your system and data, you can help prevent the spread of malware and maintain a secure online environment.

Analysis Report

General information

Family Name: Backdoor.Zegost.CP
Signature status: No Signature

Known Samples

MD5: f4bb183e98cc45b9b78512a875127ea0
SHA1: 4f6bd427c450c61f638b2ee3a080561b0d38fd9a
SHA256: 0D6B53A9B9C2ED4930C64DA2D5EE069F44DC6049080B0BAAF26715AA4BB7E28F
File Size: 1.48 MB, 1475507 bytes
MD5: 9ac028ea7a2bc5d93fe1cc27bd231bab
SHA1: c4fc02bcb2ec1806eda5bb20ddd9077bbad43284
SHA256: BD2A06D8AC828A18230DEAEA1392FA2AD6C9D6175665896D871A4B2FC1FF15B7
File Size: 6.44 MB, 6444544 bytes
MD5: 17bde8e430faedf5afd68540d6e69114
SHA1: 1692d4a204c9d51b01464acb65bbe1bff4b423d6
SHA256: 3D6948DD4B1C77D9C7CD86BACB851A7A1F149EC500F4DE18E72FCBDDC4123DAC
File Size: 2.14 MB, 2136576 bytes
MD5: aab5ee93c9208e92d0d3edafc583ebd2
SHA1: a917dae5f02236c5258168d71a9e99517dab1ce2
SHA256: 810D775F860292CC6C67BA8485E3AF801EBCFCE97E8660B4310233BD741552E8
File Size: 3.88 MB, 3884544 bytes

Windows Portable Executable Attributes

  • File doesn't have "Rich" header
  • File doesn't have debug information
  • File doesn't have relocations information
  • File doesn't have security information
  • File has been packed
  • File has exports table
  • File has TLS information
  • File is 32-bit executable
  • File is console application (IMAGE_SUBSYSTEM_WINDOWS_CUI)
  • File is either console or GUI application
Show More
  • File is GUI application (IMAGE_SUBSYSTEM_WINDOWS_GUI)
  • File is Native application (NOT .NET application)
  • File is not packed
  • IMAGE_FILE_DLL is not set inside PE header (Executable)
  • IMAGE_FILE_EXECUTABLE_IMAGE is set inside PE header (Executable Image)

Windows PE Version Information

Name Value
Company Name
  • Bettini S.r.l.
  • 广州南方卫星导航仪器有限公司
File Description
  • EncodeCmrRtcm40 动态链接库
  • GamsSDK
File Version
  • 5.14.0.4
  • 04.00.181217.190819
Internal Name EncodeCmrRtcm40.dll
Legal Copyright
  • Bettini S.r.l. © 2020
  • 广州南方卫星导航仪器有限公司
Original Filename
  • EncodeCmrRtcm40.dll
  • GamsSDK
Product Name
  • EncodeCmrRtcm40 动态链接库
  • GamsSDK
Product Version
  • 5.14.0.4
  • 04.00.181217.190819

File Traits

  • 2+ executable sections
  • dll
  • GetConsoleWindow
  • HighEntropy
  • imgui
  • WriteProcessMemory
  • x86

Block Information

Total Blocks: 18,891
Potentially Malicious Blocks: 168
Whitelisted Blocks: 8,897
Unknown Blocks: 9,826

Visual Map

0 0 x 0 x x 0 0 x x x 0 0 0 0 0 0 0 0 0 ? 0 0 ? 0 0 0 0 0 0 0 0 0 ? ? 0 0 0 0 ? ? 0 0 0 x 0 0 0 0 0 0 0 ? 0 0 ? x x ? ? ? x x x 1 0 ? 0 ? x x ? 0 ? 0 ? 0 ? x ? x ? 0 x ? ? ? ? ? 0 ? ? x ? ? ? ? x 0 0 0 ? ? ? x 0 ? ? 0 ? 0 ? 0 ? 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 ? ? ? ? ? ? 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 2 2 2 2 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 ? 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 1 0 0 0 0 1 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 1 1 0 0 1 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 1 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 1 1 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 2 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 1 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 1 0 1 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0
... Data truncated
0 - Probable Safe Block
? - Unknown Block
x - Potentially Malicious Block

Similar Families

  • Agent.AG
  • Injector.KLH
  • Kryptik.FGH
  • KuwanBar.B
  • Loader.DE
Show More
  • Redline.FAD
  • ShellcodeRunner.FN
  • Tiggre.D

Files Modified

File Attributes
\device\namedpipe\pecmd_exec_2808465827 Generic Read,Write Data,Write Attributes,Write extended,Append data
\device\namedpipe\pecmd_exec_3950548354 Generic Read,Write Data,Write Attributes,Write extended,Append data
c:\users\user\appdata\local\temp\~7034987983102780497~ Synchronize,Write Attributes
c:\users\user\appdata\local\temp\~7034987983102780497~\sg.tmp Generic Read,Write Data,Write Attributes,Write extended,Append data
c:\users\user\appdata\local\temp\~7441065651117610322.tmp Generic Read,Write Data,Write Attributes,Write extended,Append data
c:\users\user\appdata\local\temp\~7441065651117610322.tmp Synchronize,Write Attributes
c:\users\user\appdata\local\temp\~~5308915487522014528.tmp Generic Read,Write Data,Write Attributes,Write extended,Append data

Registry Modifications

Key::Value Data API Name
HKLM\system\controlset001\services\bam\state\usersettings\s-1-5-21-3119368278-1123331430-659265220-1001::\device\harddiskvolume2\windows\system32\cmd.exe 渘頒平ǜ RegNtPreCreateKey
HKLM\system\controlset001\services\bam\state\usersettings\s-1-5-21-3119368278-1123331430-659265220-1001::\device\harddiskvolume2\windows\system32\conhost.exe 胪頥平ǜ RegNtPreCreateKey
HKLM\system\controlset001\services\bam\state\usersettings\s-1-5-21-3119368278-1123331430-659265220-1001::\device\harddiskvolume2\windows\system32\conhost.exe ઇ駕平ǜ RegNtPreCreateKey
HKCU\software\microsoft\windows\currentversion\run::4f6bd427c450c61f638b2ee3a080561b0d38fd9a_0001475507 "c:\users\user\downloads\4f6bd427c450c61f638b2ee3a080561b0d38fd9a_0001475507" RegNtPreCreateKey
HKCU\software\microsoft\windows\currentversion\run::sersggr.exe "C:\Users\Xnxtluju\AppData\Local\Temp\~1402272459599668064\sersggr.exe" RegNtPreCreateKey

Windows API Usage

Category API
Other Suspicious
  • AdjustTokenPrivileges
Process Manipulation Evasion
  • NtUnmapViewOfSection
Process Shell Execute
  • CreateProcess
Syscall Use
  • ntdll.dll!NtAccessCheck
  • ntdll.dll!NtAlertThreadByThreadId
  • ntdll.dll!NtAlpcSendWaitReceivePort
  • ntdll.dll!NtApphelpCacheControl
  • ntdll.dll!NtClearEvent
  • ntdll.dll!NtClose
  • ntdll.dll!NtConnectPort
  • ntdll.dll!NtCreateEvent
  • ntdll.dll!NtCreateFile
  • ntdll.dll!NtCreateMutant
Show More
  • ntdll.dll!NtCreateSection
  • ntdll.dll!NtCreateSemaphore
  • ntdll.dll!NtDeviceIoControlFile
  • ntdll.dll!NtDuplicateObject
  • ntdll.dll!NtDuplicateToken
  • ntdll.dll!NtEnumerateValueKey
  • ntdll.dll!NtFreeVirtualMemory
  • ntdll.dll!NtMapViewOfSection
  • ntdll.dll!NtOpenFile
  • ntdll.dll!NtOpenKey
  • ntdll.dll!NtOpenKeyEx
  • ntdll.dll!NtOpenProcessToken
  • ntdll.dll!NtOpenProcessTokenEx
  • ntdll.dll!NtOpenSection
  • ntdll.dll!NtOpenSemaphore
  • ntdll.dll!NtOpenThread
  • ntdll.dll!NtOpenThreadTokenEx
  • ntdll.dll!NtProtectVirtualMemory
  • ntdll.dll!NtQueryAttributesFile
  • ntdll.dll!NtQueryDebugFilterState
  • ntdll.dll!NtQueryDirectoryFileEx
  • ntdll.dll!NtQueryInformationProcess
  • ntdll.dll!NtQueryInformationThread
  • ntdll.dll!NtQueryInformationToken
  • ntdll.dll!NtQueryKey
  • ntdll.dll!NtQueryPerformanceCounter
  • ntdll.dll!NtQuerySecurityAttributesToken
  • ntdll.dll!NtQuerySystemInformationEx
  • ntdll.dll!NtQueryValueKey
  • ntdll.dll!NtQueryVirtualMemory
  • ntdll.dll!NtQueryVolumeInformationFile
  • ntdll.dll!NtQueryWnfStateData
  • ntdll.dll!NtReadFile
  • ntdll.dll!NtReleaseMutant
  • ntdll.dll!NtReleaseSemaphore
  • ntdll.dll!NtReleaseWorkerFactoryWorker
  • ntdll.dll!NtRequestWaitReplyPort
  • ntdll.dll!NtSetEvent
  • ntdll.dll!NtSetInformationFile
  • ntdll.dll!NtSetInformationProcess
  • ntdll.dll!NtSetInformationVirtualMemory
  • ntdll.dll!NtSetInformationWorkerFactory
  • ntdll.dll!NtSubscribeWnfStateChange
  • ntdll.dll!NtTerminateProcess
  • ntdll.dll!NtTestAlert
  • ntdll.dll!NtTraceControl
  • ntdll.dll!NtUnmapViewOfSection
  • ntdll.dll!NtUnmapViewOfSectionEx
  • ntdll.dll!NtWaitForAlertByThreadId
  • ntdll.dll!NtWaitForSingleObject
  • ntdll.dll!NtWaitForWorkViaWorkerFactory
  • ntdll.dll!NtWaitLowEventPair
  • ntdll.dll!NtWorkerFactoryWorkerReady
  • ntdll.dll!NtWriteFile
  • UNKNOWN
Anti Debug
  • IsDebuggerPresent
  • NtQuerySystemInformation
User Data Access
  • GetUserObjectInformation
Process Terminate
  • TerminateProcess

Shell Command Execution

cmd.exe /c set
c:\users\user\downloads\4f6bd427c450c61f638b2ee3a080561b0d38fd9a_0001475507 PECMD**pecmd-cmd* PUTF -dd -skipb=1060864 -len=414338 "C:\Users\Xnxtluju\AppData\Local\Temp\~7441065651117610322.tmp",,c:\users\user\downloads\4f6bd427c450c61f638b2ee3a080561b0d38fd9a_0001475507
C:\Users\Xnxtluju\AppData\Local\Temp\~7034987983102780497~\sg.tmp 7zG_exe x "C:\Users\Xnxtluju\AppData\Local\Temp\~7441065651117610322.tmp" -y -aoa -o"C:\Users\Xnxtluju\AppData\Local\Temp\~1402272459599668064"
"C:\Users\Xnxtluju\AppData\Local\Temp\~1402272459599668064\sersggr.exe"
C:\WINDOWS\SysWOW64\rundll32.exe C:\WINDOWS\system32\rundll32.exe c:\users\user\downloads\c4fc02bcb2ec1806eda5bb20ddd9077bbad43284_0006444544.,LiQMAxHB
Show More
C:\WINDOWS\SysWOW64\rundll32.exe C:\WINDOWS\system32\rundll32.exe c:\users\user\downloads\1692d4a204c9d51b01464acb65bbe1bff4b423d6_0002136576.,LiQMAxHB
C:\WINDOWS\SysWOW64\rundll32.exe C:\WINDOWS\system32\rundll32.exe c:\users\user\downloads\a917dae5f02236c5258168d71a9e99517dab1ce2_0003884544.,LiQMAxHB

Related Posts

Trending

Most Viewed

Loading...