Small AB

By GoldSparrow in Trojans
Translate To:

Small AB is a downloader Trojan that infiltrates a computer through system vulnerabilities. Once Small AB is active inside the computer, it typically downloads additional malware onto the system. Small AB may also lead to identity theft, increase the chance of hacker botnets and bombard the compromised machine with annoying popup windows.

File System Details

Small AB may create the following file(s):
# File Name Detections
1. virtue_4975317

Analysis Report

General information

Family Name: Trojan.Small.AB
Signature status: No Signature

Known Samples

MD5: 1f982d2737cacbe0061aa9df8f4d0ef0
SHA1: d452381de8c9bcf2bdad995210eabe25f3a9329d
SHA256: DCB69F52D2DBEBB00504D486243BD7A07A9896620A4FA182879BD3D78099E780
File Size: 406.02 KB, 406016 bytes
MD5: 8adfef7c2e1f0a88d91f4f617143797e
SHA1: 583484caa9eba5cba77b073886d88b51e928d6b2
SHA256: 95D90C5597A497E855973DD68CC3AEEA63D3589740F017BEB94AD8D1E0A9956C
File Size: 172.54 KB, 172544 bytes

Windows Portable Executable Attributes

  • File doesn't have "Rich" header
  • File doesn't have debug information
  • File doesn't have exports table
  • File doesn't have relocations information
  • File doesn't have security information
  • File is 32-bit executable
  • File is either console or GUI application
  • File is GUI application (IMAGE_SUBSYSTEM_WINDOWS_GUI)
  • File is Native application (NOT .NET application)
  • File is not packed
Show More
  • IMAGE_FILE_DLL is not set inside PE header (Executable)
  • IMAGE_FILE_EXECUTABLE_IMAGE is set inside PE header (Executable Image)

File Icons

Windows PE Version Information

Name Value
Comments Website: http://www.ACAPsoft.com EMail: Support@ACAPsoft.com
Company Name ACAPsoft
File Description GigAlarm: Desktop Alarm and Scheduler
File Version 1.32
Internal Name GigAlarm
Legal Copyright Copyright © Andrew J Glina 2000-2009
Mailing Address PO Box 1669 GPO Hobart 7001 Tas Australia
Original Filename GigAlarm.exe
Product Name GigAlarm
Product Version 1.32

File Traits

  • HighEntropy
  • No Version Info
  • WriteProcessMemory
  • x86

Block Information

Total Blocks: 293
Potentially Malicious Blocks: 20
Whitelisted Blocks: 31
Unknown Blocks: 242

Visual Map

? ? ? x ? ? ? ? ? ? ? ? ? ? ? ? ? ? ? ? ? ? ? ? ? ? ? ? ? ? ? ? ? ? ? ? ? ? ? ? ? ? ? ? ? ? ? ? ? ? ? ? ? ? ? ? ? ? ? ? ? ? ? ? ? ? ? ? ? ? ? x ? ? ? ? ? ? ? ? ? ? ? ? ? ? ? ? ? ? ? ? ? ? 0 ? ? ? ? ? ? ? ? ? ? ? ? ? ? ? ? ? ? ? ? ? ? ? ? ? ? ? ? ? ? ? ? ? ? ? ? ? ? ? ? ? ? ? ? ? ? ? ? ? ? ? ? ? ? ? ? ? 0 ? ? ? ? ? ? ? ? ? ? ? ? ? ? ? ? ? 0 x 0 ? ? ? ? 0 x 0 ? ? 0 x 0 ? ? ? 0 x 0 ? ? ? ? ? ? 0 x 0 ? ? ? 0 x 0 ? ? ? 0 x 0 ? ? ? ? ? 0 ? 0 ? ? ? ? ? ? ? ? ? ? 0 ? ? ? ? ? ? ? ? ? ? ? ? ? ? ? ? ? ? ? ? ? ? ? ? ? ? ? ? ? ? ? ? 0 ? ? ? ? ? ? x 0 0 0 0 x x x 0 0 0 x ? x x x 0 x x 0 0 x 0
0 - Probable Safe Block
? - Unknown Block
x - Potentially Malicious Block

Similar Families

  • Small.AB

Trending

Most Viewed

Loading...