Threat Database Trojans Trojan.Agent.DRTB

Trojan.Agent.DRTB

By CagedTech in Trojans

Analysis Report

General information

Family Name: Trojan.Agent.DRTB
Signature status: No Signature

Known Samples

MD5: fd0a03da9923bea32c27d136fb9f500e
SHA1: 191939007e5201c3de51e2e8e79391039ef6504a
SHA256: 5E50ACEB7189D8ADA3016AAABC4E1B0264698B9A37AA0FD15FF7B08B4E566BFC
File Size: 1.68 MB, 1680896 bytes

Windows Portable Executable Attributes

  • File doesn't have "Rich" header
  • File doesn't have security information
  • File has exports table
  • File has TLS information
  • File is 32-bit executable
  • File is either console or GUI application
  • File is GUI application (IMAGE_SUBSYSTEM_WINDOWS_GUI)
  • File is Native application (NOT .NET application)
  • File is not packed
  • IMAGE_FILE_DLL is not set inside PE header (Executable)
Show More
  • IMAGE_FILE_EXECUTABLE_IMAGE is set inside PE header (Executable Image)

Windows PE Version Information

Name Value
Company Name Microsoft Corporation
File Description Photo Acquisition
File Version 10.0.22598.1 (WinBuild.160101.0800)
Internal Name PhotoAcq
Legal Copyright © Microsoft Corporation. All rights reserved.
Original Filename PhotoAcq.dll
Product Name Microsoft® Windows® Operating System
Product Version 10.0.22598.1

File Traits

  • dll
  • x86

Block Information

Total Blocks: 2,781
Potentially Malicious Blocks: 1,140
Whitelisted Blocks: 1,639
Unknown Blocks: 2

Visual Map

0 0 0 0 0 0 x 0 0 x 0 x 0 0 0 0 0 0 0 0 0 x 0 0 0 0 0 0 0 0 x 0 0 x x x 0 1 0 0 0 0 x x 0 0 0 0 0 x 0 0 x x 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 2 2 0 0 0 x 0 0 x 0 0 0 x 0 0 ? 0 0 0 0 0 0 0 0 0 0 0 0 0 0 x 0 0 0 x x x 0 x 0 x 0 0 x 0 x 0 x 0 0 x 0 0 0 0 0 0 0 0 x 0 0 x 0 0 x x 0 x 0 0 x x 0 0 0 x 0 x x 0 x 0 0 0 x x 0 x x x x 0 x x 0 x 0 x 0 0 x x x 0 0 x x 0 x 0 0 x 0 x 0 x 0 x 0 0 x 0 x 0 x 0 x 0 x 0 x 0 x 0 x 0 x 0 0 x 0 x 0 x 0 x x x x 0 x 0 x 0 x 0 x 0 x 0 x 0 x 0 x 0 x 0 x 0 0 0 x 0 x x x x x 0 x 0 0 x 0 0 x 0 x x x x x x x x x x x x x x x x x x x x x 0 0 x x x x x x x x x x x 0 x x x x x 0 0 x x x x x 0 0 x x x x x 0 x 0 0 x x 0 x 0 0 0 0 x x x 0 x 0 x x 0 0 x 0 x x x x 0 x x 0 0 0 x x 0 x 0 0 0 0 0 0 x 0 0 0 0 0 0 x 0 0 0 0 x 0 0 0 0 x 0 x 0 0 x 0 0 0 x x x x x x 0 0 0 0 x 0 0 x 0 x x x 0 0 0 x 0 0 x 0 0 0 0 x x x x x 0 x x 0 0 0 x x 0 0 0 0 0 0 0 0 0 x x 0 0 0 0 0 0 0 x 0 0 0 x 0 x x 0 0 x x 0 0 0 x 0 0 0 x 0 0 0 0 x 0 0 x x x 0 x 0 x 0 x x 0 x 0 x x x 0 0 0 0 x x 0 0 0 0 0 x 0 x x 0 0 0 0 0 0 0 0 0 x x 0 x 0 0 0 x x 0 x 0 0 0 x x x x 0 0 0 x 0 x x 0 0 x x x x x 0 0 0 0 x 0 0 0 0 x 0 0 x x 0 0 0 x 0 0 0 0 0 0 0 0 0 0 0 0 x 0 x 0 2 2 0 0 0 0 0 0 0 0 0 0 0 ? 0 0 0 0 x x x 0 0 0 x x x 0 0 x x x 0 0 0 x x 0 0 x 0 x 0 0 x 0 x 0 0 x 0 0 0 0 x x x 0 x x x x 0 x x 0 x 0 x 0 0 x x x 0 x 0 0 x x x 0 x x x 0 0 x x x x x 0 x 0 0 0 0 0 0 0 0 x x x x x x x x x x x x x x x x x x x x x x x 0 x 0 0 0 x 0 0 0 0 0 0 0 0 0 x 0 0 x 0 0 0 x x 0 0 x x 0 0 0 0 0 0 x x x x x 0 0 x x 0 x 0 0 0 x 0 0 x x x x 0 0 0 0 x 0 0 x 0 0 x 0 0 0 0 0 0 0 0 0 x 0 x 2 0 2 2 0 0 x 0 0 0 0 x 0 x x x 0 0 x 0 x 0 0 0 0 0 x 0 0 0 x 0 0 0 0 0 0 0 x 0 0 0 x x x x x x x 0 x x x x x x x 0 0 x x x 0 x x 0 x 0 x x 0 0 x 0 x 0 0 x 0 0 x x 0 0 x x 0 0 0 0 0 0 x 0 x 0 x x 0 0 0 0 x x 0 0 0 0 0 0 x 0 0 0 x 0 0 x x 0 x 0 x x x x x x x 0 0 x x 0 0 x x x x 0 0 0 0 0 0 x x 0 0 x 0 x 0 0 0 x x 0 0 0 0 0 0 0 0 0 0 0 x 0 0 0 0 0 0 0 0 0 0 x 0 0 0 0 0 0 0 0 0 0 0 x 0 x 0 0 x 0 x 0 0 0 0 0 x x 0 0 0 0 x 0 x x x x 0 0 x 0 0 x 0 0 0 0 0 x 0 0 0 0 0 x 0 0 0 0 0 0 0 x 0 x 0 0 0 x 0 x x x x 0 0 0 0 0 0 x 0 x 0 x 0 0 0 0 0 0 x 0 0 x 0 0 0 x 0 0 x 0 x x x x 0 x x x x 0 0 x x 0 x x 0 0 0 0 x x x x x x x x x x x x 0 x 0 0 x x x 0 0 0 x 0 x 0 x x x 0 0 0 x 0 x 0 0 0 0 0 x 0 0 x x 0 0 x 0 0 0 x 0 0 0 x 0 0 0 0 0 x x x x x 0 x 0 0 0 0 0 0 0 0 0 0 0 0 x 0 0 0 x x 0 0 0 x 0 x x 0 0 x 0 x 0 x x x x 0 x 0 0 0 x x x x x x 0 x x x 0 x x x x x x x 0 0 0 x 0 0 0 0 0 0 0 0 0 0 x x x x x x 0 0 x 0 x x 0 x 0 x x 0 x 0 0 0 0 x 0 x 0 x 0 0 x 0 0 x 0 0 x x x 0 0 0 0 0 0 0 0 x 0 x x 0 0 0 x x x x x 0 x 0 x 0 x x x 0 x x x x 0 0 0 x x 0 0 0 x x 0 0 0 0 0 x 0 0 x 0 0 0 x 0 0 x 0 0 0 0 x x x 0 0 0 x 0 x x x x 0 x x x 0 0 0 x 0 0 0 x x x 0 x x x x x x 0 0 x 0 0 x 0 0 0 0 0 0 x x x x x x 0 0 0 0 x x 0 x 0 x x 0 0 0 0 0 x x 0 0 0 0 0 0 0 0 x 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 x x 0 0 0 0 0 x 0 x x 0 x x 0 x 0 x 0 x x 0 0 0 0 0 0 0 x x 0 0 0 0 0 x x x x 0 x x 0 x x x 0 x x 0 0 x 0 x x 0 x x 0 0 x 0 x x 0 0 x x 0 x x x 0 x 0 0 x 0 x x x x 0 0 0 0 x 0 0 0 0 0 0 0 0 0 0 0 0 0 0 x 0 0 0 0 x 0 x 0 0 x 0 x x x 0 0 0 x 0 0 0 0 x 0 0 x 0 x 0 x x 0 0 0 x x 0 0 0 x x x 0 0 x 0 0 0 0 0 x 0 0 0 0 0 x x x 0 0 x 0 0 0 0 0 0 x 0 0 0 x 0 0 0 0 x 0 x 0 0 0 0 0 x x 0 x x x 0 x x x x x x x x x 0 x 0 x x x 0 x 0 x 0 x 0 0 0 x 0 x 0 0 x 0 x x 0 x x 0 0 0 0 x x x 0 x 0 x x x x x 0 0 0 0 0 0 x x x 0 x x x x x x 0 x x 0 x 0 0 0 x 0 0 0 0 x 0 0 0 0 0 x 0 0 0 x 0 0 x 0 x 0 0 x x x 0 0 x 0 0 0 x x 0 0 x 0 0 x 0 0 0 0 0 x 0 0 x 0 0 x x 0 x 0 x x 0 x 0 x 0 0 x x 0 0 x x x 0 0 0 0 x 0 0 0 0 0 0 0 x x 0 x 0 0 x 0 x 0 x x 0 x 0 0 0 0 0 0 x x x 0 0 0 0 0 0 x 0 x 0 0 0 0 0 0 1 0 0 0 0 0 1 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 x 0 0 0 x x x 0 x x x x 0 0 x 0 x x x x x x x x x x 0 x x x x 0 x 0 0 0 x 0 x x x 0 0 0 0 0 x 0 x 0 0 0 x x 0 x x 0 0 0 x x 0 0 0 0 0 0 0 x 0 x x 0 0 0 0 x x 0 x x x 0 0 0 0 0 0 x 0 x x 0 x 0 0 0 0 0 x x 0 0 x 0 x x 0 0 0 x 0 0 0 0 0 x x 0 0 0 x 0 x 0 x x x 0 0 0 0 x x x x x 0 0 x x x 0 0 0 0 0 0 0 x x 0 0 0 x x x x 0 0 0 x x 0 x x 0 0 x 0 0 0 0 0 x 0 x x x x 0 0 0 0 0 0 0 0 0 0 0 0 0 x x 0 0 x 0 x 0 x 0 x x x x 0 x x x x 0 0 0 x x 0 x x 0 0 0 0 0 0 0 0 x 0 0 0 0 x x 0 x 0 x 0 x 0 0 0 0 0 x x x x x x 0 x x x 0 x 0 0 x x x 0 0 0 0 0 0 x 0 0 0 0 0 0 0 0 0 x 0 x x x 0 x 0 x 0 x 0 x 0 0 0 x x 0 0 0 x 0 x 0 x x 0 0 x 0 0 x x x 0 0 x x 0 x 0 0 0 x 0 0 x 0 0 x
... Data truncated
0 - Probable Safe Block
? - Unknown Block
x - Potentially Malicious Block

Similar Families

  • Agent.DRTB

Windows API Usage

Category API
Syscall Use
  • ntdll.dll!NtAlpcSendWaitReceivePort
  • ntdll.dll!NtClose
  • ntdll.dll!NtCreateFile
  • ntdll.dll!NtCreateSection
  • ntdll.dll!NtFreeVirtualMemory
  • ntdll.dll!NtMapViewOfSection
  • ntdll.dll!NtOpenFile
  • ntdll.dll!NtOpenKey
  • ntdll.dll!NtOpenProcessToken
  • ntdll.dll!NtProtectVirtualMemory
Show More
  • ntdll.dll!NtQueryAttributesFile
  • ntdll.dll!NtQueryDebugFilterState
  • ntdll.dll!NtQueryInformationProcess
  • ntdll.dll!NtQueryInformationThread
  • ntdll.dll!NtQueryInformationToken
  • ntdll.dll!NtQuerySystemInformationEx
  • ntdll.dll!NtQueryValueKey
  • ntdll.dll!NtQueryVirtualMemory
  • ntdll.dll!NtQueryVolumeInformationFile
  • ntdll.dll!NtReadFile
  • ntdll.dll!NtSetEvent
  • ntdll.dll!NtSetInformationFile
  • ntdll.dll!NtSetInformationProcess
  • ntdll.dll!NtTestAlert
  • ntdll.dll!NtUnmapViewOfSection
  • ntdll.dll!NtWriteFile
  • ntdll.dll!NtWriteVirtualMemory
  • win32u.dll!NtUserGetKeyboardLayout
  • win32u.dll!NtUserGetThreadState
Process Shell Execute
  • CreateProcess
Anti Debug
  • NtQuerySystemInformation

Shell Command Execution

C:\WINDOWS\SysWOW64\rundll32.exe C:\WINDOWS\system32\rundll32.exe c:\users\user\downloads\191939007e5201c3de51e2e8e79391039ef6504a_0001680896.,LiQMAxHB

Trending

Most Viewed

Loading...