Threat Database Trojans Trojan.Bayrob.E

Trojan.Bayrob.E

By CagedTech in Trojans

Analysis Report

General information

Family Name: Trojan.Bayrob.E
Signature status: No Signature

Known Samples

MD5: 0adbce7e20da61ee4a09ddaa3e7c4d0d
SHA1: 823f6d461b337947ebeab350311e9a812a4b258e
SHA256: 68211104379E8F63E01F2D06686651ED51FA6213AB0B273C6C35137971AA16D9
File Size: 234.50 KB, 234496 bytes

Windows Portable Executable Attributes

  • File doesn't have "Rich" header
  • File doesn't have debug information
  • File doesn't have exports table
  • File doesn't have resources
  • File doesn't have security information
  • File is 32-bit executable
  • File is either console or GUI application
  • File is GUI application (IMAGE_SUBSYSTEM_WINDOWS_GUI)
  • File is Native application (NOT .NET application)
  • File is not packed
Show More
  • IMAGE_FILE_DLL is not set inside PE header (Executable)
  • IMAGE_FILE_EXECUTABLE_IMAGE is set inside PE header (Executable Image)

File Traits

  • HighEntropy
  • No Version Info
  • x86

Block Information

Total Blocks: 398
Potentially Malicious Blocks: 34
Whitelisted Blocks: 81
Unknown Blocks: 283

Visual Map

x 0 ? ? ? x 0 0 x 0 0 ? x x ? ? 0 ? ? x ? ? x 0 ? ? 0 ? ? ? ? 0 0 ? ? ? ? ? 0 1 ? ? ? ? 1 ? ? ? ? 0 0 ? ? 0 ? ? x ? ? ? ? ? ? x 0 ? ? 0 0 ? 0 ? 1 ? ? ? x ? x ? ? ? 0 ? ? 1 ? 0 ? ? ? 0 ? ? 0 ? 0 ? ? ? ? x ? ? ? 1 ? ? ? ? ? ? ? ? ? ? ? ? ? ? ? ? ? ? 0 ? ? ? 1 ? 0 ? ? ? ? ? ? ? ? ? ? ? ? x ? ? ? ? ? ? ? ? ? ? 0 ? ? ? ? 0 ? ? ? ? x ? 0 ? ? ? ? 1 ? ? ? x 0 ? ? ? ? 0 ? ? ? x ? ? ? x ? ? x ? ? ? 0 ? ? ? 0 ? ? ? ? ? ? ? ? 0 0 ? ? 0 ? ? ? 0 0 ? ? ? ? x ? 0 0 ? ? ? ? ? x ? ? x 0 0 2 0 0 0 0 0 ? ? ? ? 0 ? ? ? ? ? ? ? 0 0 ? 1 ? ? ? x ? x ? ? ? 1 ? ? 0 ? x ? x 0 ? ? ? 0 ? ? ? 0 ? ? ? ? ? ? x ? ? 0 0 ? 0 ? ? ? ? ? 0 ? ? ? ? ? ? x ? 0 ? ? ? ? x 0 ? ? ? x ? 0 ? 0 ? ? x ? ? 0 ? ? 0 ? x ? ? ? ? ? 0 ? ? ? ? ? 0 ? ? ? ? ? ? ? ? ? ? ? ? ? ? x ? x x ? ? ? ? ? ? ? 0 ? ? ? 0 ? 0 ? ? ? ? 0 0 ? ? ? 0 ? ? ? ? ?
0 - Probable Safe Block
? - Unknown Block
x - Potentially Malicious Block

Files Modified

File Attributes
c:\ohbrsnqea Synchronize,Write Attributes
c:\ohbrsnqea\cchfh3sjr0prbzfocr.exe Generic Write,Read Attributes
c:\ohbrsnqea\o0xtdx8sn Generic Write,Read Attributes
c:\windows\ohbrsnqea\o0xtdx8sn Generic Write,Read Attributes

Windows API Usage

Category API
Process Manipulation Evasion
  • NtUnmapViewOfSection
Process Shell Execute
  • CreateProcess

Shell Command Execution

C:\ohbrsnqea\cchfh3sjr0prbzfocr.exe (NULL)

Trending

Most Viewed

Loading...