Threat Database Trojans Trojan.Downloader.Gen.AS

Trojan.Downloader.Gen.AS

By CagedTech in Trojans

Analysis Report

General information

Family Name: Trojan.Downloader.Gen.AS
Signature status: Hash Mismatch

Known Samples

MD5: e568dcd3eb3afb4c6058f73a7ac442de
SHA1: 53e7fcc8a713b45bc7252de5393be8f68f46783d
SHA256: 2BDF16AA7AA12913D4F343D53E76F5705582D09175D276B4163A488ADA52C0D4
File Size: 129.95 KB, 129952 bytes

Windows Portable Executable Attributes

  • File doesn't have "Rich" header
  • File doesn't have debug information
  • File has exports table
  • File is 32-bit executable
  • File is either console or GUI application
  • File is GUI application (IMAGE_SUBSYSTEM_WINDOWS_GUI)
  • File is Native application (NOT .NET application)
  • File is not packed
  • IMAGE_FILE_DLL is not set inside PE header (Executable)
  • IMAGE_FILE_EXECUTABLE_IMAGE is set inside PE header (Executable Image)

Windows PE Version Information

Name Value
Comments Intel(R) Integrated Performance Primitives. Color Conversion. DLLs dispatcher
Company Name Intel Corporation.
File Description ippcc-7.0.dll is the ippCC dispatcher
File Version 7,0,205,963
Internal Name ippcc-7.0.dll
Legal Copyright Copyright(C) Intel Corporation, 1999-2011
Original Filename ippcc-7.0.dll
Product Name ippCC. Intel(R) Integrated Performance Primitives. Color Conversion.
Product Version 7.0 build 205.58

Digital Signatures

Signer Root Status
Intel(R) Software Products Equifax Secure Certificate Authority Hash Mismatch

File Traits

  • dll
  • x86

Block Information

Total Blocks: 206
Potentially Malicious Blocks: 9
Whitelisted Blocks: 197
Unknown Blocks: 0

Visual Map

x 0 0 x x x x 0 x 0 0 0 x x x 1 0 2 2 0 0 0 0 0 0 0 0 0 1 0 0 0 0 1 1 0 0 0 0 0 0 0 0 0 0 0 0 0 0 1 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 2 3 0 0 0 1 0 0 1 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 1 0 0 0 0 0 0 0 0 1 0 0 0 0 0 0 0 2 2 0 0 0 1 0 1 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 1 1 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 1 0 0 0 0 0 0 0 0 0 0 0 0 1 1 0 0 1 0 0 1 0 0 0 1 0 0 2 1
0 - Probable Safe Block
? - Unknown Block
x - Potentially Malicious Block

Windows API Usage

Category API
Syscall Use
  • ntdll.dll!NtAlpcSendWaitReceivePort
  • ntdll.dll!NtClose
  • ntdll.dll!NtCreateFile
  • ntdll.dll!NtCreateSection
  • ntdll.dll!NtFreeVirtualMemory
  • ntdll.dll!NtMapViewOfSection
  • ntdll.dll!NtOpenFile
  • ntdll.dll!NtOpenKey
  • ntdll.dll!NtOpenProcessToken
  • ntdll.dll!NtQueryAttributesFile
Show More
  • ntdll.dll!NtQueryDebugFilterState
  • ntdll.dll!NtQueryInformationProcess
  • ntdll.dll!NtQueryInformationToken
  • ntdll.dll!NtQuerySystemInformationEx
  • ntdll.dll!NtQueryValueKey
  • ntdll.dll!NtQueryVirtualMemory
  • ntdll.dll!NtQueryVolumeInformationFile
  • ntdll.dll!NtReadFile
  • ntdll.dll!NtSetEvent
  • ntdll.dll!NtSetInformationFile
  • ntdll.dll!NtSetInformationProcess
  • ntdll.dll!NtSetInformationVirtualMemory
  • ntdll.dll!NtSetInformationWorkerFactory
  • ntdll.dll!NtTestAlert
  • ntdll.dll!NtTraceControl
  • ntdll.dll!NtUnmapViewOfSection
  • ntdll.dll!NtWriteFile
Process Manipulation Evasion
  • NtUnmapViewOfSection
Process Shell Execute
  • CreateProcess
Anti Debug
  • NtQuerySystemInformation

Shell Command Execution

C:\WINDOWS\SysWOW64\rundll32.exe C:\WINDOWS\system32\rundll32.exe c:\users\user\downloads\53e7fcc8a713b45bc7252de5393be8f68f46783d_0000129952.,LiQMAxHB

Trending

Most Viewed

Loading...