Threat Database Trojans Trojan.Downloader.Gen.CB

Trojan.Downloader.Gen.CB

By CagedTech in Trojans

Analysis Report

General information

Family Name: Trojan.Downloader.Gen.CB
Signature status: Hash Mismatch

Known Samples

MD5: a5996eb6de4b41f509804beb75801243
SHA1: f7219b3639b07eb1c8d2d3de5a70279a4c530ef4
SHA256: 3E928C8D8A2C91DD3D287D9F54CFB40EB985F1912B33963B81B0AC31260A12E2
File Size: 380.96 KB, 380960 bytes

Windows Portable Executable Attributes

  • File doesn't have "Rich" header
  • File has exports table
  • File is 64-bit executable
  • File is either console or GUI application
  • File is GUI application (IMAGE_SUBSYSTEM_WINDOWS_GUI)
  • File is Native application (NOT .NET application)
  • File is not packed
  • IMAGE_FILE_DLL is not set inside PE header (Executable)
  • IMAGE_FILE_EXECUTABLE_IMAGE is set inside PE header (Executable Image)

Windows PE Version Information

Name Value
Company Name Microsoft Corporation
File Description F12 Developer Tools Diagnostics TAP
File Version 17.0.36015.10 built by: d17.14
Internal Name DiagnosticsTap.dll
Legal Copyright © Microsoft Corporation. All rights reserved.
Original Filename DiagnosticsTap.dll
Product Name F12 Developer Tools
Product Version 17.0.36015.10

Digital Signatures

Signer Root Status
Microsoft Corporation Microsoft Code Signing PCA 2011 Hash Mismatch

File Traits

  • 2+ executable sections
  • dll
  • x64

Block Information

Total Blocks: 1,424
Potentially Malicious Blocks: 366
Whitelisted Blocks: 1,058
Unknown Blocks: 0

Visual Map

x x x x x 0 0 x 0 x 0 x x 0 0 0 x 0 0 0 0 x 0 0 x 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 x x x 0 x 0 0 0 x 0 0 0 x 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 x 0 x 0 0 x 0 x 0 0 0 0 0 x 0 0 x 0 0 0 0 0 1 0 0 0 0 x 0 0 0 x x x x x x 0 0 0 0 x x 0 x 0 0 x x 0 0 x x 0 x x 0 x x 0 0 0 0 0 0 0 0 x 0 0 x 0 x x x x 0 0 0 0 0 0 0 0 0 0 x 0 0 x x x 0 0 0 0 0 0 0 0 x x x 0 x x 0 x 0 x 0 x x x 0 0 x 0 x x 0 1 x 0 x 0 x x 0 x x 0 x 0 x 0 0 0 0 0 0 0 x x x x x x x x x x x x x x x x x 0 x x 0 x 0 x 0 0 0 0 0 0 0 0 x x 0 0 x 0 0 0 0 0 0 x 0 0 0 0 0 0 0 0 x x 0 0 0 x x 0 x 0 0 0 x x x 0 x 0 x x 0 x 0 0 1 0 x x x x 0 x 0 x 0 x x 0 0 0 0 x 0 x x 0 0 0 0 x x x x 0 x 0 0 x x 0 0 0 x 0 0 0 0 x x 0 x x x 0 0 x 0 0 0 x 0 0 0 0 0 x 0 0 0 x x 0 x 0 1 0 0 0 0 0 x x 0 0 x 0 x x 0 0 x x x 0 0 x 0 0 0 x x x 0 0 0 x 0 0 0 x x x 0 0 0 0 x 0 0 x x x x 0 0 x x x x 0 x 0 0 x x 0 0 0 0 0 0 0 x x 0 x 0 0 0 0 x x x 0 x 0 0 x x 0 0 0 0 0 x 0 x 0 x 0 0 x 0 x 0 0 0 0 0 x 0 x x 0 x x 0 x x x x x 0 x 0 0 x x 0 x x x x x 0 0 x 0 0 0 0 0 x 0 0 0 0 0 0 x x 0 0 0 x 0 0 0 0 0 x x 0 x x x 0 x x x x 0 x x 0 0 x 0 x 0 0 0 x x 0 0 x x x x 0 0 0 x x x x x x x 0 0 0 x x 0 0 0 x x x 0 0 0 0 x x 0 0 0 x x 0 x x x x x x x x x x x x 0 x 0 0 x 0 x 0 0 0 0 x x 0 x 0 0 x 0 x 0 x 0 0 x x x x x x x x x 0 0 x x x 0 x x 0 0 x x x 0 0 x x x x x x x x 0 0 0 0 0 x 0 0 x x x x x 0 0 0 0 0 x x x 0 x x 0 x 0 0 x x x 0 0 x x x 0 x x 0 x x x x 0 x x 0 0 x x x x x x x x 0 x x x x x 0 0 x x x 0 x x x 0 x 0 0 0 0 x 0 x 0 0 0 0 0 x x 0 0 0 1 0 x 0 0 0 0 0 0 0 x 0 x 0 0 x 0 x 0 x 0 0 x 0 x 0 x 0 0 0 0 x x 0 x 0 x 0 x x 0 x x x 0 x 0 x 0 x x 0 0 0 0 0 0 x x 0 0 0 0 x x x 0 x 0 x x 0 2 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 1 0 0 0 0 0 0 0 0 0 0 0 1 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 2 0 0 1 1 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 1 0 0 0 0 0 0
0 - Probable Safe Block
? - Unknown Block
x - Potentially Malicious Block

Similar Families

Windows API Usage

Category API
Syscall Use
  • ntdll.dll!NtAccessCheck
  • ntdll.dll!NtAlpcSendWaitReceivePort
  • ntdll.dll!NtApphelpCacheControl
  • ntdll.dll!NtClose
  • ntdll.dll!NtConnectPort
  • ntdll.dll!NtCreateMutant
  • ntdll.dll!NtCreateSection
  • ntdll.dll!NtDuplicateToken
  • ntdll.dll!NtFreeVirtualMemory
  • ntdll.dll!NtMapViewOfSection
Show More
  • ntdll.dll!NtOpenFile
  • ntdll.dll!NtOpenKey
  • ntdll.dll!NtOpenKeyEx
  • ntdll.dll!NtOpenProcessToken
  • ntdll.dll!NtOpenProcessTokenEx
  • ntdll.dll!NtOpenSection
  • ntdll.dll!NtOpenSemaphore
  • ntdll.dll!NtOpenThreadTokenEx
  • ntdll.dll!NtProtectVirtualMemory
  • ntdll.dll!NtQueryAttributesFile
  • ntdll.dll!NtQueryDebugFilterState
  • ntdll.dll!NtQueryInformationProcess
  • ntdll.dll!NtQueryInformationThread
  • ntdll.dll!NtQueryInformationToken
  • ntdll.dll!NtQueryKey
  • ntdll.dll!NtQueryLicenseValue
  • ntdll.dll!NtQueryPerformanceCounter
  • ntdll.dll!NtQuerySecurityAttributesToken
  • ntdll.dll!NtQueryValueKey
  • ntdll.dll!NtQueryVirtualMemory
  • ntdll.dll!NtQueryVolumeInformationFile
  • ntdll.dll!NtQueryWnfStateData
  • ntdll.dll!NtReleaseMutant
  • ntdll.dll!NtReleaseSemaphore
  • ntdll.dll!NtReleaseWorkerFactoryWorker
  • ntdll.dll!NtRequestWaitReplyPort
  • ntdll.dll!NtSetEvent
  • ntdll.dll!NtSetInformationProcess
  • ntdll.dll!NtSetInformationThread
  • ntdll.dll!NtSetInformationVirtualMemory
  • ntdll.dll!NtSetInformationWorkerFactory
  • ntdll.dll!NtSubscribeWnfStateChange
  • ntdll.dll!NtTestAlert
  • ntdll.dll!NtTraceControl
  • ntdll.dll!NtUnmapViewOfSection
  • ntdll.dll!NtUnmapViewOfSectionEx
  • ntdll.dll!NtWaitForSingleObject
  • ntdll.dll!NtWaitForWorkViaWorkerFactory
  • ntdll.dll!NtWaitLowEventPair
  • ntdll.dll!NtWorkerFactoryWorkerReady
  • ntdll.dll!NtWriteFile
  • UNKNOWN

Trending

Most Viewed

Loading...