Threat Database Trojans Trojan.KillMBR.XB

Trojan.KillMBR.XB

By CagedTech in Trojans

Analysis Report

General information

Family Name: Trojan.KillMBR.XB
Signature status: No Signature

Known Samples

MD5: 8708ae34abd3f25ea361433ecc007efd
SHA1: f612c9371817d6002b2078de4d8e2978544a6d2e
SHA256: F22D8A2297219101B806CE2F5190A3DA6CBFEFDE233EF3ED3D4FBF7B0F8B1621
File Size: 259.58 KB, 259584 bytes
MD5: 5a987e379ecabe4bc8dbf173b08e8817
SHA1: f65e4c1061c750cb6637aa06ed36f57b813bf24f
SHA256: 8CB0BDB77FA3226FB242BA593C5388D0A62A70D53ABD2A2DA23EDF26825F342F
File Size: 264.70 KB, 264704 bytes
MD5: b8e02395624309192141c7d596785e1d
SHA1: 700a55b92066a9786f1d55f452348232aeca483d
SHA256: 8CFC3DB6483EC68886A82012226A4359706D7332ADF9E41F63742A271AFF2B80
File Size: 2.11 MB, 2110976 bytes

Windows Portable Executable Attributes

  • File doesn't have "Rich" header
  • File doesn't have exports table
  • File doesn't have security information
  • File is 32-bit executable
  • File is either console or GUI application
  • File is GUI application (IMAGE_SUBSYSTEM_WINDOWS_GUI)
  • File is Native application (NOT .NET application)
  • File is not packed
  • IMAGE_FILE_DLL is not set inside PE header (Executable)
  • IMAGE_FILE_EXECUTABLE_IMAGE is set inside PE header (Executable Image)

File Icons

File Traits

  • HighEntropy
  • No Version Info
  • x86

Block Information

Total Blocks: 724
Potentially Malicious Blocks: 26
Whitelisted Blocks: 698
Unknown Blocks: 0

Visual Map

x x x x x x x x x x x x x x x x x x x x x x x 0 1 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 2 0 0 0 0 0 0 0 0 0 1 1 0 0 1 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 1 0 0 0 1 0 0 0 0 0 0 0 2 0 0 0 0 0 0 0 0 0 0 0 0 0 0 1 1 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 1 1 0 0 0 0 0 0 0 2 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 2 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 2 0 0 0 0 0 0 0 0 0 0 0 0 0 1 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 1 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 2 2 1 1 1 1 1 1 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 x x x 0 0 0 0 0 0 0 0 0 0 0 0 0 2 0 0 0 0 0 0 0 0 0 1 1 0 0 1 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 1 0 0 2 0 1 0 0 0 0 0 0 0 2 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 1 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 1 1 0 0 0 0 0 0 0 0 0 0 2 0 2 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 2 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 2 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 2 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 2 0 0 0 0 0 0 0 2 0 0 0 0 0 0 0 0 0 0 0 0 0 0 2 0 0 0 0 0 0 0 0 0 0 0 0 0 1 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 1 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 2 2 1 1 1 1 1 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0
0 - Probable Safe Block
? - Unknown Block
x - Potentially Malicious Block

Similar Families

  • Chapak.HBK
  • Trojan.Agent.Gen.GS
  • Trojan.Kryptik.Gen.BQN

Files Modified

File Attributes
c:\users\user\appdata\local\temp\« Generic Read,Write Data,Write Attributes,Write extended,Append data,Delete,LEFT 262144
c:\users\user\appdata\local\temp\« Generic Write,Read Attributes
c:\users\user\appdata\local\temp\« Generic Write,Read Attributes,Delete,LEFT 262144
c:\users\user\appdata\local\temp\« Generic Write,Read Attributes,LEFT 262144
c:\users\user\appdata\local\temp\« Generic Write,Read Data,Read Attributes
c:\users\user\appdata\local\temp\« Generic Write,Read Data,Read Attributes,Delete,LEFT 262144
c:\users\user\appdata\local\temp\« Generic Write,Read Data,Read Attributes,LEFT 262144

Trending

Most Viewed

Loading...