Threat Database Trojans Trojan.MSIL.Injector.AJ

Trojan.MSIL.Injector.AJ

By CagedTech in Trojans

Analysis Report

General information

Family Name: Trojan.MSIL.Injector.AJ
Signature status: No Signature

Known Samples

MD5: ba3be0edd4649124766dd13004764d1a
SHA1: 366b4cc701857e39345f52d6544e3c5380b17329
SHA256: F369F2A58A215DF7EAC7131AECF8E14FF7CB6F7D0312BB138D9EF2D26BA46422
File Size: 413.18 KB, 413184 bytes

Windows Portable Executable Attributes

  • File doesn't have "Rich" header
  • File doesn't have debug information
  • File doesn't have exports table
  • File doesn't have security information
  • File is .NET application
  • File is 32-bit executable
  • File is console application (IMAGE_SUBSYSTEM_WINDOWS_CUI)
  • File is either console or GUI application
  • File is not packed
  • IMAGE_FILE_DLL is not set inside PE header (Executable)
Show More
  • IMAGE_FILE_EXECUTABLE_IMAGE is set inside PE header (Executable Image)

Windows PE Version Information

Name Value
Assembly Version 2.0.0.0
Company Name FoxBots.net
File Description BlueFox Core
File Version 2.0.0.0
Internal Name BlueFoxCore.dll
Legal Copyright Copyright © 2019
Original Filename BlueFoxCore.dll
Product Name BlueFoxCore
Product Version 2.0.0.0

File Traits

  • .NET
  • dll
  • HighEntropy
  • x86

Block Information

Total Blocks: 1,575
Potentially Malicious Blocks: 55
Whitelisted Blocks: 1,063
Unknown Blocks: 457

Visual Map

0 0 0 0 0 0 0 ? 0 x 0 0 ? ? 0 0 0 0 0 0 0 0 ? 0 0 0 0 0 0 0 0 0 0 0 0 0 0 ? ? ? 0 0 0 0 ? 0 ? 0 0 0 0 ? 0 0 ? 0 0 0 0 0 0 ? 0 ? ? ? 0 ? 0 0 0 0 ? ? 0 ? ? ? ? ? 0 x 0 0 0 0 x 0 ? 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 ? ? 0 0 0 0 ? 0 x ? 0 0 ? 0 0 ? ? ? ? ? 0 0 x 0 0 ? 0 0 0 0 ? ? ? ? 0 0 0 0 ? x 0 ? ? 0 ? ? ? ? 0 ? x ? ? 0 ? 0 ? ? ? ? 0 0 0 ? ? ? ? 0 0 0 0 0 0 0 0 ? ? ? 0 ? ? 0 0 0 0 0 0 0 0 0 0 0 0 ? 0 0 0 ? 0 0 0 0 0 0 0 x ? x 0 0 x ? 0 x ? x ? 0 0 0 ? 0 0 ? ? ? ? ? x ? 0 ? x ? ? ? ? ? ? ? 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 ? ? ? ? 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 ? x ? ? ? 0 ? 0 0 0 0 ? x 0 0 0 0 0 ? ? ? 0 0 0 0 0 0 0 ? 0 0 0 0 0 0 x ? ? 0 0 0 0 0 0 0 0 ? 0 0 0 0 ? ? ? ? ? ? 0 0 0 0 ? 0 0 0 0 0 0 0 0 ? ? ? ? 0 0 ? ? 0 ? 0 0 0 0 0 0 ? ? ? 0 0 0 0 0 0 0 0 0 0 0 ? x x ? 0 0 0 0 0 0 ? 0 0 0 ? ? 0 ? 0 0 x 0 0 0 ? ? ? ? 0 0 ? 0 0 ? ? ? x 0 0 0 ? ? ? ? 0 0 0 ? ? ? 0 ? 0 x ? ? 0 ? 0 ? 0 0 0 0 0 0 ? x ? 0 ? 0 0 ? ? ? 0 0 0 ? 0 0 0 0 0 0 ? ? ? ? 0 0 ? 0 0 x ? ? 0 x ? 0 0 ? ? 0 0 ? ? ? 0 0 0 0 ? ? ? 0 0 ? ? ? ? 0 0 ? x 0 0 0 0 0 ? ? 0 0 ? 0 ? ? ? 0 ? ? ? ? x ? 0 0 0 0 ? ? 0 0 0 0 ? 0 0 ? 0 0 ? 0 0 0 x 0 ? 0 ? 0 0 ? 0 ? ? 0 ? 0 0 0 0 ? 0 0 ? ? ? ? ? 0 ? 0 0 ? ? 0 ? 0 ? 0 0 ? 0 0 0 0 0 0 0 0 ? 0 ? 0 ? 0 ? ? ? ? 0 ? ? 0 ? ? 0 ? 0 0 0 0 ? 0 0 ? 0 ? ? ? ? 0 0 0 0 0 0 0 ? x ? x ? 0 0 ? 0 ? 0 ? 0 0 ? ? ? 0 0 ? ? ? ? ? 0 0 0 ? 0 x ? 0 0 ? ? ? ? ? ? 0 0 0 ? ? ? 0 0 ? ? 0 0 0 0 0 ? 0 0 0 0 ? 0 0 0 0 ? ? 0 ? 0 ? 0 0 0 0 0 0 ? 0 ? 0 ? 0 0 ? 0 ? ? ? 0 0 0 0 0 ? 0 0 ? 0 0 ? ? ? 0 ? ? 0 ? 0 0 0 0 ? ? ? 0 ? 0 ? ? 0 0 ? ? 0 0 0 0 0 ? ? 0 0 ? 0 0 0 ? 0 0 0 0 0 ? 0 0 ? 0 0 x 0 0 ? 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 ? 0 ? ? ? ? ? 0 ? ? ? ? ? ? ? ? 0 0 0 0 0 0 0 0 ? ? 0 0 0 0 0 0 0 0 0 0 0 0 0 ? ? 0 0 0 0 0 0 0 0 0 ? ? 0 0 0 0 0 0 0 ? ? ? ? ? 0 0 0 0 0 0 0 0 ? 0 ? ? ? ? 0 0 0 0 0 ? ? ? x 0 0 0 0 0 0 ? 0 0 ? 0 0 0 0 0 0 ? ? 0 0 0 0 0 0 ? ? 0 0 0 0 0 0 0 ? ? 0 ? x ? 0 ? 0 ? 0 0 0 0 ? 0 ? 0 0 0 0 0 ? ? 0 0 0 0 0 0 0 ? ? 0 x 0 0 0 ? ? ? ? ? ? ? 0 0 ? ? 0 0 ? ? ? ? ? ? ? 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 ? ? ? ? 0 0 ? 0 ? ? ? 0 ? ? 0 ? x x ? ? ? ? ? ? 0 ? ? x ? ? 0 ? 0 0 0 0 0 ? 0 0 0 0 0 0 x ? 0 ? ? ? x 0 ? x ? ? 0 0 ? 0 0 0 0 ? 0 ? ? ? ? 0 0 0 ? 0 0 ? 0 0 0 ? 0 0 0 0 0 0 0 ? 0 0 0 ? 0 x ? ? 0 0 0 0 0 x ? ? ? x 0 0 0 0 0 ? ? ? ? 0 0 0 0 0 0 0 ? 0 0 0 0 0 0 0 ? ? ? ? 0 0 0 0 0 0 0 ? ? ? ? 0 0 0 0 ? 0 0 0 0 0 0 0 0 0 ? ? ? x 0 0 0 0 0 0 0 0 0 0 0 ? 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 ? ? 0 0 0 0 ? ? 0 0 ? 0 0 0 0 0 x x 0 0 0 0 0 0 0 ? ? 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 ? ? ? ? 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 ? ? ? 0 0 ? 0 0 0 0 0 ? ? 0 0 ? ? ? ? ? x 0 0 0 0 0 0 0 0 0 ? 0 ? 0 0 0 0 0 ? ? ? 0 0 0 0 0 ? ? 0 0 0 0 x 0 0 0 0 0 ? ? ? ? 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 ? ? ? x 0 0 0 0 0 0 0 0 0 x 0 0 0 0 0 x 0 0 0 0 0 0 0 0 0 0 0 0 x 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 x x ? 0 ? ? 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0
0 - Probable Safe Block
? - Unknown Block
x - Potentially Malicious Block

Registry Modifications

Key::Value Data API Name
HKLM\software\microsoft\windows nt\currentversion\notifications\data::418a073aa3bc1c75 RegNtPreCreateKey

Windows API Usage

Category API
Syscall Use
  • ntdll.dll!NtAccessCheck
  • ntdll.dll!NtAlpcSendWaitReceivePort
  • ntdll.dll!NtApphelpCacheControl
  • ntdll.dll!NtClose
  • ntdll.dll!NtConnectPort
  • ntdll.dll!NtCreateMutant
  • ntdll.dll!NtCreateSection
  • ntdll.dll!NtDuplicateToken
  • ntdll.dll!NtFreeVirtualMemory
  • ntdll.dll!NtMapViewOfSection
Show More
  • ntdll.dll!NtOpenFile
  • ntdll.dll!NtOpenKey
  • ntdll.dll!NtOpenKeyEx
  • ntdll.dll!NtOpenProcessToken
  • ntdll.dll!NtOpenProcessTokenEx
  • ntdll.dll!NtOpenSection
  • ntdll.dll!NtOpenSemaphore
  • ntdll.dll!NtOpenThreadTokenEx
  • ntdll.dll!NtProtectVirtualMemory
  • ntdll.dll!NtQueryAttributesFile
  • ntdll.dll!NtQueryDebugFilterState
  • ntdll.dll!NtQueryInformationProcess
  • ntdll.dll!NtQueryInformationThread
  • ntdll.dll!NtQueryInformationToken
  • ntdll.dll!NtQueryKey
  • ntdll.dll!NtQueryPerformanceCounter
  • ntdll.dll!NtQuerySecurityAttributesToken
  • ntdll.dll!NtQueryValueKey
  • ntdll.dll!NtQueryVirtualMemory
  • ntdll.dll!NtQueryVolumeInformationFile
  • ntdll.dll!NtQueryWnfStateData
  • ntdll.dll!NtReleaseMutant
  • ntdll.dll!NtReleaseSemaphore
  • ntdll.dll!NtReleaseWorkerFactoryWorker
  • ntdll.dll!NtRequestWaitReplyPort
  • ntdll.dll!NtSetEvent
  • ntdll.dll!NtSetInformationProcess
  • ntdll.dll!NtSetInformationVirtualMemory
  • ntdll.dll!NtSetInformationWorkerFactory
  • ntdll.dll!NtSubscribeWnfStateChange
  • ntdll.dll!NtTestAlert
  • ntdll.dll!NtTraceControl
  • ntdll.dll!NtUnmapViewOfSection
  • ntdll.dll!NtUnmapViewOfSectionEx
  • ntdll.dll!NtWaitForSingleObject
  • ntdll.dll!NtWaitLowEventPair
  • ntdll.dll!NtWriteFile
  • UNKNOWN

Trending

Most Viewed

Loading...