Threat Database Trojans Trojan.MSIL.Mardom.BG

Trojan.MSIL.Mardom.BG

By CagedTech in Trojans

Analysis Report

General information

Family Name: Trojan.MSIL.Mardom.BG
Signature status: Hash Mismatch

Known Samples

MD5: c1b3cb436959507ecea9ab756916a627
SHA1: 9a2ad937d51c85b5e29121c14eedb10e10a7d7a4
SHA256: E0B5D1C90F385932AC5A9C2F62B4AE51663AC36F24382B48728A8C88F67D8F07
File Size: 1.56 MB, 1555968 bytes
MD5: 6f7d2ade454e54b5b9a7b2d500908b15
SHA1: 163336080d854d83203fb73edaf5aa9b8e4b9ac0
SHA256: 765BD0D1BA46DA4D04C560ECDAC0C0A1B8AB1DC9FD3665DE59BCED81CDB43712
File Size: 1.69 MB, 1694816 bytes

Windows Portable Executable Attributes

  • File doesn't have "Rich" header
  • File doesn't have debug information
  • File doesn't have exports table
  • File doesn't have security information
  • File is .NET application
  • File is 32-bit executable
  • File is either console or GUI application
  • File is GUI application (IMAGE_SUBSYSTEM_WINDOWS_GUI)
  • File is not packed
  • IMAGE_FILE_DLL is not set inside PE header (Executable)
Show More
  • IMAGE_FILE_EXECUTABLE_IMAGE is set inside PE header (Executable Image)

File Icons

Windows PE Version Information

Name Value
Assembly Version
  • 9.86.62.31
  • 4.8.0.0
Comments Steam Client Service
Company Name Valve Corporation
File Description Steam Client Service
File Version
  • 9.86.62.31
  • 4.8.0.0
Internal Name
  • Dcxpvnzhss.exe
  • steamservice.exe
Legal Copyright Copyright (C) Valve Corporation
Original Filename
  • Dcxpvnzhss.exe
  • steamservice.exe
Product Name Steam Client Service
Product Version
  • 9.86.62.31
  • 4.8.0.0

Digital Signatures

Signer Root Status
Valve Corp. DigiCert Trusted Root G4 Hash Mismatch

File Traits

  • .NET
  • HighEntropy
  • x86

Block Information

Total Blocks: 70
Potentially Malicious Blocks: 43
Whitelisted Blocks: 27
Unknown Blocks: 0

Visual Map

0 0 0 0 0 0 0 0 x x 0 x 0 0 x x 0 0 x 0 0 x 0 0 x x x x x x x x x 0 x 0 x x x 0 x x x x x x x x x 0 0 0 x 0 x x x x 0 0 x x x x x 0 x x x x
0 - Probable Safe Block
? - Unknown Block
x - Potentially Malicious Block

Similar Families

  • MSIL.Mardom.BG

Files Modified

File Attributes
c:\users\user\appdata\roaming\cmdll.exe Generic Read,Write Data,Write Attributes,Write extended,Append data,Delete,LEFT 262144
c:\users\user\appdata\roaming\microsoft\windows\start menu\programs\startup\cmdll.vbs Generic Write,Read Attributes

Windows API Usage

Category API
User Data Access
  • GetUserDefaultLocaleName
  • GetUserObjectInformation
Encryption Used
  • BCryptOpenAlgorithmProvider
  • CryptAcquireContext
Anti Debug
  • NtQuerySystemInformation
Other Suspicious
  • AdjustTokenPrivileges

Trending

Most Viewed

Loading...