Threat Database Trojans Trojan.MSILZilla.DN

Trojan.MSILZilla.DN

By CagedTech in Trojans

Analysis Report

General information

Family Name: Trojan.MSILZilla.DN
Signature status: Hash Mismatch

Known Samples

MD5: 833cb989782944346288996f6e440c5c
SHA1: b059347a6121f3f4b857dba01ff6c3812236d238
SHA256: 94CDDD1F092DD4D6044E9A5DBC39F8971492B20FA8731A5B22F74887E22BFEB0
File Size: 212.99 KB, 212992 bytes

Windows Portable Executable Attributes

  • File doesn't have "Rich" header
  • File doesn't have exports table
  • File is 32-bit executable
  • File is console application (IMAGE_SUBSYSTEM_WINDOWS_CUI)
  • File is either console or GUI application
  • File is Native application (NOT .NET application)
  • File is not packed
  • IMAGE_FILE_DLL is not set inside PE header (Executable)
  • IMAGE_FILE_EXECUTABLE_IMAGE is set inside PE header (Executable Image)

Windows PE Version Information

Name Value
Build Date Wed Apr 16 2008 19:28:20
Build Version 52.338651
Company Name Adobe Systems Incorporated
File Description Adobe Updater Install Manager
File Version 6, 0, 0, 1452
Internal Name AdobeUpdaterInstallMgr.exe
Legal Copyright Copyright (c) 2002-2008 by Adobe Systems Incorporated. All rights reserved.
Original Filename AdobeUpdaterInstallMgr.exe
Product Name Adobe Updater
Product Version 6.0.0.1452 (BuildVersion: 52.338651; BuildDate: Wed Apr 16 2008 19:28:20)

Digital Signatures

Signer Root Status
Adobe Systems Incorporated VeriSign Class 3 Code Signing 2004 CA Hash Mismatch

File Traits

  • big overlay
  • HighEntropy
  • Installer Manifest
  • Installer Version
  • x86

Block Information

Total Blocks: 327
Potentially Malicious Blocks: 1
Whitelisted Blocks: 326
Unknown Blocks: 0

Visual Map

0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 x 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 1 0 0 0 1 0 0 0 0 0 0 0 0 2 1 1 1 3 1 0 0 0 1 0 0 0 0 0 0 0 0 0 0 0 0 1 0 0 0 0 0 0 0 0 1 1 0 0 0 0 1 0 0 0 0 0 0 0 0 0 0 0 1 1 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 1 1 0 1 0 0 0 0 1 1 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 1 0 0 0 0 0 0 0 0 0 0 0 0 0 2 3 0 0 0 1 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 1 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 1 0 0 0 1 0 0 1 0 0 0 2 2 0 1 0 0 0 0 0 0 2 0 0 0 0 0 0 0 1 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 1 0
0 - Probable Safe Block
? - Unknown Block
x - Potentially Malicious Block

Windows API Usage

Category API
Process Shell Execute
  • CreateProcess

Shell Command Execution

"c:\users\user\downloads\Adobe_Updater.exe"

Trending

Most Viewed

Loading...