Threat Database Trojans Trojan.ShellcodeRunner.DS

Trojan.ShellcodeRunner.DS

By CagedTech in Trojans

Analysis Report

General information

Family Name: Trojan.ShellcodeRunner.DS
Signature status: No Signature

Known Samples

MD5: 43f8528ead6f6816c91923f661f57853
SHA1: b8cb14b4c6e4abe8ab08a868a8ade6c77206cfbe
SHA256: B9E9EB8C5B64149130A7B7ACEB9EC2EDAA9619AB99A73398987840069F9269DF
File Size: 109.57 KB, 109568 bytes
MD5: 16ea6b8a5f0352a3a8ff5aba30d10c4a
SHA1: cc0a6b21cf54027de67eafa7fcb3c6e1b0acf73c
SHA256: 95AC55F8AD19A0662112DEE4429CD656EE1173CC0664FBB25D09A7B6E10587F4
File Size: 109.57 KB, 109568 bytes
MD5: 44d061f3e92ac29ea668252e112481f5
SHA1: 0c552ff06d34fb4f40463d3fc87f1894b4d9083c
SHA256: 70D3AC4C6FB37354ED3287D1FA8636EB291D074C3FCD24A6B099B96824A82A10
File Size: 109.57 KB, 109568 bytes

Windows Portable Executable Attributes

  • File doesn't have "Rich" header
  • File doesn't have exports table
  • File doesn't have resources
  • File doesn't have security information
  • File is 64-bit executable
  • File is console application (IMAGE_SUBSYSTEM_WINDOWS_CUI)
  • File is either console or GUI application
  • File is Native application (NOT .NET application)
  • File is not packed
  • IMAGE_FILE_DLL is not set inside PE header (Executable)
Show More
  • IMAGE_FILE_EXECUTABLE_IMAGE is set inside PE header (Executable Image)

File Traits

  • No Version Info
  • x64

Block Information

Total Blocks: 402
Potentially Malicious Blocks: 1
Whitelisted Blocks: 401
Unknown Blocks: 0

Visual Map

x 0 0 0 0 1 0 1 0 0 0 0 0 0 0 1 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 1 1 0 0 2 0 2 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 1
0 - Probable Safe Block
? - Unknown Block
x - Potentially Malicious Block

Similar Families

  • Agent.KPSX
  • Agent.LPSG
  • Agent.OIY
  • Agent.TBF
  • Farfli.XB
Show More
  • Farfli.XC
  • Rozena.EA
  • Rugmi.GJ
  • Trojan.Agent.Gen.ADI
  • Trojan.ReverseShell.Gen.E

Windows API Usage

Category API
Syscall Use
  • ntdll.dll!NtFreeVirtualMemory
  • ntdll.dll!NtQuerySecurityAttributesToken
  • ntdll.dll!NtQueryVolumeInformationFile
  • ntdll.dll!NtSetEvent
  • ntdll.dll!NtSetInformationWorkerFactory
  • ntdll.dll!NtTestAlert
  • ntdll.dll!NtWriteFile
  • UNKNOWN

Trending

Most Viewed

Loading...