Threat Database Trojans Trojan.Spy.Banker.X

Trojan.Spy.Banker.X

By CagedTech in Trojans

Analysis Report

General information

Family Name: Trojan.Spy.Banker.X
Packers: PECompact v2.20
Signature status: No Signature

Known Samples

MD5: 1e657dfa967c32d4ed62c06d61361ee5
SHA1: fdf51c535220cfc0f6fe5697d9b7b74caa73be8a
SHA256: 331F57C4D227AECFF8A6676DAD491DBA8C1093D3171F45CDD0AEB012B7C4FC90
File Size: 1.53 MB, 1526784 bytes
MD5: 69a0f8b03a0266921d338c6fbbbd9174
SHA1: 5c218efbe0bfa0acbec15badf1d4a864be333f43
SHA256: 9A83F3B1F588B8CE7677CF0D03CB9AA355832FB3B27634ED083947B9AB8475E8
File Size: 322.56 KB, 322560 bytes

Windows Portable Executable Attributes

  • File doesn't have "Rich" header
  • File doesn't have debug information
  • File doesn't have exports table
  • File doesn't have security information
  • File has been packed
  • File has TLS information
  • File is 32-bit executable
  • File is either console or GUI application
  • File is GUI application (IMAGE_SUBSYSTEM_WINDOWS_GUI)
  • File is Native application (NOT .NET application)
Show More
  • File is not packed
  • IMAGE_FILE_DLL is not set inside PE header (Executable)
  • IMAGE_FILE_EXECUTABLE_IMAGE is set inside PE header (Executable Image)

File Icons

Windows PE Version Information

Name Value
Company Name Cateia Games
File Description HTTP://RAZZ.OWNS.IT
File Version 1.0.0.0
Legal Copyright HTTP://RAZZ.OWNS.IT
Product Name C.A.G.E. - Cateia Games Adventure Game Engine
Product Version 1.0.0.1 UPDATED

File Traits

  • 2+ executable sections
  • HighEntropy
  • No Version Info
  • packed
  • PEC2
  • PECompact v2.20
  • x86

Block Information

Total Blocks: 41
Potentially Malicious Blocks: 11
Whitelisted Blocks: 30
Unknown Blocks: 0

Visual Map

x x x x x x x x x 0 x x 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0
0 - Probable Safe Block
? - Unknown Block
x - Potentially Malicious Block

Related Posts

Trending

Most Viewed

Loading...