Threat Database Worms Worm.Burn.A

Worm.Burn.A

By CagedTech in Worms

Threat Scorecard

Popularity Rank: 21,128
Threat Level: 50 % (Medium)
Infected Computers: 31
First Seen: December 24, 2012
Last Seen: August 7, 2026
OS(es) Affected: Windows

Analysis Report

General information

Family Name: Worm.Burn.A
Signature status: No Signature

Known Samples

MD5: b46c51b9ce0ac07d2e8fd73fd0ef912e
SHA1: 1bc6c1b1986144e53a2ed22a13aaee73da725902
SHA256: F3719F6E68EB1397FA20721E3ED83CF7994B894F01C98F42DB4A2192326F52D0
File Size: 257.02 KB, 257024 bytes

Windows Portable Executable Attributes

  • File doesn't have "Rich" header
  • File doesn't have debug information
  • File doesn't have exports table
  • File doesn't have relocations information
  • File doesn't have security information
  • File is 32-bit executable
  • File is either console or GUI application
  • File is GUI application (IMAGE_SUBSYSTEM_WINDOWS_GUI)
  • File is Native application (NOT .NET application)
  • File is not packed
Show More
  • IMAGE_FILE_DLL is not set inside PE header (Executable)
  • IMAGE_FILE_EXECUTABLE_IMAGE is set inside PE header (Executable Image)

File Icons

Windows PE Version Information

Name Value
Company Name Microsoft Corporation
File Description Office XML Handler
File Version 15.0.4569.1503
Internal Name msoxmled.exe
Legal Trademarks1 Microsoft® is a registered trademark of Microsoft Corporation.
Legal Trademarks2 Windows® is a registered trademark of Microsoft Corporation.
Legal Trademarks3 Microsoft Outlook® is a registered trademark of Microsoft Corporation.
Original Filename msoxmled.exe
Product Name Microsoft Office InfoPath
Product Version 15.0.4569.1503

File Traits

  • 2+ executable sections
  • WriteProcessMemory
  • x86

Block Information

Total Blocks: 219
Potentially Malicious Blocks: 48
Whitelisted Blocks: 171
Unknown Blocks: 0

Visual Map

x x x x x 0 0 x x x 0 x x x x 0 x x x x x 0 x x x x x x x x x x x x x x x x x x x x x x x x x 0 0 0 0 0 x 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 x 0 0 0 x x 0 x x 0 0 0
0 - Probable Safe Block
? - Unknown Block
x - Potentially Malicious Block

Similar Families

  • Burn.A

Files Modified

File Attributes
c:\myrep.dat Generic Write,Read Attributes
c:\myrep.dat Synchronize,Write Attributes
c:\users\user\appdata\local\temp\bot2a73.tmp Generic Read,Write Data,Write Attributes,Write extended,Append data
c:\users\user\appdata\local\temp\bot2a73.tmp Generic Read,Write Data,Write Attributes,Write extended,Append data,Delete,LEFT 262144
c:\users\user\appdata\local\temp\bot2aa1.tmp Generic Read,Write Data,Write Attributes,Write extended,Append data
c:\users\user\appdata\local\temp\bot2aa1.tmp Generic Read,Write Data,Write Attributes,Write extended,Append data,Delete,LEFT 262144
c:\users\user\appdata\local\temp\bot2ae1.tmp Generic Read,Write Data,Write Attributes,Write extended,Append data
c:\users\user\appdata\local\temp\bot2ae1.tmp Generic Read,Write Data,Write Attributes,Write extended,Append data,Delete,LEFT 262144
c:\windows\system\bot1.exe Generic Read,Write Data,Write Attributes,Write extended,Append data
c:\windows\system\bot1.exe Generic Read,Write Data,Write Attributes,Write extended,Append data,Delete,LEFT 262144
Show More
c:\windows\system\bot1.exe Synchronize,Write Data
c:\windows\system\rcx2a43.tmp Generic Read,Write Data,Write Attributes,Write extended,Append data

Windows API Usage

Category API
Process Manipulation Evasion
  • NtUnmapViewOfSection
  • ReadProcessMemory
  • VirtualAllocEx
Process Shell Execute
  • CreateProcess
Process Terminate
  • TerminateProcess

Shell Command Execution

C:\WINDOWS\system\bot1.exe (NULL)
"c:\users\user\downloads\1bc6c1b1986144e53a2ed22a13aaee73da725902_0000257024" -cure -offset=257024 -rcline="c:\users\user\downloads\1bc6c1b1986144e53a2ed22a13aaee73da725902_0000257024"
C:\WINDOWS\system\bot1.exe
"C:\WINDOWS\system\bot1.exe" -cure -offset=90112 -rcline="C:\WINDOWS\system\bot1.exe"