Threat Database Worms Worm.Macoute.A

Worm.Macoute.A

By CagedTech in Worms

Threat Scorecard

Popularity Rank: 9,014
Threat Level: 50 % (Medium)
Infected Computers: 6,139
First Seen: November 25, 2018
Last Seen: January 24, 2026
OS(es) Affected: Windows

Analysis Report

General information

Family Name: Worm.Macoute.A
Signature status: No Signature

Known Samples

MD5: ce5c3fcf12ddbfee613a57ac9a136347
SHA1: 13084b8b9c72d8d21b143c70a7f52b00ff979577
SHA256: 5FB09F890A38F7F2B6614D23AEA33B6339F8CC910439353582F2BF8C6B4CEA42
File Size: 332.29 KB, 332288 bytes
MD5: 6f48d94ad1c2677116cc4de644c9dc86
SHA1: 1028a24fdf6accfaa13e69934cd469d85fc19151
SHA256: CE9A4B1EF02FEA757A1182854EF66299CF7CC74ECA4933E639A8A4083F0A7F7C
File Size: 364.03 KB, 364032 bytes

Windows Portable Executable Attributes

  • File doesn't have "Rich" header
  • File doesn't have debug information
  • File doesn't have exports table
  • File doesn't have relocations information
  • File doesn't have security information
  • File has TLS information
  • File is 32-bit executable
  • File is either console or GUI application
  • File is GUI application (IMAGE_SUBSYSTEM_WINDOWS_GUI)
  • File is Native application (NOT .NET application)
Show More
  • File is not packed
  • IMAGE_FILE_DLL is not set inside PE header (Executable)
  • IMAGE_FILE_EXECUTABLE_IMAGE is set inside PE header (Executable Image)

File Icons

File Traits

  • 2+ executable sections
  • CryptUnprotectData
  • No CryptProtectData
  • No Version Info
  • x86

Block Information

Total Blocks: 330
Potentially Malicious Blocks: 165
Whitelisted Blocks: 165
Unknown Blocks: 0

Visual Map

0 0 0 0 0 0 0 0 0 0 0 0 0 x x x 0 x x x x 0 0 x x x x x 0 0 0 x x x x x x x x x x x x x x 0 0 x x x x x x x x x x x x x x x x 0 x x x x x x x 0 x x x x x x x x x x x x x x x x x x x x x x x x x x 0 x x x x x x x 0 x x x x 0 x x x x x x x x x x 0 0 0 0 x x 0 x 0 x x x x x x 0 x x x x x x x x x x x x x x x x x x x x 0 x x x 0 x x x x x x x x x x 0 x x x x x x x x x x x x x x x x x x x x x x x x x x 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 x 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0
0 - Probable Safe Block
? - Unknown Block
x - Potentially Malicious Block

Similar Families

  • Floxif.D
  • Kryptik.YRC
  • Macoute.A

Trending

Most Viewed

Loading...