Threat Database Backdoors Backdoor.MSIL.ClipBanker.BJ

Backdoor.MSIL.ClipBanker.BJ

By CagedTech in Backdoors

Threat Scorecard

Popularity Rank: 19,007
Threat Level: 60 % (Medium)
Infected Computers: 354
First Seen: August 7, 2023
Last Seen: May 27, 2026
OS(es) Affected: Windows

The detection of Backdoor.MSIL.ClipBanker.BJ on your system indicates a potentially serious security threat. This detection name suggests a backdoor-type malware, which can allow unauthorized access to your computer. It is essential to understand the nature of this threat and take immediate action to remove it and prevent further damage.

What Is Backdoor.MSIL.ClipBanker.BJ?

Backdoor.MSIL.ClipBanker.BJ is a type of malware that can provide unauthorized access to your computer, allowing attackers to remotely control your system, steal sensitive information, or use your computer for malicious activities. The term "backdoor" refers to the malware's ability to bypass normal security mechanisms, creating a secret entry point for attackers. The "MSIL" part of the name suggests that the malware is written in Microsoft Intermediate Language, which is a platform-agnostic language used by the .NET Framework.

How Backdoor.MSIL.ClipBanker.BJ Operates

Backdoor malware, including Backdoor.MSIL.ClipBanker.BJ, typically operates by establishing a connection with a command and control (C2) server, which allows attackers to send commands and receive stolen data. The malware may use various techniques to evade detection, such as code obfuscation, anti-debugging, and exploiting vulnerabilities in software or operating systems. Once installed, the malware can perform a range of malicious activities, including data theft, keylogging, and using the infected computer as a botnet node for distributed denial-of-service (DDoS) attacks or spamming.

Symptoms of Infection

Identifying a backdoor infection can be challenging, as these types of malware are designed to remain stealthy. However, some common symptoms may include unusual network activity, slow system performance, unfamiliar programs or processes running in the background, and unexpected changes to system settings or files. If you suspect that your computer is infected with Backdoor.MSIL.ClipBanker.BJ, it is crucial to take immediate action to mitigate the threat.

How to Remove Backdoor.MSIL.ClipBanker.BJ

  1. Boot your computer in Safe Mode with Networking to prevent the malware from loading and to allow for a more effective removal process.
  2. Use a reputable anti-malware tool, such as SpyHunter, to perform a full scan of your system. This can help detect and remove the malware and any associated files or registry entries.
  3. Uninstall any suspicious programs or applications that you do not recognize or that were installed around the time of the suspected infection.
  4. Reset your web browsers, including Chrome, Firefox, and Edge, to their default settings to remove any malicious extensions or settings changes.
  5. Reboot your computer and perform another full scan with your anti-malware tool to ensure that the malware has been completely removed.

Conclusion

Removing Backdoor.MSIL.ClipBanker.BJ requires careful attention to detail and a thorough approach to ensure that all associated files and registry entries are removed. By following the steps outlined above and maintaining good security practices, such as keeping your operating system and software up to date, using strong passwords, and being cautious when opening email attachments or clicking on links, you can help protect your computer from future malware infections. Remember, prevention and vigilance are key to maintaining the security and integrity of your digital assets.

Analysis Report

General information

Family Name: Backdoor.MSIL.ClipBanker.BJ
Signature status: No Signature

Known Samples

MD5: 9b28616f492e4647a6e13ca29c3361f6
SHA1: e675c5c3aafe2bd0cd31833cd2c2c5513c076e32
File Size: 1.88 MB, 1884672 bytes
MD5: dafc22eab013383dce4bcdf599b4fbc7
SHA1: b52e5913bed486da305e60a9643770ac4d7c6440
SHA256: 4F103DF3799D0C5C334891273C13F6D65C75B0E2DD2DA2255F3C06FADE90D03C
File Size: 2.84 MB, 2843648 bytes
MD5: 72967adc5e6cda32e56e3f855fc0099e
SHA1: 653ff2f48880599865f462a64d584a291463d056
SHA256: A0EA33AE2B0381BB167705C7B63AE6B58E0EB26DAF54C1FB939CBD1325087B6B
File Size: 1.01 MB, 1010176 bytes
MD5: 9f4d4e322012462e29fa3a252667bdf6
SHA1: 79d430ff387eee391626216dcdf7c8020d43309c
SHA256: E9C9B909AA5C32F4C0F90DD10D7193E5FB1F9EB724FEC8D4AF465C15F37D2131
File Size: 1.78 MB, 1776665 bytes
MD5: ba6cb58cc0b3ea03384061a322f70431
SHA1: 355c05889c973c69f9f33dfdd76c6256271162b0
SHA256: E7F6A90721378C2DDC7742D20D61B1438F93363A82245C6E3C0D6FD884C6A35D
File Size: 2.98 MB, 2982170 bytes
Show More
MD5: 1fb62f209960b81404e6d5b503164603
SHA1: 2105da88e515b0d045ea86054c6334354ec4277d
SHA256: 31172DC910683ED3851F32A382C6E896A9B3F2001C166B1677105E1FE6F0EFA3
File Size: 2.84 MB, 2843648 bytes
MD5: 8b737546539b2027e384ce87d41007fc
SHA1: 33d29e328a97c394b31151cdd3696f9489aec61b
SHA256: 8D0ED55E8ECFA2B168C5627E13B9D6472613347B8D806D82427B995B9B314D7C
File Size: 2.50 MB, 2496171 bytes
MD5: af39c231acfea49fb63b3479354958a4
SHA1: eb32057c5a40995684ffc2782b91a7290a59c06d
SHA256: E07CAD0704296D6475FD1145272C05BCBE2B5F000509FCF9ED33FAFD3453C3B5
File Size: 2.50 MB, 2496277 bytes
MD5: 98001ff9867aa0d512257a2b4e399c81
SHA1: 8abd02e8652c170f2afcb1c84938fb1e246194d9
SHA256: 8D65126331265F113351560D7DFB7A89A1939F5C5BF29C42BF7B1C99506A3ECB
File Size: 1.21 MB, 1209344 bytes
MD5: d0b747ed76bc3281976c24aea013775a
SHA1: 1a790b15457dd1fb2225477709f7f5e6477c3010
SHA256: 44D543E9C25251524DBF60816FE1C260EC645B6BDD71DE97D4761C9A5DB3EE85
File Size: 3.85 MB, 3853824 bytes
MD5: 040f14f1b340e5aab9a9f12abb05ca2e
SHA1: fac38182d0af6fc29e5f7c315d052a088637b8e1
SHA256: ED1E6F7ED5F9DAD59A74EE7563987D2BFC2254C24AA963CAD20A188D02344032
File Size: 2.69 MB, 2694656 bytes
MD5: aeb226fb3d0227e1c34777b28aaa585f
SHA1: 12733ec715c068549a9c6af4003b41177f3afdb5
SHA256: 928546611A096D7EF85861213F4735AF142F6D7A980E9FF48DA5082CED03DDB2
File Size: 2.93 MB, 2930799 bytes
MD5: 52ac2db4f53724c19bf6b7247b0dec0e
SHA1: f91f57a5c1c6f67545e415be0efbcec9a0116d92
SHA256: 2CBE367AC3317CAE2ABFE9BF5EA568433B7AE2F0F328ECCDCCD29538F82BA3CA
File Size: 2.85 MB, 2845387 bytes
MD5: 7360dad9d544a5931989636f61f34bbb
SHA1: 18a1a1635de011eee809de1f509f702ee72a08c5
SHA256: 3D88709BA1EB8B40967AB5654F8612E9CA2031D402704F889C1DF56F2E3F6747
File Size: 2.24 MB, 2240512 bytes

Windows Portable Executable Attributes

  • File doesn't have "Rich" header
  • File doesn't have debug information
  • File doesn't have exports table
  • File doesn't have relocations information
  • File doesn't have security information
  • File has TLS information
  • File is .NET application
  • File is 32-bit executable
  • File is 64-bit executable
  • File is either console or GUI application
Show More
  • File is GUI application (IMAGE_SUBSYSTEM_WINDOWS_GUI)
  • File is Native application (NOT .NET application)
  • File is not packed
  • IMAGE_FILE_DLL is not set inside PE header (Executable)
  • IMAGE_FILE_EXECUTABLE_IMAGE is set inside PE header (Executable Image)

File Icons

Windows PE Version Information

Name Value
Assembly Version
  • 2.12.0.0
  • 2.1.0.0
  • 1.0.2.3
  • 1.0.0.0
Comments
  • Automotive Diagnostics Software
  • Synaptics Killer
  • ZeroSecurity0
Company Name
  • AntivirusAPKs_V3
  • Car-Tech Diagnostic
  • RenOLink
  • ZeroKnoxRemoval
File Description
  • AntivirusAPKs_V3
  • Fuckselfed
  • iRemovalProWPF
  • RenOLink
  • StartTruckH
  • Synaptics Killer
  • ZeroKnoxRemoval
File Version
  • 2.12.0.0
  • 2.1.0.0
  • 1.00
  • 1.0.2.4
  • 1.0.0.0
Internal Name
  • AntivirusAPKs_V3.dll
  • ArcticUI.exe
  • iRemovalProWPF.exe
  • RenOLink.exe
  • StartTruck.exe
  • SynapticsKiller.exe
  • TJprojMain
  • ZeroKnoxRemoval.dll
Legal Copyright
  • Copyright © 2022
  • Copyright © 2023
  • Copyright © 2024
  • Copyright © 2025
  • Gabriel Gafu (gabigafu@hotmail.com)
  • Zero Security
Legal Trademarks Car-Tech Diagnostic
Original Filename
  • AntivirusAPKs_V3.dll
  • ArcticUI.exe
  • iRemovalProWPF.exe
  • RenOLink.exe
  • StartTruck.exe
  • SynapticsKiller.exe
  • TJprojMain.exe
  • ZeroKnoxRemoval.dll
Product Name
  • AntivirusAPKs_V3
  • Fuckselfed
  • iRemovalProWPF
  • Project1
  • RenOLink
  • StartTruckH
  • Synaptics Killer
  • ZeroKnoxRemoval
Product Version
  • 2.12.0.0
  • 1.00
  • 1.0.2.4
  • 1.0.0.0
  • 1.0.0

File Traits

  • .NET
  • 2+ executable sections
  • Confuser
  • HighEntropy
  • NewLateBinding
  • ntdll
  • RijndaelManaged
  • vmp section variant
  • x64
  • x86

Block Information

Total Blocks: 2,188
Potentially Malicious Blocks: 270
Whitelisted Blocks: 474
Unknown Blocks: 1,444

Visual Map

0 x 0 ? ? 0 0 ? ? ? 0 ? ? ? ? x 0 0 0 0 0 0 ? 0 0 ? 0 0 ? 0 0 0 0 ? 0 ? 0 0 0 0 ? ? 0 x 0 0 0 0 ? ? ? 0 0 0 0 0 0 0 ? ? 0 ? 0 0 ? ? ? 0 0 0 0 x 0 0 0 0 0 ? ? ? ? ? ? ? x 0 ? 0 0 ? 0 0 0 0 0 0 0 0 ? 0 0 0 ? 0 0 0 0 0 ? 0 ? ? 0 ? x ? 0 0 0 ? 0 0 x 0 x ? 0 0 0 0 0 0 0 x 0 x 0 0 0 0 0 x 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 x 0 0 0 x 0 0 0 0 0 0 x 0 0 x 0 x x ? ? ? ? ? ? ? ? x ? ? ? ? x ? ? ? ? ? ? ? x ? ? ? ? ? ? ? ? ? x ? ? x 0 ? ? ? x ? ? ? ? ? ? ? ? ? ? ? ? ? ? ? ? ? ? ? ? ? ? x ? x ? ? ? x x x 0 ? ? ? ? ? ? ? ? ? ? ? ? ? ? x ? ? ? ? ? ? ? ? x ? ? ? x ? ? ? ? ? ? ? ? ? ? ? ? ? ? ? x ? ? ? ? ? ? ? ? ? ? ? ? ? ? ? ? ? ? ? ? ? ? ? ? ? ? ? ? ? ? ? ? ? ? ? ? ? ? ? x ? ? ? ? ? ? ? ? ? ? ? ? ? ? ? ? ? ? ? ? ? x ? ? ? x ? ? ? ? ? ? ? ? x ? ? ? ? ? ? ? ? x ? ? ? ? ? x ? ? ? ? ? ? ? ? ? ? ? x ? ? ? ? x ? x ? ? ? ? x ? ? ? ? x ? ? ? ? ? ? ? ? ? ? ? ? x ? ? ? ? ? ? ? ? x ? ? ? x ? ? ? ? ? x ? ? x ? ? ? ? ? ? ? x ? x ? x ? ? ? ? ? x ? ? ? ? ? x ? ? ? x ? ? ? ? ? ? ? ? ? ? ? ? ? 0 ? ? ? ? ? x x x ? ? ? ? ? ? ? ? ? ? ? ? ? ? ? ? ? ? ? ? ? ? x ? ? x ? x ? x ? ? ? x ? ? ? ? x ? ? x ? ? ? ? ? ? ? ? ? ? ? ? ? ? ? ? ? ? ? ? ? ? ? ? x ? ? ? x ? ? ? ? ? x x ? ? ? ? ? ? ? ? ? x ? ? ? ? ? ? ? ? ? ? ? ? ? ? ? ? ? ? ? ? ? ? ? ? ? x ? ? ? x ? x x ? x ? ? ? ? ? ? ? ? ? ? ? ? ? ? x ? x ? ? ? ? ? ? ? ? ? ? x ? ? ? ? ? x ? ? ? ? ? ? ? ? ? 0 ? ? ? ? ? ? x ? ? ? ? ? ? x ? ? ? x ? ? ? ? ? ? ? ? ? ? ? ? ? ? ? ? ? ? ? ? ? ? ? ? ? ? ? ? ? ? ? ? ? ? x ? ? ? ? x x x ? ? ? ? ? ? x ? ? 0 ? x ? ? ? x ? ? ? ? ? x ? ? ? x ? ? ? ? ? ? ? ? ? x x ? ? ? ? x ? ? ? ? x ? ? ? ? x ? ? ? ? x ? ? ? ? ? ? ? ? ? ? ? ? ? ? ? ? ? ? ? ? ? ? ? ? ? ? ? x ? ? ? ? ? ? ? ? ? ? ? x ? ? ? ? ? ? ? ? ? ? ? ? ? ? ? ? ? ? x x ? ? ? ? ? ? ? ? ? ? x ? ? ? x ? ? ? x ? ? ? ? x ? ? ? ? ? ? ? ? ? x ? ? ? ? ? ? ? ? ? ? ? ? ? ? ? x ? ? ? ? ? ? ? ? ? ? ? ? 0 ? ? ? x ? x ? ? x ? ? x ? ? ? ? ? ? ? ? ? ? ? x x x ? ? ? ? ? 0 0 x 0 0 0 0 0 0 0 0 x x x x x x x x x x x x x x x x x x x x x x x x x x x x x x x x x x x x x x x x x x x x x x x x x x x x x x x x x x x x x x x x x x x x x x x x x x x x x x x x x x x x x x x x x x x x x ? ? ? ? ? ? ? ? ? ? ? 0 ? ? ? ? ? ? ? ? ? ? ? ? ? x 0 ? ? ? ? ? ? ? ? ? ? ? ? ? ? ? ? ? x ? ? ? ? ? ? ? ? ? ? ? ? ? ? ? ? ? ? ? ? ? ? ? ? ? ? ? ? ? ? ? ? ? ? ? ? ? ? ? ? ? ? ? ? ? ? ? ? ? ? ? ? ? ? ? ? ? ? ? ? ? ? ? ? ? ? ? ? ? ? ? ? ? ? ? ? ? ? ? ? ? ? ? ? ? ? ? ? ? ? ? ? ? ? ? ? ? ? ? ? ? ? ? ? ? ? ? ? ? ? ? ? ? ? ? ? ? ? ? ? ? ? ? ? ? ? ? ? ? ? ? ? ? ? ? ? ? ? ? ? ? ? ? ? ? ? ? ? ? ? ? ? ? ? ? ? 0 0 0 0 0 0 0 0 0 ? ? ? ? ? ? ? ? ? ? ? ? ? ? ? ? ? ? ? ? ? 0 0 0 0 ? ? ? ? ? ? ? ? ? ? ? ? ? ? ? ? ? ? ? x x ? ? ? ? ? ? ? ? ? ? ? ? ? ? ? ? ? ? ? ? ? ? ? 0 ? ? ? ? ? ? ? ? ? ? ? ? ? ? 0 0 0 ? ? ? ? ? ? ? ? ? ? ? ? ? ? ? ? ? ? ? ? ? ? ? ? ? x ? ? ? ? ? ? ? ? x ? x ? x ? x ? x ? x ? x 0 0 ? ? x ? x ? x ? x ? x ? x ? x x ? ? ? ? ? ? ? ? ? ? ? ? ? ? ? ? ? ? ? ? ? ? ? ? ? ? ? ? ? ? x ? x ? x ? x ? ? ? ? ? ? ? ? ? ? ? ? ? ? ? ? ? ? ? ? x ? ? ? ? ? ? ? ? ? ? ? ? ? ? ? ? ? ? ? ? ? ? x ? ? ? ? ? ? ? ? ? ? ? ? ? ? ? ? ? ? ? ? ? ? ? ? ? ? ? ? ? ? ? ? x ? ? ? ? x x ? ? ? ? ? ? x ? ? ? ? ? ? ? ? ? ? ? ? ? ? x ? ? 0 ? 0 0 x 0 0 0 0 0 0 0 0 0 0 0 0 0 0 ? x ? ? ? ? ? ? ? 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 ? ? 0 0 0 0 0 0 0 0 0 0 0 0 0 0 ? ? ? ? ? ? ? ? ? ? ? ? ? 0 ? ? ? ? ? ? ? ? ? ? ? ? ? ? ? ? ? ? ? ? ? ? ? ? ? ? ? ? ? ? ? ? ? ? ? ? ? ? ? ? ? ? ? ? ? ? ? ? ? ? ? ? ? ? ? ? ? ? ? ? ? ? ? ? ? ? ? ? ? ? ? ? ? ? ? ? ? ? ? ? ? ? ? ? ? ? ? ? ? ? ? 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 ? ? 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 x ? ? ? 0 0 ? ? 0 ? ? ? ? ? ? ? ? ? ? 0 0 0 0 0 0 0 0 0 ? ? 0 0 ? ? ? ? ? x ? 0 ? 0 ? ? 0 0 0 0 0 0 0 x 0 0 ? ? ? ? ? ? ? ? ? ? ? ? x 0 ? 0 0 0 x 0 0 0 0 x x ? ? ? ? ? ? ? ? ? ? ? 0 0 0 0 0 ? 0 x 0 0 0 0 0 0 x 0 0 ? ? ? ? ? ? 0 ? ? 0 ? 0 0 ? 0 0 0 ? 0 x 0 0 ? 0 0 ? ? ? ? ? ? ? ? ? ? 0 ? 0 x 0 ? 0 x 0 0 0 0 ? 0 0 x 0 x 0 0 0 0 0 0 x 0 x 0 x 0 ? ? 0 0 0 ? 0 0 0 0 0 ? 0 0 0 0 0 0 0 0 0 ? 0 0 0 0 0 0 x 0 0 0 ? 0 ? 0 0 0 0 0 0 0 ? 0 0 ? 0 0 0 0 0 0 ? 0 0 x ? ? ? 0 0 0 ? 0 ? ? 0 x ? 0 0 0 ? ? ? ? 0 0 ? ? ? 0 0 0 0 0 x ? 0 x x ? ? 0 0 0 ? ? 0 ? 0 0 ? x ? 0 ? 0 0 ? ? ? ? 0 0 ? ? 0 0 0 0 0 0 0 0 0 x 0 ? ? ? ? ? ? ? ? ? ? ? ? 0 0 0 ? ? 0 0 0 0 0 0 0 0 0 0 0 0 ? ? ? 0 0 0 ? 0 x 0 0 0 0 0 0 ? ? ? ? ? ? 0 x x ? 0 0 0 0 ? ? ? ? ? 0 0 0 ? 0 ? ? 0 ? 0 ? ? 0 ? 0 ? x ? ? 0 ? ?
... Data truncated
0 - Probable Safe Block
? - Unknown Block
x - Potentially Malicious Block

Windows API Usage

Category API
User Data Access
  • GetComputerNameEx
  • GetUserDefaultLocaleName
  • GetUserObjectInformation
Syscall Use
  • ntdll.dll!NtAddAtomEx
  • ntdll.dll!NtAlertThreadByThreadId
  • ntdll.dll!NtAlpcSendWaitReceivePort
  • ntdll.dll!NtApphelpCacheControl
  • ntdll.dll!NtClearEvent
  • ntdll.dll!NtClose
  • ntdll.dll!NtCreateEvent
  • ntdll.dll!NtCreateFile
  • ntdll.dll!NtCreateKey
  • ntdll.dll!NtCreateMutant
Show More
  • ntdll.dll!NtCreatePrivateNamespace
  • ntdll.dll!NtCreateSection
  • ntdll.dll!NtCreateThreadEx
  • ntdll.dll!NtDeviceIoControlFile
  • ntdll.dll!NtDuplicateObject
  • ntdll.dll!NtEnumerateKey
  • ntdll.dll!NtEnumerateValueKey
  • ntdll.dll!NtFlushProcessWriteBuffers
  • ntdll.dll!NtFreeVirtualMemory
  • ntdll.dll!NtGetContextThread
  • ntdll.dll!NtGetWriteWatch
  • ntdll.dll!NtMapViewOfSection
  • ntdll.dll!NtOpenDirectoryObject
  • ntdll.dll!NtOpenEvent
  • ntdll.dll!NtOpenFile
  • ntdll.dll!NtOpenKey
  • ntdll.dll!NtOpenKeyEx
  • ntdll.dll!NtOpenProcess
  • ntdll.dll!NtOpenProcessToken
  • ntdll.dll!NtOpenSection
  • ntdll.dll!NtOpenThreadToken
  • ntdll.dll!NtProtectVirtualMemory
  • ntdll.dll!NtQueryAttributesFile
  • ntdll.dll!NtQueryDefaultLocale
  • ntdll.dll!NtQueryDirectoryFileEx
  • ntdll.dll!NtQueryFullAttributesFile
  • ntdll.dll!NtQueryInformationFile
  • ntdll.dll!NtQueryInformationJobObject
  • ntdll.dll!NtQueryInformationProcess
  • ntdll.dll!NtQueryInformationThread
  • ntdll.dll!NtQueryInformationToken
  • ntdll.dll!NtQueryKey
  • ntdll.dll!NtQueryLicenseValue
  • ntdll.dll!NtQueryPerformanceCounter
  • ntdll.dll!NtQuerySecurityAttributesToken
  • ntdll.dll!NtQuerySecurityObject
  • ntdll.dll!NtQuerySystemInformation
  • ntdll.dll!NtQuerySystemInformationEx
  • ntdll.dll!NtQueryValueKey
  • ntdll.dll!NtQueryVirtualMemory
  • ntdll.dll!NtQueryVolumeInformationFile
  • ntdll.dll!NtQueryWnfStateData
  • ntdll.dll!NtReadFile
  • ntdll.dll!NtReadRequestData
  • ntdll.dll!NtReleaseMutant
  • ntdll.dll!NtReleaseWorkerFactoryWorker
  • ntdll.dll!NtResetWriteWatch
  • ntdll.dll!NtResumeThread
  • ntdll.dll!NtSetEvent
  • ntdll.dll!NtSetInformationKey
  • ntdll.dll!NtSetInformationProcess
  • ntdll.dll!NtSetInformationThread
  • ntdll.dll!NtSetInformationVirtualMemory
  • ntdll.dll!NtSetInformationWorkerFactory
  • ntdll.dll!NtSubscribeWnfStateChange
  • ntdll.dll!NtSuspendThread
  • ntdll.dll!NtTestAlert
  • ntdll.dll!NtTraceControl
  • ntdll.dll!NtUnmapViewOfSection
  • ntdll.dll!NtUnmapViewOfSectionEx
  • ntdll.dll!NtWaitForAlertByThreadId
  • ntdll.dll!NtWaitForSingleObject
  • ntdll.dll!NtWaitForWorkViaWorkerFactory
  • ntdll.dll!NtWaitLowEventPair
  • ntdll.dll!NtWriteFile
  • ntdll.dll!NtYieldExecution
  • UNKNOWN
Network Winsock2
  • WSASocket
  • WSAStartup
Network Winsock
  • closesocket
  • gethostname
  • setsockopt
Network Info Queried
  • GetAdaptersAddresses
  • GetNetworkParams
Encryption Used
  • BCryptOpenAlgorithmProvider
Anti Debug
  • IsDebuggerPresent
Other Suspicious
  • SetWindowsHookEx

Related Posts

Trending

Most Viewed

Loading...