Threat Database Keyloggers Trojan.Keylogger.BI

Trojan.Keylogger.BI

By CagedTech in Keyloggers, Trojans

Analysis Report

General information

Family Name: Trojan.Keylogger.BI
Signature status: No Signature

Known Samples

MD5: cb4679515ba89ae6fc2377a79e239459
SHA1: d6a3a14a6502338ff62b6a004d42310712f1dd93
SHA256: C7D8EF0D1BDBCB19032C1E87A56F533851727C9C19362CE154D661BB8DE3D75C
File Size: 3.00 MB, 2997760 bytes

Windows Portable Executable Attributes

  • File doesn't have "Rich" header
  • File doesn't have relocations information
  • File doesn't have security information
  • File has exports table
  • File has TLS information
  • File is 32-bit executable
  • File is either console or GUI application
  • File is GUI application (IMAGE_SUBSYSTEM_WINDOWS_GUI)
  • File is Native application (NOT .NET application)
  • File is not packed
Show More
  • IMAGE_FILE_DLL is not set inside PE header (Executable)
  • IMAGE_FILE_EXECUTABLE_IMAGE is set inside PE header (Executable Image)

File Icons

Windows PE Version Information

Name Value
File Description AutoHotkey_H Unicode 32-bit
File Version 1.1.33.10-H005
Internal Name AutoHotkey_H
Legal Copyright Copyright (C) 2003-2014
Original Filename AutoHotkey.exe
Product Name AutoHotkey_H
Product Version 1.1.33.10-H005

File Traits

  • AutoHK
  • HighEntropy
  • Installer Manifest
  • WriteProcessMemory
  • x86

Block Information

Total Blocks: 2,199
Potentially Malicious Blocks: 543
Whitelisted Blocks: 1,656
Unknown Blocks: 0

Visual Map

0 x 0 x x 0 0 x x x x x x 0 x x x 0 x x 0 0 0 0 0 0 x x 0 0 0 0 0 0 x x x 0 0 0 0 0 x x 0 0 0 x 0 x 0 0 0 0 0 x 0 x 0 0 0 0 x 0 0 0 0 0 0 0 0 0 x 0 x 0 x 0 0 x 0 0 x 0 x x x x x x 0 0 0 0 0 0 0 x 0 0 0 0 x 0 0 x 0 x 0 x 0 0 0 0 0 0 0 x 0 0 0 0 0 0 0 0 0 0 0 x 0 x 0 x 0 x x x x x x x 0 0 0 0 0 x 0 0 0 x x x x x x x x x 0 0 0 0 0 0 0 x 0 x 0 0 0 0 0 x x x 0 x x x 0 x x 0 x 0 0 x 0 0 x x 0 0 0 0 0 0 0 x 0 0 0 0 0 0 0 0 0 0 0 0 0 x 0 0 x x 0 0 0 x x 0 x 0 0 0 0 0 x 0 0 0 0 x x 0 0 0 x 0 0 0 x x x x x x 0 0 0 0 0 0 0 x 0 0 x 0 x 0 0 0 0 0 x 0 0 0 0 0 x x 0 x x x 0 x x 0 0 0 0 0 0 0 0 0 0 0 0 0 x 0 0 x 0 0 0 0 0 0 x x x x 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 x 0 0 0 x 0 x 0 0 0 0 0 0 0 0 0 0 x 0 0 0 0 0 0 0 0 x 0 0 0 0 x x x x x x 0 x x x 0 0 0 0 0 0 x x 0 x 0 x x x 0 0 x x 0 x x x 0 x 0 0 x x x x x x x 0 0 x x x x x x x x x x x x 0 x 0 0 0 0 x x 0 x 0 0 0 0 0 0 0 x x 0 0 x x x 0 x 0 0 x 0 0 x 0 0 0 0 0 x x 0 x 0 0 0 0 0 0 x 0 0 x x 0 x 0 0 x x x x x x x x x x x x x x x 0 x x 0 0 0 0 0 0 0 0 0 0 0 0 0 0 x 0 0 x 0 x x x x 0 x x x 0 0 0 0 0 x 0 0 0 x x x x 0 0 0 0 0 x x 0 x x x x x 0 0 0 0 0 x 0 0 0 0 0 0 0 0 0 0 x 0 0 0 0 x 0 x x x 0 0 0 0 0 x x x 0 0 0 x 0 0 x 0 0 0 0 0 0 0 0 0 0 0 x 0 0 0 0 0 0 0 0 0 0 0 x 0 0 0 0 0 0 0 0 0 0 x 0 0 x x x x x x x 0 0 0 0 0 0 x 0 0 x x x 0 0 0 0 0 0 0 0 0 0 0 0 x 0 0 x 0 x 0 0 0 0 0 0 0 0 0 x 0 0 0 0 0 0 0 0 x x x x 0 x x x 0 0 x 0 x 0 0 0 0 0 x 0 0 0 0 0 0 0 x x x x 0 0 0 x x x 0 0 0 0 0 0 0 0 0 0 0 0 0 0 x 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 x 0 0 0 0 0 0 0 x 0 0 0 0 0 0 x 0 0 0 0 0 0 0 0 0 0 0 0 0 0 x 0 0 0 0 0 0 x x 0 0 0 0 0 x 0 0 x 0 0 0 0 0 0 x 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 x x 0 0 0 0 0 0 0 x 0 0 x 0 0 x 0 0 0 0 0 0 0 x 0 0 0 0 0 0 0 0 0 0 0 0 0 0 x x 0 0 0 0 0 0 0 0 0 0 x 0 x x x x 0 0 0 0 0 0 0 x 0 0 0 0 0 0 0 0 0 0 0 0 0 x 0 0 0 x x 0 0 0 0 0 x x x x x x 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 x 0 x 0 0 x 0 x x x 0 0 0 0 0 0 0 0 0 0 0 0 0 x 0 0 x 0 0 0 x x 0 x x x 0 x 0 x x 0 0 0 0 x 0 0 x 0 x 0 0 x x 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 x x 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 x 0 x x x 0 0 0 0 0 0 0 0 0 0 0 0 0 0 x 0 0 0 0 0 0 0 x 0 x 0 0 0 0 x 0 x 0 0 0 x 0 0 0 0 0 x x x x 0 x x x 0 0 0 x 0 x x x x 0 0 0 x x x 0 0 0 0 0 0 0 0 0 0 x x x 0 0 0 x x x x 0 0 0 0 0 x x 0 0 0 0 0 0 0 0 0 x 0 0 0 0 0 0 0 x x 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 x x x x x 0 x x 0 0 0 0 0 0 x x x x 0 x 0 0 0 0 0 0 0 0 0 0 0 0 0 0 x 0 x 0 0 0 0 0 0 0 x 0 0 0 x 0 0 0 0 0 0 0 0 x 0 0 0 0 0 0 0 0 0 0 0 x x x x x 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 x 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 x 0 x 0 0 0 0 0 0 0 x x x x 0 0 0 x x x x 0 0 0 0 0 0 0 0 0 x x 0 x x 0 x x 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 x x x 0 0 0 0 x 0 0 0 0 0 0 0 x 0 x x 0 0 0 x 0 0 0 0 0 0 0 x 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 x 0 x 0 x x x 0 0 0 0 0 x 0 x x 0 0 0 0 0 x 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 x 0 0 0 0 0 0 x 0 0 x x x x 0 0 0 0 0 0 0 0 x x 0 x 0 x 0 0 0 0 0 0 0 0 0 0 0 x x 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 x x x x x x 0 x x 0 0 0 x 0 x x 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 x 0 0 0 0 0 x 0 0 x 0 x x 0 x x 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 x x 0 0 0 0 x x 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 x 0 0 0 0 0 0 0 x 0 0 0 0 0 0 0 0 0 0 0 0 x 0 0 0 0 0 0 0 0 0 0 0 0 0 0 x x 0 0 0 0 0 0 0 0 x 0 0 0 0 x x x x x 0 0 0 0 0 x 0 x 0 x 0 0 0 0 0 x x x 0 0 x x 0 0 x x 0 0 0 0 0 0 x 0 0 0 0 0 0 0 0 0 0 0 x 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 x 0 x x x 0 0 0 0 0 x 0 x 0 0 0 x x x 0 0 0 0 0 0 0 x x 0 0 0 0 0 0 x x 0 0 0 0 x x 0 0 0 0 0 0 0 0 0 x x x x 0 0 x x x x 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 x 0 0 0 0 0 0 0 x 0 0 0 0 0 0 0 0 0 0 x 0 0 0 0 0 0 0 0 0 0 x 0 x 0 0 x x 0 0 x 0 0 0 0 0 0 0 0 0 0 0 0 x 0 x x 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 x 0 0 0 0 0 0 0 x 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 x x 0 0 0 0 0 0 x x 0 0 0 0 0 x 0 0 0 0 x x 0 0 0 0 0 x x x 0 x 0 0 0 x 0 x 0 0 x 0 x x x 0 0 x x 0 0 0 0 0 0 0 0 x x 0 0 0 0 0 0 0 0 0 0 x 0 0 0 0 0 0 x 0 0 0 x x x 0 0 0 0 0 0 x x 0 x x 0 0 x 0 0 0 0 x 0 0 x 0 0 x x 0 x x x x 0 0 0 0 0 0 0 0 0 x 0 0 0 0 0 x 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0
... Data truncated
0 - Probable Safe Block
? - Unknown Block
x - Potentially Malicious Block

Similar Families

  • Keylogger.BI
  • Stealer.BAA

Trending

Most Viewed

Loading...