Backdoor.Win32.SrvCmd.b
Named backdoor, hacktool strings
Disclosed hacktool set (old stuff) - file 2323.exePercent-encoded content decoded
SHA-2569a01121aa95c9010204acd242284ff46870067dd6204a4f092c3ec80da89da7f
MaleculeMdTh
Evidence
⋯7 more rows
0x2100c020000006c0000000000000000700200....l........p..
0x2101c4572726f722025643a2025730a000000Error %d: %s....
0x2102c4572726f722025643a2057696e736f63Error %d: Winsoc
0x2103c6b2053746172747570204661696c7572k Startup Failur
0x2104c650a0000000000000000000041636365e...........Acce
0x2105c7074656420636f6e6e656374696f6e20pted connection
0x2106c66726f6d20636c69656e742061742025from client at %
0x2107c730a000000000000000000004572726fs...........Erro
0x2108c723a20616363657074206661696c6564r: accept failed
0x2109c0a000000000000004661696c65642074........Failed t
0x210ac6f2065786563757465207368656c6c00o execute shell.
0x210bc00000000636d642e6578650000000000....cmd.exe.....
⋯5 more rows
0x2111c636b657400000000000000002f680000cket......../h..
0x2112c55736167653a20737276636d642e6578Usage: srvcmd.ex
0x2113c65205b2f685d205b706f72745d0a2f3fe [/h] [port]./?
0x2114c2020202d2053686f7720746869730a2f - Show this./
0x2115c682020202d20486964652057696e646fh - Hide Windo
0x2116c770a706f7274202d20506f727420746fw.port - Port to
0x2117c206c697374656e206f6e2c2064656661 listen on, defa
0x2118c756c747320746f20323332330a000000ults to 2323....
0x2119c00000000000000000000000000000000................
⋯15 more rows
⋯3 more rows
0x2167866726565206661696c7572652e0a0000free failure....
0x216886d656d6f727920636865636b20657272memory check err
0x216986f7220617420307825303858203d2030or at 0x%08X = 0
0x216a878253032582c2073686f756c64206265x%02X, should be
⋯7 more rows