File 945ACE2428D95A13.Rubeus.exe.avg.exe

Name: 945ACE2428D95A13.Rubeus.exe.avg.exe
Size: 457,216 bytes
MD5: 66368745046c31217b2a1e7fc7c11f24
Scanner Name: avg
Appraisal: Fragile (AND) based
Scan Debug: Duration: 492s / Chunks: 199 / Matches: 32
Scan date: 2023-07-07 17:33:19


# Iteration Offset Size Section Detail SectionType Conclusion
0 0 166304 8 .text #~ DATA Dominant. Modify this to make file undetected
1 0 166318 22 .text #~ DATA Dominant. Modify this to make file undetected
2 0 166570 8 .text #~ TypeRef DATA Dominant. Modify this to make file undetected
4 0 166592 14 .text #~ TypeRef DATA Dominant. Modify this to make file undetected
5 0 166806 11 .text #~ TypeRef DATA Dominant. Modify this to make file undetected
6 0 166834 6 .text #~ TypeRef DATA Dominant. Modify this to make file undetected
7 0 166845 6 .text #~ TypeRef DATA Dominant. Modify this to make file undetected
8 0 167307 11 .text #~ TypeRef DATA Dominant. Modify this to make file undetected
9 0 167907 5 .text #~ TypeRef DATA Dominant. Modify this to make file undetected
10 1 263457 7 .text #Strings DATA Dominant. Modify this to make file undetected
11 1 274430 7 .text #Strings DATA Dominant. Modify this to make file undetected
14 1 292126 39 .text #Strings DATA Dominant. Modify this to make file undetected
15 1 294799 30 .text #Strings DATA Dominant. Modify this to make file undetected
16 1 295722 20 .text #Strings DATA Dominant. Modify this to make file undetected
17 1 296785 54 .text #Strings DATA Dominant. Modify this to make file undetected
18 1 298816 29 .text #Strings DATA Dominant. Modify this to make file undetected
19 1 302252 13 .text #Strings DATA Dominant. Modify this to make file undetected
20 1 309264 51 .text #Strings DATA Dominant. Modify this to make file undetected

Match 0: 166304 (size: 8)

Dominant. Modify this to make file undetected

.text #~

000289A0   57 FF A2 3F 09 1E 00 00                            W..?....

Match 1: 166318 (size: 22)

Dominant. Modify this to make file undetected

.text #~

000289AE   00 00 01 00 00 00 F7 00 00 00 67 01 00 00 A4 06    ..........g.....
000289BE   00 00 22 08 00 00                                  .."...

Match 2: 166570 (size: 8)

Dominant. Modify this to make file undetected

.text #~ TypeRef

00028AAA   B0 87 B7 CA 06 00 8B 07                            ........

0x28aa8: TypeRef[22]: ResolutionScope: ref table AssemblyRef[1] TypeName: AsymmetricAlgorithm TypeNamespace: System.Security.Cryptography
0x28aae: TypeRef[23]: ResolutionScope: ref table AssemblyRef[1] TypeName: Func`1 TypeNamespace: System

Match 4: 166592 (size: 14)

Dominant. Modify this to make file undetected

.text #~ TypeRef

00028AC0   06 00 FE 99 B7 CA 06 00 D6 A1 B7 CA 06 00          ..............

0x28ac0: TypeRef[26]: ResolutionScope: ref table AssemblyRef[1] TypeName: RSACryptoServiceProvider TypeNamespace: System.Security.Cryptography
0x28ac6: TypeRef[27]: ResolutionScope: ref table AssemblyRef[1] TypeName: RandomNumberGenerator TypeNamespace: System.Security.Cryptography
0x28acc: TypeRef[28]: ResolutionScope: ref table AssemblyRef[1] TypeName: MulticastDelegate TypeNamespace: System

Match 5: 166806 (size: 11)

Dominant. Modify this to make file undetected

.text #~ TypeRef

00028B96   8D 87 06 00 E4 99 B7 CA 06 00 91                   ...........

0x28b92: TypeRef[61]: ResolutionScope: ref table AssemblyRef[1] TypeName: Guid TypeNamespace: System
0x28b98: TypeRef[62]: ResolutionScope: ref table AssemblyRef[1] TypeName: SHA1CryptoServiceProvider TypeNamespace: System.Security.Cryptography
0x28b9e: TypeRef[63]: ResolutionScope: ref table AssemblyRef[1] TypeName: Tuple`4 TypeNamespace: System

Match 6: 166834 (size: 6)

Dominant. Modify this to make file undetected

.text #~ TypeRef

00028BB2   90 42 B7 CA 16 00                                  .B....

0x28bb0: TypeRef[66]: ResolutionScope: ref table AssemblyRef[2] TypeName: Oid TypeNamespace: System.Security.Cryptography
0x28bb6: TypeRef[67]: ResolutionScope: ref table AssemblyRef[5] TypeName: SignedCms TypeNamespace: System.Security.Cryptography.Pkcs

Match 7: 166845 (size: 6)

Dominant. Modify this to make file undetected

.text #~ TypeRef

00028BBD   00 1F 92 B7 CA 06                                  ......

0x28bbc: TypeRef[68]: ResolutionScope: ref table AssemblyRef[1] TypeName: CryptographicException TypeNamespace: System.Security.Cryptography
0x28bc2: TypeRef[69]: ResolutionScope: ref table AssemblyRef[1] TypeName: NullReferenceException TypeNamespace: System

Match 8: 167307 (size: 11)

Dominant. Modify this to make file undetected

.text #~ TypeRef

00028D8B   00 B3 17 B7 CA 06 00 3C AF B7 CA                   .......<...

0x28d8a: TypeRef[145]: ResolutionScope: ref table AssemblyRef[1] TypeName: RSA TypeNamespace: System.Security.Cryptography
0x28d90: TypeRef[146]: ResolutionScope: ref table AssemblyRef[1] TypeName: RSAParameters TypeNamespace: System.Security.Cryptography

Match 9: 167907 (size: 5)

Dominant. Modify this to make file undetected

.text #~ TypeRef

00028FE3   00 BA 95 B7 CA                                     .....

0x28fe2: TypeRef[245]: ResolutionScope: ref table AssemblyRef[1] TypeName: CspKeyContainerInfo TypeNamespace: System.Security.Cryptography

Match 10: 263457 (size: 7)

Dominant. Modify this to make file undetected

.text #Strings

00040521   41 00 52 53 41 00 5F                               A.RSA._

Match 11: 274430 (size: 7)

Dominant. Modify this to make file undetected

.text #Strings

00042FFE   64 00 4F 69 64 00 67                               d.Oid.g

Match 14: 292126 (size: 39)

Dominant. Modify this to make file undetected

.text #Strings

0004751E   6D 00 41 73 79 6D 6D 65 74 72 69 63 41 6C 67 6F    m.AsymmetricAlgo
0004752E   72 69 74 68 6D 00 48 61 73 68 41 6C 67 6F 72 69    rithm.HashAlgori
0004753E   74 68 6D 00 4B 65 79                               thm.Key

Match 15: 294799 (size: 30)

Dominant. Modify this to make file undetected

.text #Strings

00047F8F   43 72 79 70 74 6F 67 72 61 70 68 69 63 45 78 63    CryptographicExc
00047F9F   65 70 74 69 6F 6E 00 41 72 69 74 68 6D 65          eption.Arithme

Match 16: 295722 (size: 20)

Dominant. Modify this to make file undetected

.text #Strings

0004832A   43 73 70 4B 65 79 43 6F 6E 74 61 69 6E 65 72 49    CspKeyContainerI
0004833A   6E 66 6F 00                                        nfo.

Match 17: 296785 (size: 54)

Dominant. Modify this to make file undetected

.text #Strings

00048751   65 72 00 53 48 41 31 43 72 79 70 74 6F 53 65 72    er.SHA1CryptoSer
00048761   76 69 63 65 50 72 6F 76 69 64 65 72 00 52 53 41    viceProvider.RSA
00048771   43 72 79 70 74 6F 53 65 72 76 69 63 65 50 72 6F    CryptoServicePro
00048781   76 69 64 65 72 00                                  vider.

Match 18: 298816 (size: 29)

Dominant. Modify this to make file undetected

.text #Strings

00048F40   72 61 74 6F 72 00 52 61 6E 64 6F 6D 4E 75 6D 62    rator.RandomNumb
00048F50   65 72 47 65 6E 65 72 61 74 6F 72 00 67             erGenerator.g

Match 19: 302252 (size: 13)

Dominant. Modify this to make file undetected

.text #Strings

00049CAC   52 53 41 50 61 72 61 6D 65 74 65 72 73             RSAParameters

Match 20: 309264 (size: 51)

Dominant. Modify this to make file undetected

.text #Strings

0004B810   65 70 6B 65 79 00 4F 61 6B 6C 65 79 00 48 61 73    epkey.Oakley.Has
0004B820   4E 6F 74 69 66 79 00 53 79 73 74 65 6D 2E 53 65    Notify.System.Se
0004B830   63 75 72 69 74 79 2E 43 72 79 70 74 6F 67 72 61    curity.Cryptogra
0004B840   70 68 79                                           phy

Test # MatchOrder ModifyPosition Match#0
#~ 8b
#~ 22b
#~ 8b
#~ 5b
#~ 14b
#~ 11b
#~ 6b
#~ 6b
#~ 11b
#~ 5b
#Strings 7b
#Strings 7b
#Strings 10b
#Strings 6b
#Strings 39b
#Strings 30b
#Strings 20b
#Strings 54b
#Strings 29b
#Strings 13b
#Strings 51b
4 INCREMENTAL MIDDLE8 1 14 15 16 17 18 20
5 INCREMENTAL FULL 0 1 2 3 4 5 6 7 8 9 10 11 12 13 14 15 16 17 18 19 20
6 DECREMENTAL FULL 20 19 18 17 16 15 14 13 12 11 10 9 8 7 6 5 4 3 2 1 0
7 ALL MIDDLE8 0 0 0 0 0 0 0
8 ALL THIRDS4 0 0 0 0 0 0 0
9 ALL FULL 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0



  • Green: Not detected
  • Red: Detected by AV

Match Order

  • Isolated: Test each match individually, by themselves. At most one match is modified per scan
  • Incremental: Modify each match after another, additive. At the end, all matches are modified
  • Decremental: Modify each match after another, additive, downwards (last first)


  • ModifyPosition FULL: Overwrite complete match: MMMMMMMMMMMM
  • ModifyPosition MIDDLE8: Overwrite 8 bytes in the middle of the match (partial): aaaaMMMMMMMMaaaa
  • ModifyPosition THIRD8: Overwrite 8 bytes in the first and second third of the match (partial): aaaaMMMMMMMMaaaaMMMMMMMMaaaa
