SlideShare a Scribd company logo
sigcheck main option
@Sh1n0g1
no option
>sigcheck Shinobot.exe
Sigcheck v2.30 - File version and signature viewer
Copyright (C) 2004-2015 Mark Russinovich
Sysinternals - www.sysinternals.com
E:DesktopShinoBOT.exe:
Verified: Unsigned
Link date: 17:41 2016/12/22
Publisher: n/a
Company: Sh1n0g1 Inc.
Description: ShinoBOT
Product: ShinoBOT
Prod version: 3.1.0.0
File version: 3.1.0.0
MachineType: 32-bit
-q (quiet)
>sigcheck -q ShinoBOT.exe
E:DesktopShinoBOT.exe:
Verified: Unsigned
Link date: 17:41 2016/12/22
Publisher: n/a
Company: Sh1n0g1 Inc.
Description: ShinoBOT
Product: ShinoBOT
Prod version: 3.1.0.0
File version: 3.1.0.0
MachineType: 32-bit
The following banner disappears.
Sigcheck v2.30 - File version and
signature viewer
Copyright (C) 2004-2015 Mark
Russinovich
Sysinternals - www.sysinternals.com
-a (extended version information, entropy)
>sigcheck -a ShinoBOT.exe
Sigcheck v2.30 - File version and signature viewer
Copyright (C) 2004-2015 Mark Russinovich
Sysinternals - www.sysinternals.com
E:DesktopShinoBOT.exe:
Verified: Unsigned
Link date: 17:41 2016/12/22
Publisher: n/a
Company: Sh1n0g1 Inc.
Description: ShinoBOT
Product: ShinoBOT
Prod version: 3.1.0.0
File version: 3.1.0.0
MachineType: 32-bit
Binary Version: 3.1.0.0
Original Name: SHINOBOT_BUILDER.exe
Internal Name: SHINOBOT_BUILDER.exe
Copyright: Sh1n0g1 Inc.
Comments: RAT simulator
Entropy: 4.719
-h (hashes)
>sigcheck -h ShinoBOT.exe
Sigcheck v2.30 - File version and signature viewer
Copyright (C) 2004-2015 Mark Russinovich
Sysinternals - www.sysinternals.com
E:DesktopShinoBOT.exe:
Verified: Unsigned
Link date: 17:41 2016/12/22
Publisher: n/a
Company: Sh1n0g1 Inc.
Description: ShinoBOT
Product: ShinoBOT
Prod version: 3.1.0.0
File version: 3.1.0.0
MachineType: 32-bit
MD5: 9B2166D3B72C84396EDECE1673E923B7
SHA1: CF8C8D3F48FB1304E0AAB7EFB6C3EB9BBE833BC5
PESHA1: 5A7BAE6C68F50ABA37EB0FDC5B698115DB13C14B
PE256: CB30CF07163B72F49DADA51CDC3965E6F79AA6D9A430524AD81C0D445155CDDC
SHA256: BF7EFF73A37965B7ECD784E621F0B7118402C4C03E450E648B8922F070D440C8
IMP: F34D5F2D4577ED6D9CEEC516C1F5A744
-v (VirusTotal)
>sigcheck -v ShinoBOT1326.exe
Sigcheck v2.30 - File version and signature viewer
Copyright (C) 2004-2015 Mark Russinovich
Sysinternals - www.sysinternals.com
e:WorkShinoBOT1326.exe:
Verified: Unsigned
Link date: 9:23 2013/07/25
Publisher: n/a
Company: Sh1n0g1
Description: ShinoBOT
Product: ShinoBOT
Prod version: 1.3.2.6
File version: 1.3.2.6
MachineType: 32-bit
VT detection: 44/57
VT link:
https://www.virustotal.com/file/e10506ed829846ae5b7cddbb7ff636b18f632f28f072f9
b399b9cbdbd643b8d9/analysis/
-i (signed info)
>sigcheck -i DummyPopup_Signed.exe
Sigcheck v2.30 - File version and signature viewer
Copyright (C) 2004-2015 Mark Russinovich
Sysinternals - www.sysinternals.com
E:DesktopDummyPopup_Signed.exe:
Verified: Signed
Catalog: E:DesktopDummyPopup_Signed.exe
Signer:
Sh1n0g1 Inc
Status: ????????????????????????????????
Valid Usage: All
Serial Number: 01
Thumbprint: 9C85EA7F5672E74E3A5C45279EECBD979B559DDB
Algorithm: SHA1
Valid from: 16:54 2013/11/22
Valid to: 16:54 2015/11/22
Signing date: n/a
Publisher: Sh1n0g1 Inc
Company: n/a
Description: Popup
Product: Popup
Prod version: 1.0.0.0
File version: 1.0.0.0
MachineType: 32-bit
aihqv combined
>sigcheck -a -i -h -q -v DummyPopup_Signed.exe
E:DesktopDummyPopup_Signed.exe:
Verified: Signed
Catalog: E:DesktopDummyPopup_Signed.exe
Signer:
Sh1n0g1 Inc
Status: ????????????????????????????????
Valid Usage: All
Serial Number: 01
Thumbprint: 9C85EA7F5672E74E3A5C45279EECBD979B559DDB
Algorithm: SHA1
Valid from: 16:54 2013/11/22
Valid to: 16:54 2015/11/22
Signing date: n/a
Publisher: Sh1n0g1 Inc
Company: n/a
Description: Popup
Product: Popup
Prod version: 1.0.0.0
File version: 1.0.0.0
MachineType: 32-bit
Binary Version: 1.0.0.0
Original Name: DummyPopup.exe
Internal Name: DummyPopup.exe
Copyright: Copyright ゥ 2013
Comments: n/a
Entropy: 6.755
MD5: 66F65B57235F9886537BB791DB6DFB14
SHA1: D71365CCDC97D0A1BD88A97C81DAD6562749CA0A
PESHA1: AC6275E718A4E334B042B870DD66F3BB759B56FA
PE256: 05D0ABD52B5E3A6C9CBD2033FC806568EEDFD235C0F3297FE9F3F409580A1FAA
SHA256: 821B0E74CBBF042C32A691103D5DC449A1812E9FB0E5185B61B2F21CCCC1E883
IMP: F34D5F2D4577ED6D9CEEC516C1F5A744
VT detection: 1/56
VT link: https://www.virustotal.com/file/821b0e74cbbf042c32a691103d5dc449a1812e9fb0e5185b61b2f21cccc1e883/analysis/

More Related Content

Similar to Sigcheck option memo

DEF CON 27 - HUBER AND ROSKOSCH - im on your phone listening attacking voip c...
DEF CON 27 - HUBER AND ROSKOSCH - im on your phone listening attacking voip c...DEF CON 27 - HUBER AND ROSKOSCH - im on your phone listening attacking voip c...
DEF CON 27 - HUBER AND ROSKOSCH - im on your phone listening attacking voip c...
Felipe Prado
 
Lewis brady engine_terminology (edited version)
Lewis brady engine_terminology (edited version)Lewis brady engine_terminology (edited version)
Lewis brady engine_terminology (edited version)
LewisB2013
 
console32.vswindows32v15.suoconsole32.vswindows32v15.docx
console32.vswindows32v15.suoconsole32.vswindows32v15.docxconsole32.vswindows32v15.suoconsole32.vswindows32v15.docx
console32.vswindows32v15.suoconsole32.vswindows32v15.docx
aidaclewer
 
Active proxied sessions
Active proxied sessionsActive proxied sessions
Active proxied sessionsds5ysm
 
growthbotics audit.pdf
growthbotics audit.pdfgrowthbotics audit.pdf
growthbotics audit.pdf
Wilson Kao
 
Serial number soft
Serial number softSerial number soft
Serial number soft
sandi271979
 
Electrical Schematic Open Hardware PowerPC Notebook motherboard v. 0.5
 Electrical Schematic Open Hardware PowerPC Notebook motherboard v. 0.5 Electrical Schematic Open Hardware PowerPC Notebook motherboard v. 0.5
Electrical Schematic Open Hardware PowerPC Notebook motherboard v. 0.5
Roberto Innocenti
 
Open Hardware PowerPC Notebook motherboard V.0.6 August 2020
Open Hardware PowerPC Notebook motherboard V.0.6 August 2020Open Hardware PowerPC Notebook motherboard V.0.6 August 2020
Open Hardware PowerPC Notebook motherboard V.0.6 August 2020
Roberto Innocenti
 
Introducing Intelligence Into Your Malware Analysis
Introducing Intelligence Into Your Malware AnalysisIntroducing Intelligence Into Your Malware Analysis
Introducing Intelligence Into Your Malware Analysis
Brian Baskin
 
Electrical Schematic Open Hardware PowerPC Notebook motherboard v. 0.4
Electrical Schematic Open Hardware PowerPC Notebook motherboard v. 0.4Electrical Schematic Open Hardware PowerPC Notebook motherboard v. 0.4
Electrical Schematic Open Hardware PowerPC Notebook motherboard v. 0.4
Roberto Innocenti
 
ambil aja
ambil aja ambil aja
ambil aja
muxander
 
Symbolic Debugging with DWARF
Symbolic Debugging with DWARFSymbolic Debugging with DWARF
Symbolic Debugging with DWARF
Samy Bahra
 
How can you remove Pro PC Cleaner, and avoid other scareware lile optimizers?
How can you remove Pro PC Cleaner, and avoid other scareware lile optimizers?How can you remove Pro PC Cleaner, and avoid other scareware lile optimizers?
How can you remove Pro PC Cleaner, and avoid other scareware lile optimizers?howtoguides
 
Vulnerabilities in multiplayer games (2001-2012)
Vulnerabilities in multiplayer games (2001-2012)Vulnerabilities in multiplayer games (2001-2012)
Vulnerabilities in multiplayer games (2001-2012)
Luigi Auriemma
 
Improvements in meta spdxscanner through FOSSology - Ueba San
Improvements in meta spdxscanner through FOSSology - Ueba SanImprovements in meta spdxscanner through FOSSology - Ueba San
Improvements in meta spdxscanner through FOSSology - Ueba San
Shane Coughlan
 
Crossing the Production Barrier: Development at Scale
Crossing the Production Barrier: Development at ScaleCrossing the Production Barrier: Development at Scale
Crossing the Production Barrier: Development at Scalejgoulah
 
Monitoring Containers with Weave Scope
Monitoring Containers with Weave ScopeMonitoring Containers with Weave Scope
Monitoring Containers with Weave Scope
Weaveworks
 
[1C2]webrtc 개발, 현재와 미래
[1C2]webrtc 개발, 현재와 미래[1C2]webrtc 개발, 현재와 미래
[1C2]webrtc 개발, 현재와 미래
NAVER D2
 
LIST OF 150 MALICIOUS APPS REMOVED FROM PLAYSTORE
LIST OF 150 MALICIOUS APPS REMOVED FROM PLAYSTORELIST OF 150 MALICIOUS APPS REMOVED FROM PLAYSTORE
LIST OF 150 MALICIOUS APPS REMOVED FROM PLAYSTORE
Kweku Zurek
 

Similar to Sigcheck option memo (20)

DEF CON 27 - HUBER AND ROSKOSCH - im on your phone listening attacking voip c...
DEF CON 27 - HUBER AND ROSKOSCH - im on your phone listening attacking voip c...DEF CON 27 - HUBER AND ROSKOSCH - im on your phone listening attacking voip c...
DEF CON 27 - HUBER AND ROSKOSCH - im on your phone listening attacking voip c...
 
Lewis brady engine_terminology (edited version)
Lewis brady engine_terminology (edited version)Lewis brady engine_terminology (edited version)
Lewis brady engine_terminology (edited version)
 
console32.vswindows32v15.suoconsole32.vswindows32v15.docx
console32.vswindows32v15.suoconsole32.vswindows32v15.docxconsole32.vswindows32v15.suoconsole32.vswindows32v15.docx
console32.vswindows32v15.suoconsole32.vswindows32v15.docx
 
Active proxied sessions
Active proxied sessionsActive proxied sessions
Active proxied sessions
 
growthbotics audit.pdf
growthbotics audit.pdfgrowthbotics audit.pdf
growthbotics audit.pdf
 
Readme
ReadmeReadme
Readme
 
Serial number soft
Serial number softSerial number soft
Serial number soft
 
Electrical Schematic Open Hardware PowerPC Notebook motherboard v. 0.5
 Electrical Schematic Open Hardware PowerPC Notebook motherboard v. 0.5 Electrical Schematic Open Hardware PowerPC Notebook motherboard v. 0.5
Electrical Schematic Open Hardware PowerPC Notebook motherboard v. 0.5
 
Open Hardware PowerPC Notebook motherboard V.0.6 August 2020
Open Hardware PowerPC Notebook motherboard V.0.6 August 2020Open Hardware PowerPC Notebook motherboard V.0.6 August 2020
Open Hardware PowerPC Notebook motherboard V.0.6 August 2020
 
Introducing Intelligence Into Your Malware Analysis
Introducing Intelligence Into Your Malware AnalysisIntroducing Intelligence Into Your Malware Analysis
Introducing Intelligence Into Your Malware Analysis
 
Electrical Schematic Open Hardware PowerPC Notebook motherboard v. 0.4
Electrical Schematic Open Hardware PowerPC Notebook motherboard v. 0.4Electrical Schematic Open Hardware PowerPC Notebook motherboard v. 0.4
Electrical Schematic Open Hardware PowerPC Notebook motherboard v. 0.4
 
ambil aja
ambil aja ambil aja
ambil aja
 
Symbolic Debugging with DWARF
Symbolic Debugging with DWARFSymbolic Debugging with DWARF
Symbolic Debugging with DWARF
 
How can you remove Pro PC Cleaner, and avoid other scareware lile optimizers?
How can you remove Pro PC Cleaner, and avoid other scareware lile optimizers?How can you remove Pro PC Cleaner, and avoid other scareware lile optimizers?
How can you remove Pro PC Cleaner, and avoid other scareware lile optimizers?
 
Vulnerabilities in multiplayer games (2001-2012)
Vulnerabilities in multiplayer games (2001-2012)Vulnerabilities in multiplayer games (2001-2012)
Vulnerabilities in multiplayer games (2001-2012)
 
Improvements in meta spdxscanner through FOSSology - Ueba San
Improvements in meta spdxscanner through FOSSology - Ueba SanImprovements in meta spdxscanner through FOSSology - Ueba San
Improvements in meta spdxscanner through FOSSology - Ueba San
 
Crossing the Production Barrier: Development at Scale
Crossing the Production Barrier: Development at ScaleCrossing the Production Barrier: Development at Scale
Crossing the Production Barrier: Development at Scale
 
Monitoring Containers with Weave Scope
Monitoring Containers with Weave ScopeMonitoring Containers with Weave Scope
Monitoring Containers with Weave Scope
 
[1C2]webrtc 개발, 현재와 미래
[1C2]webrtc 개발, 현재와 미래[1C2]webrtc 개발, 현재와 미래
[1C2]webrtc 개발, 현재와 미래
 
LIST OF 150 MALICIOUS APPS REMOVED FROM PLAYSTORE
LIST OF 150 MALICIOUS APPS REMOVED FROM PLAYSTORELIST OF 150 MALICIOUS APPS REMOVED FROM PLAYSTORE
LIST OF 150 MALICIOUS APPS REMOVED FROM PLAYSTORE
 

More from Shota Shinogi

LLM App Hacking (AVTOKYO2023)
LLM App Hacking (AVTOKYO2023)LLM App Hacking (AVTOKYO2023)
LLM App Hacking (AVTOKYO2023)
Shota Shinogi
 
ネットストーカー御用達OSINTツールBlackBirdを触ってみた.pptx
ネットストーカー御用達OSINTツールBlackBirdを触ってみた.pptxネットストーカー御用達OSINTツールBlackBirdを触ってみた.pptx
ネットストーカー御用達OSINTツールBlackBirdを触ってみた.pptx
Shota Shinogi
 
HamaCTF WriteUp (Unpack category)
HamaCTF WriteUp (Unpack category)HamaCTF WriteUp (Unpack category)
HamaCTF WriteUp (Unpack category)
Shota Shinogi
 
CyberChefの使い方(HamaCTF2019 WriteUp編)
CyberChefの使い方(HamaCTF2019 WriteUp編)CyberChefの使い方(HamaCTF2019 WriteUp編)
CyberChefの使い方(HamaCTF2019 WriteUp編)
Shota Shinogi
 
ドラえもんの秘密道具「夜ランプ」を作ろうとした話(ネタ)
ドラえもんの秘密道具「夜ランプ」を作ろうとした話(ネタ)ドラえもんの秘密道具「夜ランプ」を作ろうとした話(ネタ)
ドラえもんの秘密道具「夜ランプ」を作ろうとした話(ネタ)
Shota Shinogi
 
AndroidとPCのみでスマート電球BLEハッキング
AndroidとPCのみでスマート電球BLEハッキングAndroidとPCのみでスマート電球BLEハッキング
AndroidとPCのみでスマート電球BLEハッキング
Shota Shinogi
 
Honeypot Spotted
Honeypot SpottedHoneypot Spotted
Honeypot Spotted
Shota Shinogi
 
RISEconf 2015 UNOFFICIAL Schedule
RISEconf 2015 UNOFFICIAL ScheduleRISEconf 2015 UNOFFICIAL Schedule
RISEconf 2015 UNOFFICIAL Schedule
Shota Shinogi
 
Hexdump memo
Hexdump memoHexdump memo
Hexdump memo
Shota Shinogi
 
ShinoBOT Suite
ShinoBOT SuiteShinoBOT Suite
ShinoBOT Suite
Shota Shinogi
 
Introduction of ShinoBOT (Black Hat USA 2013 Arsenal)
Introduction of ShinoBOT (Black Hat USA 2013 Arsenal)Introduction of ShinoBOT (Black Hat USA 2013 Arsenal)
Introduction of ShinoBOT (Black Hat USA 2013 Arsenal)
Shota Shinogi
 

More from Shota Shinogi (11)

LLM App Hacking (AVTOKYO2023)
LLM App Hacking (AVTOKYO2023)LLM App Hacking (AVTOKYO2023)
LLM App Hacking (AVTOKYO2023)
 
ネットストーカー御用達OSINTツールBlackBirdを触ってみた.pptx
ネットストーカー御用達OSINTツールBlackBirdを触ってみた.pptxネットストーカー御用達OSINTツールBlackBirdを触ってみた.pptx
ネットストーカー御用達OSINTツールBlackBirdを触ってみた.pptx
 
HamaCTF WriteUp (Unpack category)
HamaCTF WriteUp (Unpack category)HamaCTF WriteUp (Unpack category)
HamaCTF WriteUp (Unpack category)
 
CyberChefの使い方(HamaCTF2019 WriteUp編)
CyberChefの使い方(HamaCTF2019 WriteUp編)CyberChefの使い方(HamaCTF2019 WriteUp編)
CyberChefの使い方(HamaCTF2019 WriteUp編)
 
ドラえもんの秘密道具「夜ランプ」を作ろうとした話(ネタ)
ドラえもんの秘密道具「夜ランプ」を作ろうとした話(ネタ)ドラえもんの秘密道具「夜ランプ」を作ろうとした話(ネタ)
ドラえもんの秘密道具「夜ランプ」を作ろうとした話(ネタ)
 
AndroidとPCのみでスマート電球BLEハッキング
AndroidとPCのみでスマート電球BLEハッキングAndroidとPCのみでスマート電球BLEハッキング
AndroidとPCのみでスマート電球BLEハッキング
 
Honeypot Spotted
Honeypot SpottedHoneypot Spotted
Honeypot Spotted
 
RISEconf 2015 UNOFFICIAL Schedule
RISEconf 2015 UNOFFICIAL ScheduleRISEconf 2015 UNOFFICIAL Schedule
RISEconf 2015 UNOFFICIAL Schedule
 
Hexdump memo
Hexdump memoHexdump memo
Hexdump memo
 
ShinoBOT Suite
ShinoBOT SuiteShinoBOT Suite
ShinoBOT Suite
 
Introduction of ShinoBOT (Black Hat USA 2013 Arsenal)
Introduction of ShinoBOT (Black Hat USA 2013 Arsenal)Introduction of ShinoBOT (Black Hat USA 2013 Arsenal)
Introduction of ShinoBOT (Black Hat USA 2013 Arsenal)
 

Recently uploaded

May Marketo Masterclass, London MUG May 22 2024.pdf
May Marketo Masterclass, London MUG May 22 2024.pdfMay Marketo Masterclass, London MUG May 22 2024.pdf
May Marketo Masterclass, London MUG May 22 2024.pdf
Adele Miller
 
Graphic Design Crash Course for beginners
Graphic Design Crash Course for beginnersGraphic Design Crash Course for beginners
Graphic Design Crash Course for beginners
e20449
 
OpenFOAM solver for Helmholtz equation, helmholtzFoam / helmholtzBubbleFoam
OpenFOAM solver for Helmholtz equation, helmholtzFoam / helmholtzBubbleFoamOpenFOAM solver for Helmholtz equation, helmholtzFoam / helmholtzBubbleFoam
OpenFOAM solver for Helmholtz equation, helmholtzFoam / helmholtzBubbleFoam
takuyayamamoto1800
 
Climate Science Flows: Enabling Petabyte-Scale Climate Analysis with the Eart...
Climate Science Flows: Enabling Petabyte-Scale Climate Analysis with the Eart...Climate Science Flows: Enabling Petabyte-Scale Climate Analysis with the Eart...
Climate Science Flows: Enabling Petabyte-Scale Climate Analysis with the Eart...
Globus
 
How to Position Your Globus Data Portal for Success Ten Good Practices
How to Position Your Globus Data Portal for Success Ten Good PracticesHow to Position Your Globus Data Portal for Success Ten Good Practices
How to Position Your Globus Data Portal for Success Ten Good Practices
Globus
 
Cyaniclab : Software Development Agency Portfolio.pdf
Cyaniclab : Software Development Agency Portfolio.pdfCyaniclab : Software Development Agency Portfolio.pdf
Cyaniclab : Software Development Agency Portfolio.pdf
Cyanic lab
 
Utilocate provides Smarter, Better, Faster, Safer Locate Ticket Management
Utilocate provides Smarter, Better, Faster, Safer Locate Ticket ManagementUtilocate provides Smarter, Better, Faster, Safer Locate Ticket Management
Utilocate provides Smarter, Better, Faster, Safer Locate Ticket Management
Utilocate
 
Providing Globus Services to Users of JASMIN for Environmental Data Analysis
Providing Globus Services to Users of JASMIN for Environmental Data AnalysisProviding Globus Services to Users of JASMIN for Environmental Data Analysis
Providing Globus Services to Users of JASMIN for Environmental Data Analysis
Globus
 
Pro Unity Game Development with C-sharp Book
Pro Unity Game Development with C-sharp BookPro Unity Game Development with C-sharp Book
Pro Unity Game Development with C-sharp Book
abdulrafaychaudhry
 
Lecture 1 Introduction to games development
Lecture 1 Introduction to games developmentLecture 1 Introduction to games development
Lecture 1 Introduction to games development
abdulrafaychaudhry
 
Enterprise Software Development with No Code Solutions.pptx
Enterprise Software Development with No Code Solutions.pptxEnterprise Software Development with No Code Solutions.pptx
Enterprise Software Development with No Code Solutions.pptx
QuickwayInfoSystems3
 
Quarkus Hidden and Forbidden Extensions
Quarkus Hidden and Forbidden ExtensionsQuarkus Hidden and Forbidden Extensions
Quarkus Hidden and Forbidden Extensions
Max Andersen
 
Vitthal Shirke Microservices Resume Montevideo
Vitthal Shirke Microservices Resume MontevideoVitthal Shirke Microservices Resume Montevideo
Vitthal Shirke Microservices Resume Montevideo
Vitthal Shirke
 
Orion Context Broker introduction 20240604
Orion Context Broker introduction 20240604Orion Context Broker introduction 20240604
Orion Context Broker introduction 20240604
Fermin Galan
 
Globus Compute wth IRI Workflows - GlobusWorld 2024
Globus Compute wth IRI Workflows - GlobusWorld 2024Globus Compute wth IRI Workflows - GlobusWorld 2024
Globus Compute wth IRI Workflows - GlobusWorld 2024
Globus
 
Cracking the code review at SpringIO 2024
Cracking the code review at SpringIO 2024Cracking the code review at SpringIO 2024
Cracking the code review at SpringIO 2024
Paco van Beckhoven
 
Text-Summarization-of-Breaking-News-Using-Fine-tuning-BART-Model.pptx
Text-Summarization-of-Breaking-News-Using-Fine-tuning-BART-Model.pptxText-Summarization-of-Breaking-News-Using-Fine-tuning-BART-Model.pptx
Text-Summarization-of-Breaking-News-Using-Fine-tuning-BART-Model.pptx
ShamsuddeenMuhammadA
 
AI Pilot Review: The World’s First Virtual Assistant Marketing Suite
AI Pilot Review: The World’s First Virtual Assistant Marketing SuiteAI Pilot Review: The World’s First Virtual Assistant Marketing Suite
AI Pilot Review: The World’s First Virtual Assistant Marketing Suite
Google
 
Understanding Globus Data Transfers with NetSage
Understanding Globus Data Transfers with NetSageUnderstanding Globus Data Transfers with NetSage
Understanding Globus Data Transfers with NetSage
Globus
 
Gamify Your Mind; The Secret Sauce to Delivering Success, Continuously Improv...
Gamify Your Mind; The Secret Sauce to Delivering Success, Continuously Improv...Gamify Your Mind; The Secret Sauce to Delivering Success, Continuously Improv...
Gamify Your Mind; The Secret Sauce to Delivering Success, Continuously Improv...
Shahin Sheidaei
 

Recently uploaded (20)

May Marketo Masterclass, London MUG May 22 2024.pdf
May Marketo Masterclass, London MUG May 22 2024.pdfMay Marketo Masterclass, London MUG May 22 2024.pdf
May Marketo Masterclass, London MUG May 22 2024.pdf
 
Graphic Design Crash Course for beginners
Graphic Design Crash Course for beginnersGraphic Design Crash Course for beginners
Graphic Design Crash Course for beginners
 
OpenFOAM solver for Helmholtz equation, helmholtzFoam / helmholtzBubbleFoam
OpenFOAM solver for Helmholtz equation, helmholtzFoam / helmholtzBubbleFoamOpenFOAM solver for Helmholtz equation, helmholtzFoam / helmholtzBubbleFoam
OpenFOAM solver for Helmholtz equation, helmholtzFoam / helmholtzBubbleFoam
 
Climate Science Flows: Enabling Petabyte-Scale Climate Analysis with the Eart...
Climate Science Flows: Enabling Petabyte-Scale Climate Analysis with the Eart...Climate Science Flows: Enabling Petabyte-Scale Climate Analysis with the Eart...
Climate Science Flows: Enabling Petabyte-Scale Climate Analysis with the Eart...
 
How to Position Your Globus Data Portal for Success Ten Good Practices
How to Position Your Globus Data Portal for Success Ten Good PracticesHow to Position Your Globus Data Portal for Success Ten Good Practices
How to Position Your Globus Data Portal for Success Ten Good Practices
 
Cyaniclab : Software Development Agency Portfolio.pdf
Cyaniclab : Software Development Agency Portfolio.pdfCyaniclab : Software Development Agency Portfolio.pdf
Cyaniclab : Software Development Agency Portfolio.pdf
 
Utilocate provides Smarter, Better, Faster, Safer Locate Ticket Management
Utilocate provides Smarter, Better, Faster, Safer Locate Ticket ManagementUtilocate provides Smarter, Better, Faster, Safer Locate Ticket Management
Utilocate provides Smarter, Better, Faster, Safer Locate Ticket Management
 
Providing Globus Services to Users of JASMIN for Environmental Data Analysis
Providing Globus Services to Users of JASMIN for Environmental Data AnalysisProviding Globus Services to Users of JASMIN for Environmental Data Analysis
Providing Globus Services to Users of JASMIN for Environmental Data Analysis
 
Pro Unity Game Development with C-sharp Book
Pro Unity Game Development with C-sharp BookPro Unity Game Development with C-sharp Book
Pro Unity Game Development with C-sharp Book
 
Lecture 1 Introduction to games development
Lecture 1 Introduction to games developmentLecture 1 Introduction to games development
Lecture 1 Introduction to games development
 
Enterprise Software Development with No Code Solutions.pptx
Enterprise Software Development with No Code Solutions.pptxEnterprise Software Development with No Code Solutions.pptx
Enterprise Software Development with No Code Solutions.pptx
 
Quarkus Hidden and Forbidden Extensions
Quarkus Hidden and Forbidden ExtensionsQuarkus Hidden and Forbidden Extensions
Quarkus Hidden and Forbidden Extensions
 
Vitthal Shirke Microservices Resume Montevideo
Vitthal Shirke Microservices Resume MontevideoVitthal Shirke Microservices Resume Montevideo
Vitthal Shirke Microservices Resume Montevideo
 
Orion Context Broker introduction 20240604
Orion Context Broker introduction 20240604Orion Context Broker introduction 20240604
Orion Context Broker introduction 20240604
 
Globus Compute wth IRI Workflows - GlobusWorld 2024
Globus Compute wth IRI Workflows - GlobusWorld 2024Globus Compute wth IRI Workflows - GlobusWorld 2024
Globus Compute wth IRI Workflows - GlobusWorld 2024
 
Cracking the code review at SpringIO 2024
Cracking the code review at SpringIO 2024Cracking the code review at SpringIO 2024
Cracking the code review at SpringIO 2024
 
Text-Summarization-of-Breaking-News-Using-Fine-tuning-BART-Model.pptx
Text-Summarization-of-Breaking-News-Using-Fine-tuning-BART-Model.pptxText-Summarization-of-Breaking-News-Using-Fine-tuning-BART-Model.pptx
Text-Summarization-of-Breaking-News-Using-Fine-tuning-BART-Model.pptx
 
AI Pilot Review: The World’s First Virtual Assistant Marketing Suite
AI Pilot Review: The World’s First Virtual Assistant Marketing SuiteAI Pilot Review: The World’s First Virtual Assistant Marketing Suite
AI Pilot Review: The World’s First Virtual Assistant Marketing Suite
 
Understanding Globus Data Transfers with NetSage
Understanding Globus Data Transfers with NetSageUnderstanding Globus Data Transfers with NetSage
Understanding Globus Data Transfers with NetSage
 
Gamify Your Mind; The Secret Sauce to Delivering Success, Continuously Improv...
Gamify Your Mind; The Secret Sauce to Delivering Success, Continuously Improv...Gamify Your Mind; The Secret Sauce to Delivering Success, Continuously Improv...
Gamify Your Mind; The Secret Sauce to Delivering Success, Continuously Improv...
 

Sigcheck option memo

  • 2. no option >sigcheck Shinobot.exe Sigcheck v2.30 - File version and signature viewer Copyright (C) 2004-2015 Mark Russinovich Sysinternals - www.sysinternals.com E:DesktopShinoBOT.exe: Verified: Unsigned Link date: 17:41 2016/12/22 Publisher: n/a Company: Sh1n0g1 Inc. Description: ShinoBOT Product: ShinoBOT Prod version: 3.1.0.0 File version: 3.1.0.0 MachineType: 32-bit
  • 3. -q (quiet) >sigcheck -q ShinoBOT.exe E:DesktopShinoBOT.exe: Verified: Unsigned Link date: 17:41 2016/12/22 Publisher: n/a Company: Sh1n0g1 Inc. Description: ShinoBOT Product: ShinoBOT Prod version: 3.1.0.0 File version: 3.1.0.0 MachineType: 32-bit The following banner disappears. Sigcheck v2.30 - File version and signature viewer Copyright (C) 2004-2015 Mark Russinovich Sysinternals - www.sysinternals.com
  • 4. -a (extended version information, entropy) >sigcheck -a ShinoBOT.exe Sigcheck v2.30 - File version and signature viewer Copyright (C) 2004-2015 Mark Russinovich Sysinternals - www.sysinternals.com E:DesktopShinoBOT.exe: Verified: Unsigned Link date: 17:41 2016/12/22 Publisher: n/a Company: Sh1n0g1 Inc. Description: ShinoBOT Product: ShinoBOT Prod version: 3.1.0.0 File version: 3.1.0.0 MachineType: 32-bit Binary Version: 3.1.0.0 Original Name: SHINOBOT_BUILDER.exe Internal Name: SHINOBOT_BUILDER.exe Copyright: Sh1n0g1 Inc. Comments: RAT simulator Entropy: 4.719
  • 5. -h (hashes) >sigcheck -h ShinoBOT.exe Sigcheck v2.30 - File version and signature viewer Copyright (C) 2004-2015 Mark Russinovich Sysinternals - www.sysinternals.com E:DesktopShinoBOT.exe: Verified: Unsigned Link date: 17:41 2016/12/22 Publisher: n/a Company: Sh1n0g1 Inc. Description: ShinoBOT Product: ShinoBOT Prod version: 3.1.0.0 File version: 3.1.0.0 MachineType: 32-bit MD5: 9B2166D3B72C84396EDECE1673E923B7 SHA1: CF8C8D3F48FB1304E0AAB7EFB6C3EB9BBE833BC5 PESHA1: 5A7BAE6C68F50ABA37EB0FDC5B698115DB13C14B PE256: CB30CF07163B72F49DADA51CDC3965E6F79AA6D9A430524AD81C0D445155CDDC SHA256: BF7EFF73A37965B7ECD784E621F0B7118402C4C03E450E648B8922F070D440C8 IMP: F34D5F2D4577ED6D9CEEC516C1F5A744
  • 6. -v (VirusTotal) >sigcheck -v ShinoBOT1326.exe Sigcheck v2.30 - File version and signature viewer Copyright (C) 2004-2015 Mark Russinovich Sysinternals - www.sysinternals.com e:WorkShinoBOT1326.exe: Verified: Unsigned Link date: 9:23 2013/07/25 Publisher: n/a Company: Sh1n0g1 Description: ShinoBOT Product: ShinoBOT Prod version: 1.3.2.6 File version: 1.3.2.6 MachineType: 32-bit VT detection: 44/57 VT link: https://www.virustotal.com/file/e10506ed829846ae5b7cddbb7ff636b18f632f28f072f9 b399b9cbdbd643b8d9/analysis/
  • 7. -i (signed info) >sigcheck -i DummyPopup_Signed.exe Sigcheck v2.30 - File version and signature viewer Copyright (C) 2004-2015 Mark Russinovich Sysinternals - www.sysinternals.com E:DesktopDummyPopup_Signed.exe: Verified: Signed Catalog: E:DesktopDummyPopup_Signed.exe Signer: Sh1n0g1 Inc Status: ???????????????????????????????? Valid Usage: All Serial Number: 01 Thumbprint: 9C85EA7F5672E74E3A5C45279EECBD979B559DDB Algorithm: SHA1 Valid from: 16:54 2013/11/22 Valid to: 16:54 2015/11/22 Signing date: n/a Publisher: Sh1n0g1 Inc Company: n/a Description: Popup Product: Popup Prod version: 1.0.0.0 File version: 1.0.0.0 MachineType: 32-bit
  • 8. aihqv combined >sigcheck -a -i -h -q -v DummyPopup_Signed.exe E:DesktopDummyPopup_Signed.exe: Verified: Signed Catalog: E:DesktopDummyPopup_Signed.exe Signer: Sh1n0g1 Inc Status: ???????????????????????????????? Valid Usage: All Serial Number: 01 Thumbprint: 9C85EA7F5672E74E3A5C45279EECBD979B559DDB Algorithm: SHA1 Valid from: 16:54 2013/11/22 Valid to: 16:54 2015/11/22 Signing date: n/a Publisher: Sh1n0g1 Inc Company: n/a Description: Popup Product: Popup Prod version: 1.0.0.0 File version: 1.0.0.0 MachineType: 32-bit Binary Version: 1.0.0.0 Original Name: DummyPopup.exe Internal Name: DummyPopup.exe Copyright: Copyright ゥ 2013 Comments: n/a Entropy: 6.755 MD5: 66F65B57235F9886537BB791DB6DFB14 SHA1: D71365CCDC97D0A1BD88A97C81DAD6562749CA0A PESHA1: AC6275E718A4E334B042B870DD66F3BB759B56FA PE256: 05D0ABD52B5E3A6C9CBD2033FC806568EEDFD235C0F3297FE9F3F409580A1FAA SHA256: 821B0E74CBBF042C32A691103D5DC449A1812E9FB0E5185B61B2F21CCCC1E883 IMP: F34D5F2D4577ED6D9CEEC516C1F5A744 VT detection: 1/56 VT link: https://www.virustotal.com/file/821b0e74cbbf042c32a691103d5dc449a1812e9fb0e5185b61b2f21cccc1e883/analysis/