ºÝºÝߣ

ºÝºÝߣShare a Scribd company logo
sigcheck main option
@Sh1n0g1
no option
>sigcheck Shinobot.exe
Sigcheck v2.30 - File version and signature viewer
Copyright (C) 2004-2015 Mark Russinovich
Sysinternals - www.sysinternals.com
E:DesktopShinoBOT.exe:
Verified: Unsigned
Link date: 17:41 2016/12/22
Publisher: n/a
Company: Sh1n0g1 Inc.
Description: ShinoBOT
Product: ShinoBOT
Prod version: 3.1.0.0
File version: 3.1.0.0
MachineType: 32-bit
-q (quiet)
>sigcheck -q ShinoBOT.exe
E:DesktopShinoBOT.exe:
Verified: Unsigned
Link date: 17:41 2016/12/22
Publisher: n/a
Company: Sh1n0g1 Inc.
Description: ShinoBOT
Product: ShinoBOT
Prod version: 3.1.0.0
File version: 3.1.0.0
MachineType: 32-bit
The following banner disappears.
Sigcheck v2.30 - File version and
signature viewer
Copyright (C) 2004-2015 Mark
Russinovich
Sysinternals - www.sysinternals.com
-a (extended version information, entropy)
>sigcheck -a ShinoBOT.exe
Sigcheck v2.30 - File version and signature viewer
Copyright (C) 2004-2015 Mark Russinovich
Sysinternals - www.sysinternals.com
E:DesktopShinoBOT.exe:
Verified: Unsigned
Link date: 17:41 2016/12/22
Publisher: n/a
Company: Sh1n0g1 Inc.
Description: ShinoBOT
Product: ShinoBOT
Prod version: 3.1.0.0
File version: 3.1.0.0
MachineType: 32-bit
Binary Version: 3.1.0.0
Original Name: SHINOBOT_BUILDER.exe
Internal Name: SHINOBOT_BUILDER.exe
Copyright: Sh1n0g1 Inc.
Comments: RAT simulator
Entropy: 4.719
-h (hashes)
>sigcheck -h ShinoBOT.exe
Sigcheck v2.30 - File version and signature viewer
Copyright (C) 2004-2015 Mark Russinovich
Sysinternals - www.sysinternals.com
E:DesktopShinoBOT.exe:
Verified: Unsigned
Link date: 17:41 2016/12/22
Publisher: n/a
Company: Sh1n0g1 Inc.
Description: ShinoBOT
Product: ShinoBOT
Prod version: 3.1.0.0
File version: 3.1.0.0
MachineType: 32-bit
MD5: 9B2166D3B72C84396EDECE1673E923B7
SHA1: CF8C8D3F48FB1304E0AAB7EFB6C3EB9BBE833BC5
PESHA1: 5A7BAE6C68F50ABA37EB0FDC5B698115DB13C14B
PE256: CB30CF07163B72F49DADA51CDC3965E6F79AA6D9A430524AD81C0D445155CDDC
SHA256: BF7EFF73A37965B7ECD784E621F0B7118402C4C03E450E648B8922F070D440C8
IMP: F34D5F2D4577ED6D9CEEC516C1F5A744
-v (VirusTotal)
>sigcheck -v ShinoBOT1326.exe
Sigcheck v2.30 - File version and signature viewer
Copyright (C) 2004-2015 Mark Russinovich
Sysinternals - www.sysinternals.com
e:WorkShinoBOT1326.exe:
Verified: Unsigned
Link date: 9:23 2013/07/25
Publisher: n/a
Company: Sh1n0g1
Description: ShinoBOT
Product: ShinoBOT
Prod version: 1.3.2.6
File version: 1.3.2.6
MachineType: 32-bit
VT detection: 44/57
VT link:
https://www.virustotal.com/file/e10506ed829846ae5b7cddbb7ff636b18f632f28f072f9
b399b9cbdbd643b8d9/analysis/
-i (signed info)
>sigcheck -i DummyPopup_Signed.exe
Sigcheck v2.30 - File version and signature viewer
Copyright (C) 2004-2015 Mark Russinovich
Sysinternals - www.sysinternals.com
E:DesktopDummyPopup_Signed.exe:
Verified: Signed
Catalog: E:DesktopDummyPopup_Signed.exe
Signer:
Sh1n0g1 Inc
Status: ????????????????????????????????
Valid Usage: All
Serial Number: 01
Thumbprint: 9C85EA7F5672E74E3A5C45279EECBD979B559DDB
Algorithm: SHA1
Valid from: 16:54 2013/11/22
Valid to: 16:54 2015/11/22
Signing date: n/a
Publisher: Sh1n0g1 Inc
Company: n/a
Description: Popup
Product: Popup
Prod version: 1.0.0.0
File version: 1.0.0.0
MachineType: 32-bit
aihqv combined
>sigcheck -a -i -h -q -v DummyPopup_Signed.exe
E:DesktopDummyPopup_Signed.exe:
Verified: Signed
Catalog: E:DesktopDummyPopup_Signed.exe
Signer:
Sh1n0g1 Inc
Status: ????????????????????????????????
Valid Usage: All
Serial Number: 01
Thumbprint: 9C85EA7F5672E74E3A5C45279EECBD979B559DDB
Algorithm: SHA1
Valid from: 16:54 2013/11/22
Valid to: 16:54 2015/11/22
Signing date: n/a
Publisher: Sh1n0g1 Inc
Company: n/a
Description: Popup
Product: Popup
Prod version: 1.0.0.0
File version: 1.0.0.0
MachineType: 32-bit
Binary Version: 1.0.0.0
Original Name: DummyPopup.exe
Internal Name: DummyPopup.exe
Copyright: Copyright ? 2013
Comments: n/a
Entropy: 6.755
MD5: 66F65B57235F9886537BB791DB6DFB14
SHA1: D71365CCDC97D0A1BD88A97C81DAD6562749CA0A
PESHA1: AC6275E718A4E334B042B870DD66F3BB759B56FA
PE256: 05D0ABD52B5E3A6C9CBD2033FC806568EEDFD235C0F3297FE9F3F409580A1FAA
SHA256: 821B0E74CBBF042C32A691103D5DC449A1812E9FB0E5185B61B2F21CCCC1E883
IMP: F34D5F2D4577ED6D9CEEC516C1F5A744
VT detection: 1/56
VT link: https://www.virustotal.com/file/821b0e74cbbf042c32a691103d5dc449a1812e9fb0e5185b61b2f21cccc1e883/analysis/

More Related Content

Similar to Sigcheck option memo (20)

DEF CON 27 - HUBER AND ROSKOSCH - im on your phone listening attacking voip c...
DEF CON 27 - HUBER AND ROSKOSCH - im on your phone listening attacking voip c...DEF CON 27 - HUBER AND ROSKOSCH - im on your phone listening attacking voip c...
DEF CON 27 - HUBER AND ROSKOSCH - im on your phone listening attacking voip c...
Felipe Prado
?
Lewis brady engine_terminology (edited version)
Lewis brady engine_terminology (edited version)Lewis brady engine_terminology (edited version)
Lewis brady engine_terminology (edited version)
LewisB2013
?
console32.vswindows32v15.suoconsole32.vswindows32v15.docx
console32.vswindows32v15.suoconsole32.vswindows32v15.docxconsole32.vswindows32v15.suoconsole32.vswindows32v15.docx
console32.vswindows32v15.suoconsole32.vswindows32v15.docx
aidaclewer
?
Active proxied sessions
Active proxied sessionsActive proxied sessions
Active proxied sessions
ds5ysm
?
growthbotics audit.pdf
growthbotics audit.pdfgrowthbotics audit.pdf
growthbotics audit.pdf
Wilson Kao
?
Readme
ReadmeReadme
Readme
David Sting
?
Serial number soft
Serial number softSerial number soft
Serial number soft
sandi271979
?
Electrical Schematic Open Hardware PowerPC Notebook motherboard v. 0.5
 Electrical Schematic Open Hardware PowerPC Notebook motherboard v. 0.5 Electrical Schematic Open Hardware PowerPC Notebook motherboard v. 0.5
Electrical Schematic Open Hardware PowerPC Notebook motherboard v. 0.5
Roberto Innocenti
?
Open Hardware PowerPC Notebook motherboard V.0.6 August 2020
Open Hardware PowerPC Notebook motherboard V.0.6 August 2020Open Hardware PowerPC Notebook motherboard V.0.6 August 2020
Open Hardware PowerPC Notebook motherboard V.0.6 August 2020
Roberto Innocenti
?
Introducing Intelligence Into Your Malware Analysis
Introducing Intelligence Into Your Malware AnalysisIntroducing Intelligence Into Your Malware Analysis
Introducing Intelligence Into Your Malware Analysis
Brian Baskin
?
Electrical Schematic Open Hardware PowerPC Notebook motherboard v. 0.4
Electrical Schematic Open Hardware PowerPC Notebook motherboard v. 0.4Electrical Schematic Open Hardware PowerPC Notebook motherboard v. 0.4
Electrical Schematic Open Hardware PowerPC Notebook motherboard v. 0.4
Roberto Innocenti
?
ambil aja
ambil aja ambil aja
ambil aja
muxander
?
Symbolic Debugging with DWARF
Symbolic Debugging with DWARFSymbolic Debugging with DWARF
Symbolic Debugging with DWARF
Samy Bahra
?
How can you remove Pro PC Cleaner, and avoid other scareware lile optimizers?
How can you remove Pro PC Cleaner, and avoid other scareware lile optimizers?How can you remove Pro PC Cleaner, and avoid other scareware lile optimizers?
How can you remove Pro PC Cleaner, and avoid other scareware lile optimizers?
howtoguides
?
Vulnerabilities in multiplayer games (2001-2012)
Vulnerabilities in multiplayer games (2001-2012)Vulnerabilities in multiplayer games (2001-2012)
Vulnerabilities in multiplayer games (2001-2012)
Luigi Auriemma
?
Improvements in meta spdxscanner through FOSSology - Ueba San
Improvements in meta spdxscanner through FOSSology - Ueba SanImprovements in meta spdxscanner through FOSSology - Ueba San
Improvements in meta spdxscanner through FOSSology - Ueba San
Shane Coughlan
?
Crossing the Production Barrier: Development at Scale
Crossing the Production Barrier: Development at ScaleCrossing the Production Barrier: Development at Scale
Crossing the Production Barrier: Development at Scale
jgoulah
?
Monitoring Containers with Weave Scope
Monitoring Containers with Weave ScopeMonitoring Containers with Weave Scope
Monitoring Containers with Weave Scope
Weaveworks
?
[1C2]webrtc ?????, ??????? ????
[1C2]webrtc ?????, ??????? ????[1C2]webrtc ?????, ??????? ????
[1C2]webrtc ?????, ??????? ????
NAVER D2
?
LIST OF 150 MALICIOUS APPS REMOVED FROM PLAYSTORE
LIST OF 150 MALICIOUS APPS REMOVED FROM PLAYSTORELIST OF 150 MALICIOUS APPS REMOVED FROM PLAYSTORE
LIST OF 150 MALICIOUS APPS REMOVED FROM PLAYSTORE
Kweku Zurek
?
DEF CON 27 - HUBER AND ROSKOSCH - im on your phone listening attacking voip c...
DEF CON 27 - HUBER AND ROSKOSCH - im on your phone listening attacking voip c...DEF CON 27 - HUBER AND ROSKOSCH - im on your phone listening attacking voip c...
DEF CON 27 - HUBER AND ROSKOSCH - im on your phone listening attacking voip c...
Felipe Prado
?
Lewis brady engine_terminology (edited version)
Lewis brady engine_terminology (edited version)Lewis brady engine_terminology (edited version)
Lewis brady engine_terminology (edited version)
LewisB2013
?
console32.vswindows32v15.suoconsole32.vswindows32v15.docx
console32.vswindows32v15.suoconsole32.vswindows32v15.docxconsole32.vswindows32v15.suoconsole32.vswindows32v15.docx
console32.vswindows32v15.suoconsole32.vswindows32v15.docx
aidaclewer
?
Active proxied sessions
Active proxied sessionsActive proxied sessions
Active proxied sessions
ds5ysm
?
growthbotics audit.pdf
growthbotics audit.pdfgrowthbotics audit.pdf
growthbotics audit.pdf
Wilson Kao
?
Electrical Schematic Open Hardware PowerPC Notebook motherboard v. 0.5
 Electrical Schematic Open Hardware PowerPC Notebook motherboard v. 0.5 Electrical Schematic Open Hardware PowerPC Notebook motherboard v. 0.5
Electrical Schematic Open Hardware PowerPC Notebook motherboard v. 0.5
Roberto Innocenti
?
Open Hardware PowerPC Notebook motherboard V.0.6 August 2020
Open Hardware PowerPC Notebook motherboard V.0.6 August 2020Open Hardware PowerPC Notebook motherboard V.0.6 August 2020
Open Hardware PowerPC Notebook motherboard V.0.6 August 2020
Roberto Innocenti
?
Introducing Intelligence Into Your Malware Analysis
Introducing Intelligence Into Your Malware AnalysisIntroducing Intelligence Into Your Malware Analysis
Introducing Intelligence Into Your Malware Analysis
Brian Baskin
?
Electrical Schematic Open Hardware PowerPC Notebook motherboard v. 0.4
Electrical Schematic Open Hardware PowerPC Notebook motherboard v. 0.4Electrical Schematic Open Hardware PowerPC Notebook motherboard v. 0.4
Electrical Schematic Open Hardware PowerPC Notebook motherboard v. 0.4
Roberto Innocenti
?
Symbolic Debugging with DWARF
Symbolic Debugging with DWARFSymbolic Debugging with DWARF
Symbolic Debugging with DWARF
Samy Bahra
?
How can you remove Pro PC Cleaner, and avoid other scareware lile optimizers?
How can you remove Pro PC Cleaner, and avoid other scareware lile optimizers?How can you remove Pro PC Cleaner, and avoid other scareware lile optimizers?
How can you remove Pro PC Cleaner, and avoid other scareware lile optimizers?
howtoguides
?
Vulnerabilities in multiplayer games (2001-2012)
Vulnerabilities in multiplayer games (2001-2012)Vulnerabilities in multiplayer games (2001-2012)
Vulnerabilities in multiplayer games (2001-2012)
Luigi Auriemma
?
Improvements in meta spdxscanner through FOSSology - Ueba San
Improvements in meta spdxscanner through FOSSology - Ueba SanImprovements in meta spdxscanner through FOSSology - Ueba San
Improvements in meta spdxscanner through FOSSology - Ueba San
Shane Coughlan
?
Crossing the Production Barrier: Development at Scale
Crossing the Production Barrier: Development at ScaleCrossing the Production Barrier: Development at Scale
Crossing the Production Barrier: Development at Scale
jgoulah
?
Monitoring Containers with Weave Scope
Monitoring Containers with Weave ScopeMonitoring Containers with Weave Scope
Monitoring Containers with Weave Scope
Weaveworks
?
[1C2]webrtc ?????, ??????? ????
[1C2]webrtc ?????, ??????? ????[1C2]webrtc ?????, ??????? ????
[1C2]webrtc ?????, ??????? ????
NAVER D2
?
LIST OF 150 MALICIOUS APPS REMOVED FROM PLAYSTORE
LIST OF 150 MALICIOUS APPS REMOVED FROM PLAYSTORELIST OF 150 MALICIOUS APPS REMOVED FROM PLAYSTORE
LIST OF 150 MALICIOUS APPS REMOVED FROM PLAYSTORE
Kweku Zurek
?

More from Shota Shinogi (11)

LLM App Hacking (AVTOKYO2023)
LLM App Hacking (AVTOKYO2023)LLM App Hacking (AVTOKYO2023)
LLM App Hacking (AVTOKYO2023)
Shota Shinogi
?
¥Í¥Ã¥È¥¹¥È©`¥«©`ÓùÓôﰿ³§±õ±·°Õ¥Ä©`¥ëµþ±ô²¹³¦°ìµþ¾±°ù»å¤ò´¥¤Ã¤Æ¤ß¤¿.±è±è³Ù³æ
¥Í¥Ã¥È¥¹¥È©`¥«©`ÓùÓôﰿ³§±õ±·°Õ¥Ä©`¥ëµþ±ô²¹³¦°ìµþ¾±°ù»å¤ò´¥¤Ã¤Æ¤ß¤¿.±è±è³Ù³æ¥Í¥Ã¥È¥¹¥È©`¥«©`ÓùÓôﰿ³§±õ±·°Õ¥Ä©`¥ëµþ±ô²¹³¦°ìµþ¾±°ù»å¤ò´¥¤Ã¤Æ¤ß¤¿.±è±è³Ù³æ
¥Í¥Ã¥È¥¹¥È©`¥«©`ÓùÓôﰿ³§±õ±·°Õ¥Ä©`¥ëµþ±ô²¹³¦°ìµþ¾±°ù»å¤ò´¥¤Ã¤Æ¤ß¤¿.±è±è³Ù³æ
Shota Shinogi
?
HamaCTF WriteUp (Unpack category)
HamaCTF WriteUp (Unpack category)HamaCTF WriteUp (Unpack category)
HamaCTF WriteUp (Unpack category)
Shota Shinogi
?
CyberChef¤Îʹ¤¤·½£¨HamaCTF2019 WriteUp¾Ž£©
CyberChef¤Îʹ¤¤·½£¨HamaCTF2019 WriteUp¾Ž£©CyberChef¤Îʹ¤¤·½£¨HamaCTF2019 WriteUp¾Ž£©
CyberChef¤Îʹ¤¤·½£¨HamaCTF2019 WriteUp¾Ž£©
Shota Shinogi
?
¥É¥é¤¨¤â¤ó¤ÎÃØÃܵÀ¾ß¡¸Ò¹¥é¥ó¥×¡¹¤ò×÷¤í¤¦¤È¤·¤¿»°£¨¥Í¥¿£©
¥É¥é¤¨¤â¤ó¤ÎÃØÃܵÀ¾ß¡¸Ò¹¥é¥ó¥×¡¹¤ò×÷¤í¤¦¤È¤·¤¿»°£¨¥Í¥¿£©¥É¥é¤¨¤â¤ó¤ÎÃØÃܵÀ¾ß¡¸Ò¹¥é¥ó¥×¡¹¤ò×÷¤í¤¦¤È¤·¤¿»°£¨¥Í¥¿£©
¥É¥é¤¨¤â¤ó¤ÎÃØÃܵÀ¾ß¡¸Ò¹¥é¥ó¥×¡¹¤ò×÷¤í¤¦¤È¤·¤¿»°£¨¥Í¥¿£©
Shota Shinogi
?
´¡²Ô»å°ù´Ç¾±»å¤È±Ê°ä¤Î¤ß¤Ç¥¹¥Þ©`¥ÈµçÇòµþ³¢·¡¥Ï¥Ã¥­¥ó¥°
´¡²Ô»å°ù´Ç¾±»å¤È±Ê°ä¤Î¤ß¤Ç¥¹¥Þ©`¥ÈµçÇòµþ³¢·¡¥Ï¥Ã¥­¥ó¥°´¡²Ô»å°ù´Ç¾±»å¤È±Ê°ä¤Î¤ß¤Ç¥¹¥Þ©`¥ÈµçÇòµþ³¢·¡¥Ï¥Ã¥­¥ó¥°
´¡²Ô»å°ù´Ç¾±»å¤È±Ê°ä¤Î¤ß¤Ç¥¹¥Þ©`¥ÈµçÇòµþ³¢·¡¥Ï¥Ã¥­¥ó¥°
Shota Shinogi
?
Honeypot Spotted
Honeypot SpottedHoneypot Spotted
Honeypot Spotted
Shota Shinogi
?
RISEconf 2015 UNOFFICIAL Schedule
RISEconf 2015 UNOFFICIAL ScheduleRISEconf 2015 UNOFFICIAL Schedule
RISEconf 2015 UNOFFICIAL Schedule
Shota Shinogi
?
Hexdump memo
Hexdump memoHexdump memo
Hexdump memo
Shota Shinogi
?
ShinoBOT Suite
ShinoBOT SuiteShinoBOT Suite
ShinoBOT Suite
Shota Shinogi
?
Introduction of ShinoBOT (Black Hat USA 2013 Arsenal)
Introduction of ShinoBOT (Black Hat USA 2013 Arsenal)Introduction of ShinoBOT (Black Hat USA 2013 Arsenal)
Introduction of ShinoBOT (Black Hat USA 2013 Arsenal)
Shota Shinogi
?
LLM App Hacking (AVTOKYO2023)
LLM App Hacking (AVTOKYO2023)LLM App Hacking (AVTOKYO2023)
LLM App Hacking (AVTOKYO2023)
Shota Shinogi
?
¥Í¥Ã¥È¥¹¥È©`¥«©`ÓùÓôﰿ³§±õ±·°Õ¥Ä©`¥ëµþ±ô²¹³¦°ìµþ¾±°ù»å¤ò´¥¤Ã¤Æ¤ß¤¿.±è±è³Ù³æ
¥Í¥Ã¥È¥¹¥È©`¥«©`ÓùÓôﰿ³§±õ±·°Õ¥Ä©`¥ëµþ±ô²¹³¦°ìµþ¾±°ù»å¤ò´¥¤Ã¤Æ¤ß¤¿.±è±è³Ù³æ¥Í¥Ã¥È¥¹¥È©`¥«©`ÓùÓôﰿ³§±õ±·°Õ¥Ä©`¥ëµþ±ô²¹³¦°ìµþ¾±°ù»å¤ò´¥¤Ã¤Æ¤ß¤¿.±è±è³Ù³æ
¥Í¥Ã¥È¥¹¥È©`¥«©`ÓùÓôﰿ³§±õ±·°Õ¥Ä©`¥ëµþ±ô²¹³¦°ìµþ¾±°ù»å¤ò´¥¤Ã¤Æ¤ß¤¿.±è±è³Ù³æ
Shota Shinogi
?
HamaCTF WriteUp (Unpack category)
HamaCTF WriteUp (Unpack category)HamaCTF WriteUp (Unpack category)
HamaCTF WriteUp (Unpack category)
Shota Shinogi
?
CyberChef¤Îʹ¤¤·½£¨HamaCTF2019 WriteUp¾Ž£©
CyberChef¤Îʹ¤¤·½£¨HamaCTF2019 WriteUp¾Ž£©CyberChef¤Îʹ¤¤·½£¨HamaCTF2019 WriteUp¾Ž£©
CyberChef¤Îʹ¤¤·½£¨HamaCTF2019 WriteUp¾Ž£©
Shota Shinogi
?
¥É¥é¤¨¤â¤ó¤ÎÃØÃܵÀ¾ß¡¸Ò¹¥é¥ó¥×¡¹¤ò×÷¤í¤¦¤È¤·¤¿»°£¨¥Í¥¿£©
¥É¥é¤¨¤â¤ó¤ÎÃØÃܵÀ¾ß¡¸Ò¹¥é¥ó¥×¡¹¤ò×÷¤í¤¦¤È¤·¤¿»°£¨¥Í¥¿£©¥É¥é¤¨¤â¤ó¤ÎÃØÃܵÀ¾ß¡¸Ò¹¥é¥ó¥×¡¹¤ò×÷¤í¤¦¤È¤·¤¿»°£¨¥Í¥¿£©
¥É¥é¤¨¤â¤ó¤ÎÃØÃܵÀ¾ß¡¸Ò¹¥é¥ó¥×¡¹¤ò×÷¤í¤¦¤È¤·¤¿»°£¨¥Í¥¿£©
Shota Shinogi
?
´¡²Ô»å°ù´Ç¾±»å¤È±Ê°ä¤Î¤ß¤Ç¥¹¥Þ©`¥ÈµçÇòµþ³¢·¡¥Ï¥Ã¥­¥ó¥°
´¡²Ô»å°ù´Ç¾±»å¤È±Ê°ä¤Î¤ß¤Ç¥¹¥Þ©`¥ÈµçÇòµþ³¢·¡¥Ï¥Ã¥­¥ó¥°´¡²Ô»å°ù´Ç¾±»å¤È±Ê°ä¤Î¤ß¤Ç¥¹¥Þ©`¥ÈµçÇòµþ³¢·¡¥Ï¥Ã¥­¥ó¥°
´¡²Ô»å°ù´Ç¾±»å¤È±Ê°ä¤Î¤ß¤Ç¥¹¥Þ©`¥ÈµçÇòµþ³¢·¡¥Ï¥Ã¥­¥ó¥°
Shota Shinogi
?
RISEconf 2015 UNOFFICIAL Schedule
RISEconf 2015 UNOFFICIAL ScheduleRISEconf 2015 UNOFFICIAL Schedule
RISEconf 2015 UNOFFICIAL Schedule
Shota Shinogi
?
Introduction of ShinoBOT (Black Hat USA 2013 Arsenal)
Introduction of ShinoBOT (Black Hat USA 2013 Arsenal)Introduction of ShinoBOT (Black Hat USA 2013 Arsenal)
Introduction of ShinoBOT (Black Hat USA 2013 Arsenal)
Shota Shinogi
?

Recently uploaded (20)

Adobe Marketo Engage Champion Deep Dive: Extending Marketo With AEM Forms
Adobe Marketo Engage Champion Deep Dive: Extending Marketo With AEM FormsAdobe Marketo Engage Champion Deep Dive: Extending Marketo With AEM Forms
Adobe Marketo Engage Champion Deep Dive: Extending Marketo With AEM Forms
BradBedford3
?
Upgrade Your Compliance and Traceability with Codebeamer ALM Solutions by 3HT...
Upgrade Your Compliance and Traceability with Codebeamer ALM Solutions by 3HT...Upgrade Your Compliance and Traceability with Codebeamer ALM Solutions by 3HT...
Upgrade Your Compliance and Traceability with Codebeamer ALM Solutions by 3HT...
3 HTi - Engineering Software and Solutions
?
Wondershare Filmora Crack 2025 + Key Free Download
Wondershare Filmora Crack 2025 + Key Free DownloadWondershare Filmora Crack 2025 + Key Free Download
Wondershare Filmora Crack 2025 + Key Free Download
nasirali027m
?
Data Storytelling for Portfolio Leaders - Webinar
Data Storytelling for Portfolio Leaders - WebinarData Storytelling for Portfolio Leaders - Webinar
Data Storytelling for Portfolio Leaders - Webinar
OnePlan Solutions
?
How Biometric Attendance Systems Reduce Payroll Fraud & Costs?
How Biometric Attendance Systems Reduce Payroll Fraud & Costs?How Biometric Attendance Systems Reduce Payroll Fraud & Costs?
How Biometric Attendance Systems Reduce Payroll Fraud & Costs?
Star Link Communication Pvt Ltd
?
Symantec Endpoint Protection Presentation ºÝºÝߣ
Symantec Endpoint Protection Presentation ºÝºÝߣSymantec Endpoint Protection Presentation ºÝºÝߣ
Symantec Endpoint Protection Presentation ºÝºÝߣ
VLODI
?
The Role of Blockchain in Transparent & Secure Procurement.pptx
The Role of Blockchain in Transparent & Secure Procurement.pptxThe Role of Blockchain in Transparent & Secure Procurement.pptx
The Role of Blockchain in Transparent & Secure Procurement.pptx
asmith539880
?
40179_Bednar.ppt Oracle Database Upgrade Assistant
40179_Bednar.ppt Oracle Database Upgrade Assistant40179_Bednar.ppt Oracle Database Upgrade Assistant
40179_Bednar.ppt Oracle Database Upgrade Assistant
herryheryadi1
?
M251_Meeting 5 (Inheritance and Polymorphism).ppt
M251_Meeting 5 (Inheritance and Polymorphism).pptM251_Meeting 5 (Inheritance and Polymorphism).ppt
M251_Meeting 5 (Inheritance and Polymorphism).ppt
smartashammari
?
OutSystems User Group Utrecht February 2025.pdf
OutSystems User Group Utrecht February 2025.pdfOutSystems User Group Utrecht February 2025.pdf
OutSystems User Group Utrecht February 2025.pdf
mail496323
?
LLM Security - Smart to protect, but too smart to be protected
LLM Security - Smart to protect, but too smart to be protectedLLM Security - Smart to protect, but too smart to be protected
LLM Security - Smart to protect, but too smart to be protected
Ivo Andreev
?
Benefits of flutter development reasons to choose in 2025.pptx
Benefits of flutter development reasons to choose in 2025.pptxBenefits of flutter development reasons to choose in 2025.pptx
Benefits of flutter development reasons to choose in 2025.pptx
seo02siddhiinfosoft
?
Metaverse Meetup: Explore Mulesoft MAC Project
Metaverse Meetup: Explore  Mulesoft MAC ProjectMetaverse Meetup: Explore  Mulesoft MAC Project
Metaverse Meetup: Explore Mulesoft MAC Project
GiulioPicchi
?
Trivium: A Framework For Symbolic Metaprogramming in C++
Trivium: A Framework For Symbolic Metaprogramming in C++Trivium: A Framework For Symbolic Metaprogramming in C++
Trivium: A Framework For Symbolic Metaprogramming in C++
andreasmaniotis
?
VADY: Revolutionizing Business Intelligence with AI-Powered Insights
VADY: Revolutionizing Business Intelligence with AI-Powered InsightsVADY: Revolutionizing Business Intelligence with AI-Powered Insights
VADY: Revolutionizing Business Intelligence with AI-Powered Insights
NewFangledVision
?
Ship Show Ask at Lean Agile Edinburgh 2025
Ship Show Ask at Lean Agile Edinburgh 2025Ship Show Ask at Lean Agile Edinburgh 2025
Ship Show Ask at Lean Agile Edinburgh 2025
rouanw
?
Proxed.AI - Secure AI APIs in iOS - No SDK, Just Change Your API URL
Proxed.AI - Secure AI APIs in iOS - No SDK, Just Change Your API URLProxed.AI - Secure AI APIs in iOS - No SDK, Just Change Your API URL
Proxed.AI - Secure AI APIs in iOS - No SDK, Just Change Your API URL
Proxed.AI
?
Happiest MInds - Pimcore PIM Expertise.pdf
Happiest MInds - Pimcore PIM Expertise.pdfHappiest MInds - Pimcore PIM Expertise.pdf
Happiest MInds - Pimcore PIM Expertise.pdf
Happiest Minds Technologies
?
Web Development Services by Icubetechnolabs.pdf
Web Development Services by Icubetechnolabs.pdfWeb Development Services by Icubetechnolabs.pdf
Web Development Services by Icubetechnolabs.pdf
ICUBETECHNOLABS
?
Evaluation as an Essential Component of the Generative AI Lifecycle
Evaluation as an Essential Component of the Generative AI LifecycleEvaluation as an Essential Component of the Generative AI Lifecycle
Evaluation as an Essential Component of the Generative AI Lifecycle
Maxim Salnikov
?
Adobe Marketo Engage Champion Deep Dive: Extending Marketo With AEM Forms
Adobe Marketo Engage Champion Deep Dive: Extending Marketo With AEM FormsAdobe Marketo Engage Champion Deep Dive: Extending Marketo With AEM Forms
Adobe Marketo Engage Champion Deep Dive: Extending Marketo With AEM Forms
BradBedford3
?
Wondershare Filmora Crack 2025 + Key Free Download
Wondershare Filmora Crack 2025 + Key Free DownloadWondershare Filmora Crack 2025 + Key Free Download
Wondershare Filmora Crack 2025 + Key Free Download
nasirali027m
?
Data Storytelling for Portfolio Leaders - Webinar
Data Storytelling for Portfolio Leaders - WebinarData Storytelling for Portfolio Leaders - Webinar
Data Storytelling for Portfolio Leaders - Webinar
OnePlan Solutions
?
How Biometric Attendance Systems Reduce Payroll Fraud & Costs?
How Biometric Attendance Systems Reduce Payroll Fraud & Costs?How Biometric Attendance Systems Reduce Payroll Fraud & Costs?
How Biometric Attendance Systems Reduce Payroll Fraud & Costs?
Star Link Communication Pvt Ltd
?
Symantec Endpoint Protection Presentation ºÝºÝߣ
Symantec Endpoint Protection Presentation ºÝºÝߣSymantec Endpoint Protection Presentation ºÝºÝߣ
Symantec Endpoint Protection Presentation ºÝºÝߣ
VLODI
?
The Role of Blockchain in Transparent & Secure Procurement.pptx
The Role of Blockchain in Transparent & Secure Procurement.pptxThe Role of Blockchain in Transparent & Secure Procurement.pptx
The Role of Blockchain in Transparent & Secure Procurement.pptx
asmith539880
?
40179_Bednar.ppt Oracle Database Upgrade Assistant
40179_Bednar.ppt Oracle Database Upgrade Assistant40179_Bednar.ppt Oracle Database Upgrade Assistant
40179_Bednar.ppt Oracle Database Upgrade Assistant
herryheryadi1
?
M251_Meeting 5 (Inheritance and Polymorphism).ppt
M251_Meeting 5 (Inheritance and Polymorphism).pptM251_Meeting 5 (Inheritance and Polymorphism).ppt
M251_Meeting 5 (Inheritance and Polymorphism).ppt
smartashammari
?
OutSystems User Group Utrecht February 2025.pdf
OutSystems User Group Utrecht February 2025.pdfOutSystems User Group Utrecht February 2025.pdf
OutSystems User Group Utrecht February 2025.pdf
mail496323
?
LLM Security - Smart to protect, but too smart to be protected
LLM Security - Smart to protect, but too smart to be protectedLLM Security - Smart to protect, but too smart to be protected
LLM Security - Smart to protect, but too smart to be protected
Ivo Andreev
?
Benefits of flutter development reasons to choose in 2025.pptx
Benefits of flutter development reasons to choose in 2025.pptxBenefits of flutter development reasons to choose in 2025.pptx
Benefits of flutter development reasons to choose in 2025.pptx
seo02siddhiinfosoft
?
Metaverse Meetup: Explore Mulesoft MAC Project
Metaverse Meetup: Explore  Mulesoft MAC ProjectMetaverse Meetup: Explore  Mulesoft MAC Project
Metaverse Meetup: Explore Mulesoft MAC Project
GiulioPicchi
?
Trivium: A Framework For Symbolic Metaprogramming in C++
Trivium: A Framework For Symbolic Metaprogramming in C++Trivium: A Framework For Symbolic Metaprogramming in C++
Trivium: A Framework For Symbolic Metaprogramming in C++
andreasmaniotis
?
VADY: Revolutionizing Business Intelligence with AI-Powered Insights
VADY: Revolutionizing Business Intelligence with AI-Powered InsightsVADY: Revolutionizing Business Intelligence with AI-Powered Insights
VADY: Revolutionizing Business Intelligence with AI-Powered Insights
NewFangledVision
?
Ship Show Ask at Lean Agile Edinburgh 2025
Ship Show Ask at Lean Agile Edinburgh 2025Ship Show Ask at Lean Agile Edinburgh 2025
Ship Show Ask at Lean Agile Edinburgh 2025
rouanw
?
Proxed.AI - Secure AI APIs in iOS - No SDK, Just Change Your API URL
Proxed.AI - Secure AI APIs in iOS - No SDK, Just Change Your API URLProxed.AI - Secure AI APIs in iOS - No SDK, Just Change Your API URL
Proxed.AI - Secure AI APIs in iOS - No SDK, Just Change Your API URL
Proxed.AI
?
Web Development Services by Icubetechnolabs.pdf
Web Development Services by Icubetechnolabs.pdfWeb Development Services by Icubetechnolabs.pdf
Web Development Services by Icubetechnolabs.pdf
ICUBETECHNOLABS
?
Evaluation as an Essential Component of the Generative AI Lifecycle
Evaluation as an Essential Component of the Generative AI LifecycleEvaluation as an Essential Component of the Generative AI Lifecycle
Evaluation as an Essential Component of the Generative AI Lifecycle
Maxim Salnikov
?

Sigcheck option memo

  • 2. no option >sigcheck Shinobot.exe Sigcheck v2.30 - File version and signature viewer Copyright (C) 2004-2015 Mark Russinovich Sysinternals - www.sysinternals.com E:DesktopShinoBOT.exe: Verified: Unsigned Link date: 17:41 2016/12/22 Publisher: n/a Company: Sh1n0g1 Inc. Description: ShinoBOT Product: ShinoBOT Prod version: 3.1.0.0 File version: 3.1.0.0 MachineType: 32-bit
  • 3. -q (quiet) >sigcheck -q ShinoBOT.exe E:DesktopShinoBOT.exe: Verified: Unsigned Link date: 17:41 2016/12/22 Publisher: n/a Company: Sh1n0g1 Inc. Description: ShinoBOT Product: ShinoBOT Prod version: 3.1.0.0 File version: 3.1.0.0 MachineType: 32-bit The following banner disappears. Sigcheck v2.30 - File version and signature viewer Copyright (C) 2004-2015 Mark Russinovich Sysinternals - www.sysinternals.com
  • 4. -a (extended version information, entropy) >sigcheck -a ShinoBOT.exe Sigcheck v2.30 - File version and signature viewer Copyright (C) 2004-2015 Mark Russinovich Sysinternals - www.sysinternals.com E:DesktopShinoBOT.exe: Verified: Unsigned Link date: 17:41 2016/12/22 Publisher: n/a Company: Sh1n0g1 Inc. Description: ShinoBOT Product: ShinoBOT Prod version: 3.1.0.0 File version: 3.1.0.0 MachineType: 32-bit Binary Version: 3.1.0.0 Original Name: SHINOBOT_BUILDER.exe Internal Name: SHINOBOT_BUILDER.exe Copyright: Sh1n0g1 Inc. Comments: RAT simulator Entropy: 4.719
  • 5. -h (hashes) >sigcheck -h ShinoBOT.exe Sigcheck v2.30 - File version and signature viewer Copyright (C) 2004-2015 Mark Russinovich Sysinternals - www.sysinternals.com E:DesktopShinoBOT.exe: Verified: Unsigned Link date: 17:41 2016/12/22 Publisher: n/a Company: Sh1n0g1 Inc. Description: ShinoBOT Product: ShinoBOT Prod version: 3.1.0.0 File version: 3.1.0.0 MachineType: 32-bit MD5: 9B2166D3B72C84396EDECE1673E923B7 SHA1: CF8C8D3F48FB1304E0AAB7EFB6C3EB9BBE833BC5 PESHA1: 5A7BAE6C68F50ABA37EB0FDC5B698115DB13C14B PE256: CB30CF07163B72F49DADA51CDC3965E6F79AA6D9A430524AD81C0D445155CDDC SHA256: BF7EFF73A37965B7ECD784E621F0B7118402C4C03E450E648B8922F070D440C8 IMP: F34D5F2D4577ED6D9CEEC516C1F5A744
  • 6. -v (VirusTotal) >sigcheck -v ShinoBOT1326.exe Sigcheck v2.30 - File version and signature viewer Copyright (C) 2004-2015 Mark Russinovich Sysinternals - www.sysinternals.com e:WorkShinoBOT1326.exe: Verified: Unsigned Link date: 9:23 2013/07/25 Publisher: n/a Company: Sh1n0g1 Description: ShinoBOT Product: ShinoBOT Prod version: 1.3.2.6 File version: 1.3.2.6 MachineType: 32-bit VT detection: 44/57 VT link: https://www.virustotal.com/file/e10506ed829846ae5b7cddbb7ff636b18f632f28f072f9 b399b9cbdbd643b8d9/analysis/
  • 7. -i (signed info) >sigcheck -i DummyPopup_Signed.exe Sigcheck v2.30 - File version and signature viewer Copyright (C) 2004-2015 Mark Russinovich Sysinternals - www.sysinternals.com E:DesktopDummyPopup_Signed.exe: Verified: Signed Catalog: E:DesktopDummyPopup_Signed.exe Signer: Sh1n0g1 Inc Status: ???????????????????????????????? Valid Usage: All Serial Number: 01 Thumbprint: 9C85EA7F5672E74E3A5C45279EECBD979B559DDB Algorithm: SHA1 Valid from: 16:54 2013/11/22 Valid to: 16:54 2015/11/22 Signing date: n/a Publisher: Sh1n0g1 Inc Company: n/a Description: Popup Product: Popup Prod version: 1.0.0.0 File version: 1.0.0.0 MachineType: 32-bit
  • 8. aihqv combined >sigcheck -a -i -h -q -v DummyPopup_Signed.exe E:DesktopDummyPopup_Signed.exe: Verified: Signed Catalog: E:DesktopDummyPopup_Signed.exe Signer: Sh1n0g1 Inc Status: ???????????????????????????????? Valid Usage: All Serial Number: 01 Thumbprint: 9C85EA7F5672E74E3A5C45279EECBD979B559DDB Algorithm: SHA1 Valid from: 16:54 2013/11/22 Valid to: 16:54 2015/11/22 Signing date: n/a Publisher: Sh1n0g1 Inc Company: n/a Description: Popup Product: Popup Prod version: 1.0.0.0 File version: 1.0.0.0 MachineType: 32-bit Binary Version: 1.0.0.0 Original Name: DummyPopup.exe Internal Name: DummyPopup.exe Copyright: Copyright ? 2013 Comments: n/a Entropy: 6.755 MD5: 66F65B57235F9886537BB791DB6DFB14 SHA1: D71365CCDC97D0A1BD88A97C81DAD6562749CA0A PESHA1: AC6275E718A4E334B042B870DD66F3BB759B56FA PE256: 05D0ABD52B5E3A6C9CBD2033FC806568EEDFD235C0F3297FE9F3F409580A1FAA SHA256: 821B0E74CBBF042C32A691103D5DC449A1812E9FB0E5185B61B2F21CCCC1E883 IMP: F34D5F2D4577ED6D9CEEC516C1F5A744 VT detection: 1/56 VT link: https://www.virustotal.com/file/821b0e74cbbf042c32a691103d5dc449a1812e9fb0e5185b61b2f21cccc1e883/analysis/