{"id":1877,"date":"2013-05-08T19:33:04","date_gmt":"2013-05-08T19:33:04","guid":{"rendered":"http:\/\/www.hexacorn.com\/blog\/?p=1877"},"modified":"2019-08-31T23:08:37","modified_gmt":"2019-08-31T23:08:37","slug":"and-the-most-popular-windows-account-for-compiling-malware-is","status":"publish","type":"post","link":"https:\/\/www.hexacorn.com\/blog\/2013\/05\/08\/and-the-most-popular-windows-account-for-compiling-malware-is\/","title":{"rendered":"&#8230;and the most popular windows account for compiling malware is:"},"content":{"rendered":"<p>Administrator.<\/p>\n<p>Many malware samples contain debug strings that include paths often directly pointing to a location where the source code is stored and so it happens that often it&#8217;s also a location under the USERPROFILE. For the fun of it, I extracted the strings from a large batch of samples and came up with the following statistics (showing top 50):<\/p>\n<pre>&nbsp;&nbsp; 3893 Administrator\n&nbsp;&nbsp; 2963 JUANJO\n&nbsp;&nbsp; 1121 ryanch\n&nbsp;&nbsp;&nbsp; 928 Boy\n&nbsp;&nbsp;&nbsp; 617 UserXP\n&nbsp;&nbsp;&nbsp; 612 user\n&nbsp;&nbsp;&nbsp; 519 1337\n&nbsp;&nbsp;&nbsp; 502 User\n&nbsp;&nbsp;&nbsp; 465 Admin\n&nbsp;&nbsp;&nbsp; 435 root\n&nbsp;&nbsp;&nbsp; 422 bld4act\n&nbsp;&nbsp;&nbsp; 418 Owner\n&nbsp;&nbsp;&nbsp; 347 nosferatus\n&nbsp;&nbsp;&nbsp; 305 Administrateur\n&nbsp;&nbsp;&nbsp; 300 M4x\n&nbsp;&nbsp;&nbsp; 296 ismael\n&nbsp;&nbsp;&nbsp; 277 goga\n&nbsp;&nbsp;&nbsp; 277 Kyle\n&nbsp;&nbsp;&nbsp; 255 Mirko\n&nbsp;&nbsp;&nbsp; 247 1134\n&nbsp;&nbsp;&nbsp; 244 kdglkrkjdfhslej\n&nbsp;&nbsp;&nbsp; 241 FEDERIKO\n&nbsp;&nbsp;&nbsp; 234 t0fx\n&nbsp;&nbsp;&nbsp; 231 rstephens\n&nbsp;&nbsp;&nbsp; 219 DarkCoderSc\n&nbsp;&nbsp;&nbsp; 218 gcc\n&nbsp;&nbsp;&nbsp; 205 icyheart\n&nbsp;&nbsp;&nbsp; 200 Dave\n&nbsp;&nbsp;&nbsp; 197 michael\n&nbsp;&nbsp;&nbsp; 197 Roshan\n&nbsp;&nbsp;&nbsp; 197 James\n&nbsp;&nbsp;&nbsp; 195 Ben\n&nbsp;&nbsp;&nbsp; 182 John\n&nbsp;&nbsp;&nbsp; 178 admin\n&nbsp;&nbsp;&nbsp; 173 Dev\n&nbsp;&nbsp;&nbsp; 161 box1\n&nbsp;&nbsp;&nbsp; 157 nonadmin\n&nbsp;&nbsp;&nbsp; 153 FELIPE\n&nbsp;&nbsp;&nbsp; 152 Familie\n&nbsp;&nbsp;&nbsp; 151 Timothy\n&nbsp;&nbsp;&nbsp; 137 Dhivin\n&nbsp;&nbsp;&nbsp; 133 Vortex\n&nbsp;&nbsp;&nbsp; 131 Robert\n&nbsp;&nbsp;&nbsp; 130 dabdoub\n&nbsp;&nbsp;&nbsp; 129 USER\n&nbsp;&nbsp;&nbsp; 127 dr zinou\n&nbsp;&nbsp;&nbsp; 125 packar\n&nbsp;&nbsp;&nbsp; 122 David\n&nbsp;&nbsp;&nbsp; 116 nathu\n&nbsp;&nbsp;&nbsp; 116 Daniel<\/pre>\n<p>It&#8217;s obviously biased.<\/p>\n<p>Other interesting names include:<\/p>\n<ul>\n<li>tom age five<\/li>\n<li>GANGSTA<\/li>\n<li>Krusty the Clown<\/li>\n<li>^_^<\/li>\n<li>ItchyFingerz<\/li>\n<li>irishboy<\/li>\n<li>romantic<\/li>\n<li>lol<\/li>\n<li>brad pitt<\/li>\n<li>Love Bebe<\/li>\n<li>LorD^^$$steal3R<\/li>\n<li>Cyber-Warrior Ender<\/li>\n<li>auchan<\/li>\n<li>F-B-I<\/li>\n<li>Valued Sony Customer<\/li>\n<li>SexyReplay<\/li>\n<li>Microsoft<\/li>\n<li>Poo<\/li>\n<li>Trojan<\/li>\n<li>P@wn3d<\/li>\n<li>Emperor Zhou Tai Nu<\/li>\n<\/ul>\n<p>There are over 7000 account names on the list. If you want the full list, please contact me offline.<\/p>\n","protected":false},"excerpt":{"rendered":"<p>Administrator. Many malware samples contain debug strings that include paths often directly pointing to a location where the source code is stored and so it happens that often it&#8217;s also a location under the USERPROFILE. For the fun of it, &hellip; <a href=\"https:\/\/www.hexacorn.com\/blog\/2013\/05\/08\/and-the-most-popular-windows-account-for-compiling-malware-is\/\">Continue reading <span class=\"meta-nav\">&rarr;<\/span><\/a><\/p>\n","protected":false},"author":1,"featured_media":0,"comment_status":"closed","ping_status":"closed","sticky":false,"template":"","format":"standard","meta":[],"categories":[28,9,88],"tags":[],"_links":{"self":[{"href":"https:\/\/www.hexacorn.com\/blog\/wp-json\/wp\/v2\/posts\/1877"}],"collection":[{"href":"https:\/\/www.hexacorn.com\/blog\/wp-json\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/www.hexacorn.com\/blog\/wp-json\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/www.hexacorn.com\/blog\/wp-json\/wp\/v2\/users\/1"}],"replies":[{"embeddable":true,"href":"https:\/\/www.hexacorn.com\/blog\/wp-json\/wp\/v2\/comments?post=1877"}],"version-history":[{"count":5,"href":"https:\/\/www.hexacorn.com\/blog\/wp-json\/wp\/v2\/posts\/1877\/revisions"}],"predecessor-version":[{"id":6725,"href":"https:\/\/www.hexacorn.com\/blog\/wp-json\/wp\/v2\/posts\/1877\/revisions\/6725"}],"wp:attachment":[{"href":"https:\/\/www.hexacorn.com\/blog\/wp-json\/wp\/v2\/media?parent=1877"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/www.hexacorn.com\/blog\/wp-json\/wp\/v2\/categories?post=1877"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/www.hexacorn.com\/blog\/wp-json\/wp\/v2\/tags?post=1877"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}