Threat Database Trojans Trojan.Delf.G

Trojan.Delf.G

By CagedTech in Trojans

Threat Scorecard

Popularity Rank: 23,468
Threat Level: 80 % (High)
Infected Computers: 90
First Seen: July 24, 2009
Last Seen: January 20, 2026
OS(es) Affected: Windows

Aliases

15 security vendors flagged this file as malicious.

Antivirus Vendor Detection
Panda Trj/Downloader.MDW
NOD32 probably a variant of Win32/TrojanDownloader.Delf
McAfee-GW-Edition Trojan.Dldr.Delf.gkb
McAfee+Artemis Generic!Artemis
Ikarus Trojan-Downloader.Win32.Delf
F-Secure Trojan-Downloader.Win32.Delf.gkb
eSafe Suspicious File
Comodo TrojWare.Win32.TrojanDownloader.Delf.gkb
BitDefender Trojan.Generic.249612
AVG Downloader.Generic7.EWA
Avast Win32:Rootkit-gen
Authentium W32/Downldr2.BOTB
Antiy-AVL Trojan/Win32.Delf
AntiVir TR/Dldr.Delf.gkb
AhnLab-V3 Win-Trojan/Xema.variant

SpyHunter Detects & Remove Trojan.Delf.G

File System Details

Trojan.Delf.G may create the following file(s):
# File Name MD5 Detections
1. FD.exe 0bea26a93ed61a0ecf9ef9d5db66464d 0

Analysis Report

General information

Family Name: Trojan.Delf.G
Signature status: No Signature

Known Samples

MD5: 84514c305dab0f4bc28496ac728d60c7
SHA1: fe68f744ef272013ef6e5ca2b582e69bc576c859
SHA256: 4BF40B298B85472D408D8955191D1E5FFA0514858FB004EFE5BED7AB6CC685A8
File Size: 9.78 MB, 9780484 bytes

Windows Portable Executable Attributes

  • File doesn't have "Rich" header
  • File doesn't have debug information
  • File doesn't have exports table
  • File doesn't have relocations information
  • File doesn't have security information
  • File has TLS information
  • File is 32-bit executable
  • File is either console or GUI application
  • File is GUI application (IMAGE_SUBSYSTEM_WINDOWS_GUI)
  • File is Native application (NOT .NET application)
Show More
  • File is not packed
  • IMAGE_FILE_DLL is not set inside PE header (Executable)
  • IMAGE_FILE_EXECUTABLE_IMAGE is set inside PE header (Executable Image)

File Icons

Windows PE Version Information

Name Value
Comments This installation was built with Inno Setup.
Company Name DXsoft
File Description AALog Setup
File Version 3.1.0.1157
Legal Copyright Copyright © 1998-2011 Alexander Anipkin
Product Name AALog
Product Version 3.1.0.1157

File Traits

  • HighEntropy
  • imgui
  • packed
  • VirtualQueryEx
  • WriteProcessMemory
  • x86

Files Modified

File Attributes
c:\users\user\appdata\local\temp\is-ie66t.tmp\_isetup\_regdll.tmp Generic Read,Write Data,Write Attributes,Write extended,Append data
c:\users\user\appdata\local\temp\is-ie66t.tmp\_isetup\_setup64.tmp Generic Read,Write Data,Write Attributes,Write extended,Append data
c:\users\user\appdata\local\temp\is-ie66t.tmp\_isetup\_shfoldr.dll Generic Read,Write Data,Write Attributes,Write extended,Append data
c:\users\user\appdata\local\temp\is-rfp93.tmp\fe68f744ef272013ef6e5ca2b582e69bc576c859_0009780484.tmp Generic Write,Read Attributes

Windows API Usage

Category API
Process Manipulation Evasion
  • NtUnmapViewOfSection
Process Shell Execute
  • CreateProcess
User Data Access
  • GetUserObjectInformation

Shell Command Execution

"C:\Users\Yvgtxgkd\AppData\Local\Temp\is-RFP93.tmp\fe68f744ef272013ef6e5ca2b582e69bc576c859_0009780484.tmp" /SL5="$5030A,9536224,53248,c:\users\user\downloads\fe68f744ef272013ef6e5ca2b582e69bc576c859_0009780484"

Related Posts

Trending

Most Viewed

Loading...