Threat Database Trojans Win32/ExpressDownloader.J

Win32/ExpressDownloader.J

By CagedTech in Trojans

Threat Scorecard

Threat Level: 10 % (Normal)
Infected Computers: 52
First Seen: September 29, 2014
Last Seen: November 24, 2025
OS(es) Affected: Windows

Win32/ExpressDownloader.J is a Trojan that can harm the affected computer. As soon as Win32/ExpressDownloader.J is installed, Win32/ExpressDownloader.J will start its harmful activities. Win32/ExpressDownloader.J has the capacity of opening a backdoor on your computer so third parties may access your machine. Win32/ExpressDownloader.J also changes your browser's settings and the image of your desktop's background and causes the computer to slow down considerably. Win32/ExpressDownloader.J is the kind of threat that shouldn't be allowed to stay on an affected computer. Win32/ExpressDownloader.J's removal requires the cooperation of a strong anti-malware tool.

Analysis Report

General information

Family Name: PUP.ExpressDownloader.A
Signature status: Self Signed

Known Samples

MD5: f8130b6678d02112913725ed7530e8dd
SHA1: f44235d3f6da873c4d2b3292e082542fa65812da
SHA256: D98E470E942E009D6545BEE07CE3E5D8EA1DD0C1C6B321837EDBEAC1C8C9AC82
File Size: 4.44 MB, 4442976 bytes

Windows Portable Executable Attributes

  • File doesn't have "Rich" header
  • File doesn't have exports table
  • File doesn't have relocations information
  • File has TLS information
  • File is 32-bit executable
  • File is either console or GUI application
  • File is GUI application (IMAGE_SUBSYSTEM_WINDOWS_GUI)
  • File is Native application (NOT .NET application)
  • File is not packed
  • IMAGE_FILE_DLL is not set inside PE header (Executable)
Show More
  • IMAGE_FILE_EXECUTABLE_IMAGE is set inside PE header (Executable Image)

File Icons

Windows PE Version Information

Name Value
File Description The Sparter executable
File Version 1, 0, 1180, 1
Internal Name sparter
Legal Copyright © 2006 - 2016 Sparter <sparter>
Original Filename sparter.exe
Product Name sparter app
Product Version 7.92.2.1

Digital Signatures

Signer Root Status
Live Commit LLC Live Commit LLC Self Signed

Block Information

Total Blocks: 7,000
Potentially Malicious Blocks: 1,405
Whitelisted Blocks: 5,511
Unknown Blocks: 84

Visual Map

0 0 0 0 0 0 0 0 0 0 0 0 0 x 0 0 0 0 0 x 0 0 0 0 0 x 0 0 x 0 x 0 0 0 x 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 x 0 0 0 0 0 0 0 0 0 0 0 0 0 x 0 1 0 1 0 0 x 0 0 0 0 0 0 0 0 0 2 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 x 0 x 0 0 0 x x x 0 0 0 0 0 x 0 0 0 0 0 0 0 0 0 0 0 0 0 x 0 0 x 0 0 x 0 0 x 0 0 0 0 x 0 0 0 x x x x x 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 x 0 x 0 0 0 0 0 0 0 0 0 x x 0 0 x x 0 0 0 0 0 x 0 0 0 0 0 0 0 x 0 0 0 0 0 0 0 0 0 0 0 0 0 x x x x 0 x 0 0 0 0 1 0 0 0 0 0 x 0 0 x x 0 x 0 0 0 0 x 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 1 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 x x 0 0 x 0 0 x x x 0 0 x 0 0 x 0 0 x x 0 0 0 x x 0 0 x 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 x x x 0 0 x 0 0 x 0 x 0 0 0 0 x 0 x 0 x 0 x 0 0 0 0 x 0 0 0 0 0 0 0 x x x 0 0 x x 0 0 0 0 0 0 0 0 0 0 x x 0 0 x 0 x x 0 0 x x 0 0 x x 0 0 0 0 0 0 0 0 x 0 0 0 0 0 0 0 0 0 0 0 x x 0 0 0 0 0 0 x 0 0 0 0 0 x 0 x 0 x x x 0 x 0 x 0 0 x 0 0 0 0 0 0 0 0 0 0 0 x x x x x x x 0 x x 0 0 0 0 x x x x 0 0 0 x 0 x 0 0 x x x x x 0 x 0 x x 0 x 0 x x x 0 0 0 0 x 0 x 0 x x x 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 x 0 0 0 0 x 0 x x 0 0 x 0 x 0 x x x x 0 0 x 0 0 x x 0 0 0 0 x x x x 0 1 1 0 0 0 0 0 0 x x 0 0 0 0 0 0 0 0 0 0 0 0 0 x x x 0 0 0 x 0 x 0 0 x 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 x 0 0 0 x x 0 0 0 0 0 x x 0 0 0 0 0 0 0 x 0 0 0 0 0 0 0 0 0 0 0 x x 0 0 0 0 x x 0 0 0 x 0 0 0 x 0 0 x 0 0 0 x 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 x 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 x 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 x x 0 0 0 0 0 0 x x 0 0 0 x 0 0 0 0 0 0 0 0 0 x 0 0 0 0 0 0 0 0 0 0 0 0 x 0 0 0 0 0 0 0 0 x 0 0 0 0 x x x x 0 x 0 0 0 0 x 0 0 0 0 0 0 0 0 0 0 x 0 0 0 0 0 0 0 0 0 0 0 x 0 0 0 0 x 0 0 x x 0 x 0 0 0 0 x 0 0 0 x 0 0 0 0 0 x 0 0 x x 0 0 x 0 x 0 0 0 0 0 0 0 0 x x 0 0 0 0 0 x 0 x x 0 x 0 x x x x x 0 x 0 0 0 0 0 0 0 0 0 x x 0 0 0 0 0 0 0 0 x x x x x x 0 0 0 0 0 0 0 0 0 0 0 0 x 0 0 0 x 0 x 0 0 0 0 0 0 0 0 x 0 0 0 x x x 0 0 0 0 0 0 0 0 0 0 0 x x x 0 0 0 0 0 0 0 x x x 0 0 0 0 x 0 0 x x x 0 0 0 0 0 0 0 0 0 0 0 0 x x 0 0 0 0 0 0 x 0 0 x 0 0 0 0 0 0 0 0 0 0 x x x x 0 x 0 0 0 0 0 x 0 0 0 0 0 0 0 x x 0 0 x 0 0 0 x x 0 x x 0 x x x 0 x 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 x 0 0 0 0 0 0 x 0 x x 0 x 0 0 x x 0 0 0 0 x x x 0 x x 0 0 0 0 0 x 0 0 x 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 x x 0 0 0 0 0 0 0 0 0 0 0 0 0 0 x x x 0 0 x 0 x x 0 0 x 0 0 0 x x 0 0 0 0 0 x 0 x x x x x x x x x 0 x 0 x 0 0 0 0 0 0 x x 0 0 0 0 0 x x 0 x 0 0 0 0 0 0 0 0 x 0 0 x 0 0 x 0 0 0 0 0 0 0 0 x 0 0 0 0 0 0 0 x 0 0 0 0 0 0 0 x x x x x x 0 0 0 0 0 x 0 x x 0 x 0 x 0 0 0 0 x 0 0 0 x 0 0 x 0 x x 0 x 0 x x x 0 0 x 0 x 0 x 0 0 x x 0 x 0 0 0 0 0 x 0 x 0 0 0 0 x x x 0 0 0 0 0 x 0 0 0 x 0 0 x 0 0 0 0 0 x x 0 x x 0 x 0 0 x x x 0 0 0 0 x 0 0 0 0 0 0 0 0 x 0 x x 0 x 0 x 0 0 0 0 0 x 0 0 x 0 0 0 x x x x 0 0 0 x 0 0 x 0 0 0 x 0 0 0 x 0 0 0 x 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 x x 0 0 0 0 0 x 0 0 0 0 0 0 x 0 0 0 0 x x x 0 x x 0 x 0 x 0 x 0 0 0 0 0 0 0 0 x x x 0 x 0 0 0 x 0 0 0 0 0 0 x 0 0 0 x 1 0 0 0 x 0 0 1 1 0 0 0 0 0 0 0 0 x 0 0 0 0 0 0 x 0 x 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 x x 0 0 x 0 0 0 0 0 0 0 0 x 0 0 0 x x 0 x 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 x 0 0 x x 0 0 x 0 x x x x x 0 0 0 0 0 0 0 x 0 0 0 0 0 0 0 0 0 0 0 0 x 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 x 0 0 0 0 0 0 0 0 0 0 x 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 x x x 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 x x 0 0 x ? 0 x 0 0 0 x 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 x x x 0 x 0 x 0 0 0 0 0 0 0 0 0 0 0 x x x 0 0 x 0 0 0 0 0 0 0 0 0 0 0 0 x x x x x 0 0 0 0 0 0 0 0 0 0 0 x 0 0 0 x 0 0 0 0 0 0 0 0 0 x 0 0 0 0 0 0 0 0 0 0 0 x 0 0 0 0 0 0 0 x 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 ? 0 0 0 0 0 0 0 0 0 0 0 0 x 0 0 0 x 0 0 x 0 0 0 0 0 0 0 0 0 0 0 0 0 0 x 0 x 0 0 0 0 x 0 0 0 0 x 0 x x 0 0 x 0 0 0 0 0 0 x 0 x 0 0 0 0 0 0 0 0 x 0 0 0 0 0 0 0 0 0 x 0 x x 0 0 x 0 0 x x x 0 0 0 0 0 x 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 x x x x x x x x x x x x 0 0 0 0 0 0 0 0 0 0 x 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 x 0 0 0 0 0 0 0 0 0 0 0 0 0 0 x x 0 0 0 0 0 0 x x 0 x x x x 0 x x 0 0 0 0 x 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 x 0 0 0 0 0 0 0 0 0 0 0 x 0 0 0 0 0 0 0 0 0 0
... Data truncated
0 - Probable Safe Block
? - Unknown Block
x - Potentially Malicious Block

Similar Families

  • ExpressDownloader.B

Files Modified

File Attributes
c:\users\user\appdata\local\temp\lxye2nyjq9.tmp\htmlayout.dll Generic Write,Read Attributes

Windows API Usage

Category API
Network Winsock2
  • WSAStartup

Trending

Most Viewed

Loading...