Threat Database Trojans Exploit:JS/Dotcaf.A

Exploit:JS/Dotcaf.A

By CagedTech in Trojans

Threat Scorecard

Popularity Rank: 1,048
Threat Level: 90 % (High)
Infected Computers: 34,423
First Seen: October 22, 2014
Last Seen: February 14, 2026
OS(es) Affected: Windows

Exploit:JS/Dotcaf.A is a threat that may install itself on your computer using known vulnerabilities, freeware programs, e-mail attachments, torrents and may enter the computer bundled with other threats such as HEUR.Trojan.Win32.Generic Virus. Exploit:JS/Dotcaf.A is used by hackers to install Possibly Unwanted Programs or threats on your machine. Exploit:JS/Dotcaf.A opens a backdoor that will be a gateway for third parties to take control of the infected computer. Exploit:JS/Dotcaf.A changes your Web browser settings, adds corrupted codes to your Registry and disables security-related software. Exploit:JS/Dotcaf.A may collect selected data that will be used against the computer user. Exploit:JS/Dotcaf.A is a high-level threat and, as such, should be deleted from the infected computer immediately after been detected to avoid further harm. Computer users should run a deep scan of their systems to detect all the changes made by Exploit:JS/Dotcaf.A, remove it and any related threat.

Analysis Report

General information

Family Name: Trojan.Injector.E
Signature status: No Signature

Known Samples

MD5: 68887a9983368cd741a9ac1ab3c1572d
SHA1: a3a39f02d233c6a0b8e089ce6961fbad4ac081d6
SHA256: 71653A80DD76F94F70B27AA45AE83FB4B80E3865B001BB9AA0063ADA1AE0BEFA
File Size: 3.03 MB, 3029584 bytes
MD5: 73ee59774faf6c435cbd4cc5c0427cc2
SHA1: 90e4cef02053db008f127b60d464ffbf9f42dba2
SHA256: DBDBC4995389014C9237206E1D8F0812B4C8E487BF053DF75CD9234A821AA783
File Size: 1.28 MB, 1282488 bytes
MD5: cb0c91363f2497a6ade323e1232286bb
SHA1: 2d4e071d13cf59ece24ad178792f91553b552beb
SHA256: 431116DB9E29CC47CA4EB797FA9AC7658D6809EB36C65F889DFB7C42964ABF9D
File Size: 1.80 MB, 1796663 bytes

Windows Portable Executable Attributes

  • File doesn't have "Rich" header
  • File doesn't have debug information
  • File doesn't have exports table
  • File doesn't have relocations information
  • File doesn't have security information
  • File has exports table
  • File has TLS information
  • File is 32-bit executable
  • File is either console or GUI application
  • File is GUI application (IMAGE_SUBSYSTEM_WINDOWS_GUI)
Show More
  • File is Native application (NOT .NET application)
  • File is not packed
  • IMAGE_FILE_DLL is not set inside PE header (Executable)
  • IMAGE_FILE_EXECUTABLE_IMAGE is set inside PE header (Executable Image)

File Icons

Windows PE Version Information

Name Value
Company Name
  • Abyssmedia.com
  • Microsoft
File Description Audio Converter Plus
File Version
  • 6.9.1.0
  • 1.00
Internal Name Win
Original Filename Win.exe
Product Name
  • Audio Converter Plus
  • Win
Product Version
  • 6.9.1.0
  • 1.00

Digital Signatures

Signer Root Status
3DP GlobalSign Root Not Trusted

File Traits

  • 2+ executable sections
  • HighEntropy
  • x86

Files Modified

File Attributes
c:\users\user\appdata\local\temp\nsm62c3.tmp\langdll.dll Generic Write,Read Attributes
c:\users\user\appdata\local\temp\nsx62b3.tmp Generic Read,Write Data,Write Attributes,Write extended,Append data,Delete

Windows API Usage

Category API
Other Suspicious
  • SetWindowsHookEx

Trending

Most Viewed

Loading...