Threat Database Trojans PWS:Win32/Blaknight.A

PWS:Win32/Blaknight.A

By CagedTech in Trojans

Threat Scorecard

Popularity Rank: 13,805
Threat Level: 90 % (High)
Infected Computers: 232
First Seen: November 24, 2014
Last Seen: September 26, 2025
OS(es) Affected: Windows

PWS:Win32/Blaknight.A is a highly threatening Trojan infection, also detected as Infostealer.Limitail. The main function of PWS:Win32/Blaknight.A is to collect sensitive information such as the user name and passwords for any kind of accounts, including banking accounts. After collecting the mentioned data, PWS:Win32/Blaknight.A may send it to a remote server. PWS:Win32/Blaknight.A may install other threats on the infected computer. PWS:Win32/Blaknight.A may block some applications from running, especially if they are related to your machine's security. Computer users that got infected by PWS:Win32/Blaknight.A should change their user names and passwords as soon as the threat has been uncovered. Failure to accomplish these measures may lead to fraud, identity theft and other harmful consequences. Do not hesitate! You should choose an up-to-date and powerful anti-malware device to remove PWS:Win32/Blaknight.A from your computer immediately.

Analysis Report

General information

Family Name: Trojan.Small.AB
Signature status: No Signature

Known Samples

MD5: 1f982d2737cacbe0061aa9df8f4d0ef0
SHA1: d452381de8c9bcf2bdad995210eabe25f3a9329d
SHA256: DCB69F52D2DBEBB00504D486243BD7A07A9896620A4FA182879BD3D78099E780
File Size: 406.02 KB, 406016 bytes

Windows Portable Executable Attributes

  • File doesn't have "Rich" header
  • File doesn't have debug information
  • File doesn't have exports table
  • File doesn't have relocations information
  • File doesn't have security information
  • File is 32-bit executable
  • File is either console or GUI application
  • File is GUI application (IMAGE_SUBSYSTEM_WINDOWS_GUI)
  • File is Native application (NOT .NET application)
  • File is not packed
Show More
  • IMAGE_FILE_DLL is not set inside PE header (Executable)
  • IMAGE_FILE_EXECUTABLE_IMAGE is set inside PE header (Executable Image)

File Icons

File Traits

  • HighEntropy
  • No Version Info
  • WriteProcessMemory
  • x86

Block Information

Total Blocks: 105
Potentially Malicious Blocks: 86
Whitelisted Blocks: 16
Unknown Blocks: 3

Visual Map

x x 0 x x x x ? x ? x x x 0 0 x x 0 0 0 x x x 0 x 0 x x x x x x x x 0 x x x x x 0 x x x x x x x x 0 0 x x x 0 x x x x x x x x x x x x x 0 0 x 0 x x x x x x x x x x x x x x x x x x x x x x x x x x x x x x x x ?
0 - Probable Safe Block
? - Unknown Block
x - Potentially Malicious Block

Similar Families

  • Small.AB

Trending

Most Viewed

Loading...