Threat Database Trojans Trojan.Blackmoon.G

Trojan.Blackmoon.G

Trojan.Blackmoon.G is classified as a Trojan, a type of malicious software that disguises itself as a legitimate or harmless file to trick users into installing it. Once active on a system, Trojans like this one typically operate quietly in the background, carrying out harmful actions without the user's knowledge or consent. Because specific technical details about this particular variant are limited, this article describes the behavior that is typical of Trojans in this category so you can better understand the general risks involved.

What This Threat Does

Like most Trojans, Trojan.Blackmoon.G is designed to perform malicious actions while hiding its presence from the user. Typical Trojan behavior includes allowing remote attackers to gain unauthorized access to an infected machine, collecting sensitive information such as login credentials or personal files, downloading and installing additional malware, modifying system settings, and establishing communication with remote servers controlled by cybercriminals. Trojans in this family may also attempt to disable or interfere with security tools in order to avoid detection and remain on the system for as long as possible.

How It Usually Gets Onto Computers

Trojans commonly spread through deceptive methods rather than self-replication. Typical infection routes include malicious email attachments disguised as invoices, documents, or other legitimate-looking files; fake software updates or cracked program downloads; bundled installers that silently add unwanted components alongside desired software; malicious links shared through messaging apps or social media; and compromised or deceptive websites that prompt users to download infected files. Users often unknowingly trigger the infection by opening an attachment or running a downloaded file that appears trustworthy.

Risks for the User

An active Trojan infection can expose a user to serious risks. These typically include theft of personal or financial information, unauthorized remote access to the device, installation of additional malware such as ransomware or spyware, degraded system performance due to background malicious processes, and potential loss of privacy if the Trojan is capable of logging keystrokes or capturing screenshots. In some cases, infected machines may also be used as part of a larger network of compromised computers without the owner's awareness.

Signs of Infection

Because Trojans are built to operate stealthily, signs of infection are not always obvious. However, users may notice unusual symptoms such as slower-than-normal system performance, unexpected pop-ups or error messages, unfamiliar processes running in Task Manager, programs or security tools being disabled without explanation, unusual network activity, or changes to browser settings and homepages that were not made by the user. Any of these symptoms can indicate the presence of a Trojan or similar malicious software.

How to Stay Protected

To reduce the risk of infection, users should avoid opening email attachments or clicking links from unknown or unexpected sources, download software only from official or trusted websites, keep the operating system and installed applications updated with the latest security patches, and use reputable security software to scan downloads and monitor system activity. Regularly backing up important files, exercising caution with free or cracked software, and being wary of urgent or suspicious messages requesting personal information are also effective ways to lower the chances of encountering threats like Trojan.Blackmoon.G.

Analysis Report

General information

Family Name: Trojan.Blackmoon.G
Packers: UPX
Signature status: No Signature

Known Samples

MD5: 1d6ebc38c101d54a84e109a0122d7c0f
SHA1: 72b939986b2a1222dad961e6f3f373ee5cb5c55b
SHA256: 008EA17F9F86AAEE588D4CF666C7A901C6DB7B7C29E7CA7EF30B29C18E2E7A91
File Size: 158.72 KB, 158720 bytes

Windows Portable Executable Attributes

  • File doesn't have "Rich" header
  • File doesn't have debug information
  • File doesn't have exports table
  • File doesn't have relocations information
  • File doesn't have resources
  • File doesn't have security information
  • File has been packed
  • File is 32-bit executable
  • File is either console or GUI application
  • File is GUI application (IMAGE_SUBSYSTEM_WINDOWS_GUI)
Show More
  • File is Native application (NOT .NET application)
  • IMAGE_FILE_DLL is not set inside PE header (Executable)
  • IMAGE_FILE_EXECUTABLE_IMAGE is set inside PE header (Executable Image)

File Traits

  • .UPX
  • 2+ executable sections
  • HighEntropy
  • No Version Info
  • packed
  • x86

Block Information

Total Blocks: 991
Potentially Malicious Blocks: 331
Whitelisted Blocks: 292
Unknown Blocks: 368

Visual Map

0 x x ? ? x x ? x ? x x 0 ? 0 0 0 ? ? x x 0 x x x 0 0 ? x ? ? 0 0 ? ? ? ? ? x x x x ? x x x x x ? ? ? 0 ? 0 ? ? ? ? x x x ? ? x 0 x 0 x 0 x 0 x ? ? x x x x ? x x x x x x 0 x ? x ? ? x ? x ? ? ? ? x x ? ? ? ? ? ? ? ? ? ? ? ? ? ? ? ? ? ? ? x x ? x ? ? ? ? 0 x ? 0 ? ? x x x x x x x x x x ? ? ? ? ? ? ? ? ? ? ? ? ? ? ? ? ? ? ? ? ? ? ? x ? ? ? ? x ? ? ? ? ? x 0 ? ? x ? ? 0 ? ? ? ? x ? ? ? ? ? ? ? ? ? x x x ? ? ? ? ? ? ? ? ? ? x x 0 0 x x x 0 ? ? ? ? ? ? ? ? ? ? ? x x ? ? ? 0 0 0 x ? ? ? ? ? x x x x ? ? x ? ? ? ? ? ? ? ? ? ? ? ? ? ? ? x 0 x 0 x x ? x x x ? x 0 ? 0 ? x ? ? ? ? x x x x ? x x x x x x x x x ? ? ? ? ? ? ? ? ? ? ? ? ? ? ? ? x ? 0 ? x ? ? x x x x x x x ? ? ? 0 ? ? 0 x x ? x ? ? ? ? ? ? ? ? ? 0 ? ? x x ? ? ? ? ? x ? x x ? x 0 ? x x x ? ? ? 0 ? ? ? ? ? ? x ? x x ? x x ? ? ? ? ? ? ? ? x ? ? ? ? ? ? ? ? ? ? ? ? ? ? x x ? ? ? ? ? ? ? ? ? x x ? ? ? ? ? ? x x x x x x ? ? x x x x x ? ? ? ? ? ? ? x ? ? ? ? ? x x x x x x ? ? x x x ? x ? ? 0 ? x ? ? ? x x x x x x x x ? x ? ? 0 ? ? x x ? x x x x x x ? x 0 ? ? x x ? ? x ? ? x x x x ? x 0 ? ? x x ? x ? x ? ? x x x x ? x 0 ? 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 x 0 0 x x x x x x x 0 x 0 x x x x x x x x x x 0 x x x 0 x x x x 0 x x x x x 0 x x 0 x x x 1 x 1 0 x 0 0 x x x x x ? x x x x x x x x x x x 0 0 x x 0 x x x x x x x x x x x x 0 x x x x x x x x x x x x x x 0 x x x 0 x x x 0 x 0 0 x x x x x x x ? ? x 0 x x x x x x 0 0 x x x x x x x x x x x x 0 x x 0 x x x x 0 x x x ? ? ? x x ? ? ? 0 ? ? ? ? ? ? 0 ? ? ? ? 0 ? ? ? ? ? x ? x 0 x x ? ? x x x x 0 x ? ? ? ? x 0 0 x 0 ? ? 0 ? ? ? ? ? ? ? ? ? ? ? 0 ? ? 0 ? ? ? ? ? ? ? ? ? ? ? ? ? 0 ? 0 0 0 0 0 ? ? x 0 x 1
0 - Probable Safe Block
? - Unknown Block
x - Potentially Malicious Block

Registry Modifications

Key::Value Data API Name
HKCU\software\microsoft\windows\currentversion\internet settings\5.0\cache\content::cacheprefix RegNtPreCreateKey
HKCU\software\microsoft\windows\currentversion\internet settings\5.0\cache\cookies::cacheprefix Cookie: RegNtPreCreateKey
HKCU\software\microsoft\windows\currentversion\internet settings\5.0\cache\history::cacheprefix Visited: RegNtPreCreateKey

Windows API Usage

Category API
Anti Debug
  • NtQuerySystemInformation
Network Urlomon
  • URLDownloadToFile