Threat Database Trojans Trojan.Buzus.AD

Trojan.Buzus.AD

By CagedTech in Trojans

Threat Scorecard

Popularity Rank: 22,570
Threat Level: 80 % (High)
Infected Computers: 21
First Seen: September 1, 2021
Last Seen: June 13, 2026
OS(es) Affected: Windows

Analysis Report

General information

Family Name: Trojan.Buzus.AD
Signature status: Hash Mismatch

Known Samples

MD5: 69db7753b1e3d9ced49e86f9907adf02
SHA1: dbecfd5b1f474429f3b9ac38faaedcec113fec28
SHA256: 439DB9D71CCACF658270449B9133E353AC6835657D2CC596D81AAD6FF3C0680D
File Size: 59.65 KB, 59652 bytes

Windows Portable Executable Attributes

  • File doesn't have "Rich" header
  • File doesn't have exports table
  • File is 32-bit executable
  • File is either console or GUI application
  • File is GUI application (IMAGE_SUBSYSTEM_WINDOWS_GUI)
  • File is Native application (NOT .NET application)
  • File is not packed
  • IMAGE_FILE_DLL is not set inside PE header (Executable)
  • IMAGE_FILE_EXECUTABLE_IMAGE is set inside PE header (Executable Image)

Windows PE Version Information

Name Value
Comments http://www.internetdownloadmanager.com/
Company Name Internet Download Manager, Tonec Inc.
File Description IDM module
File Version 6, 42, 2, 1
Internal Name MediumIL
Legal Copyright Tonec Inc., Copyright © 1999 - 2023. All right reserved.
Original Filename MediumIL
Product Name Internet Download Manager Module
Product Version 6, 42, 2, 1

Digital Signatures

Signer Root Status
Tonec Inc. DigiCert Trusted G4 Code Signing RSA4096 SHA384 2021 CA1 Hash Mismatch

File Traits

  • 2+ executable sections
  • HighEntropy
  • x86

Block Information

Total Blocks: 210
Potentially Malicious Blocks: 53
Whitelisted Blocks: 157
Unknown Blocks: 0

Visual Map

0 2 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 2 3 0 0 1 0 1 0 0 1 0 0 0 1 0 0 1 0 0 0 2 2 0 0 1 0 0 0 1 1 1 0 1 1 0 0 0 0 1 0 0 0 0 0 0 0 0 0 0 0 1 1 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 1 1 0 0 1 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 1 0 0 0 0 0 0 0 0 0 0 0 0 1 1 1 0 0 0 0 1 0 0 0 0 2 0 0 1 x x x x x x x x x 0 x x x 0 x x 0 x x x 0 x x x x x x x x x x x 0 x x x x 0 x x x x x x x x x x x x x x 0 x x x x x x x
0 - Probable Safe Block
? - Unknown Block
x - Potentially Malicious Block

Related Posts

Trending

Most Viewed

Loading...