Threat Database Trojans Trojan.Crackonosh

Trojan.Crackonosh

By CagedTech in Trojans

Threat Scorecard

Ranking: 1,317
Threat Level: 80 % (High)
Infected Computers: 126,886
First Seen: June 28, 2021
Last Seen: April 25, 2024
OS(es) Affected: Windows

File System Details

Trojan.Crackonosh may create the following file(s):
# File Name MD5 Detections
1. winscomrssrv.dll 919611928882e781abab300bf9227374 15,604
2. startupcheck.vbs a0ee12852d89c9958aa08e389019bfe4 2,291
3. maintenance.vbs 66a8544fd47ab338b7a9be449591e7b6 1,624
4. ServiceInstaller.msi a45f17b66542514aaeae074ac1336483 1,184
5. ServiceInstaller.msi 156dab1b32859a3b90bdbfa51e7559e2 713
6. startupcheck.vbs b6a58f7b79567b6aa575a807840f5cbd 482
7. ServiceInstaller.msi d76be92fb67398cb9c2f70a0953bebe7 430
8. maintenance.vbs 4cb3b51e35ad2e8039152008f966061e 297
9. startupcheck.vbs 1699430ce512d58d3209601c6babb9c9 87
10. startupcheck.vbs cb5521fe37b51b04b55cdb060291884b 50
11. winrmsrv.exe e5ec4f6b803a7025e0278da1b54feae0 47
12. startupchecklibrary.dll 0769a11aab49c76e0bb2e2cc61c98a77 44
13. maintenance.vbs 6eaf94c3692bcbe14359be78ad2c9d00 15
14. wksprtcli.dll c7308958986fe345e3576f49fc4fc153 12
15. ServiceInstaller.msi 748c3dac3e38dcc0cb48caff5f5ce5bb 8
16. serviceinstaller.exe 3ca7ef8ca046aa506077c97aa70ba230 7
17. maintenance.vbs 73867398eaa405c3ecce96172d323faa 6
18. startupchecklibrary.dll b35516312d3645dd1309a815625a129a 5
19. wksprtcli.dll 77a49194e41cbf0f1b706533fe460231 4
20. startupchecklibrary.dll f2945b486b1a8c44c33fca84f89cc8eb 2
21. winscomrssrv.dll c22e39b86fbde7751e55f01986854594 2
22. maintenance.vbs fa185d1df9505a982f6db5fe551fbdd1 2
23. startupchecklibrary.dll 38421cd27b886d8627c28fd64faa7b68 2
24. startupcheck.vbs d96689ccb6ee800cc3cf4140b4b3079a 2
25. maintenance.vbs 7c60d2c16201eed1073f5466f8ec2456 2
26. ServiceInstaller.msi 79538329ec6c83d3539c71210e5648c4 2
27. ServiceInstaller.exe e0b559ff1b7b4873d9e229b91039884e 2
28. winscomrssrv.dll 6ee92d315a2d53d4b878ec913443dd6f 1
More files

Registry Details

Trojan.Crackonosh may create the following registry entry or registry entries:
File name without path
7B296FC0-376B-497d-B013-58F4D9633A22-5P-1.B5841A4C-A289-439d-8115-50AB69CD450
7B296FC0-376B-497d-B013-58F4D9633A22-5P-1.B5841A4C-A289-439d-8115-50AB69CD450B
UserAccountControlSettingsDevice.dat
Regexp file mask
%windir%\system32\maintenance.vbs
%windir%\system32\startupcheck.vbs
%windir%\system32\tasks\microsoft\windows\application experience\startupchecklibrary
%windir%\system32\tasks\microsoft\windows\maintenance\installwinsat
%windir%\system32\tasks\microsoft\windows\wdi\srvhost
%windir%\system32\tasks\microsoft\windows\windows error reporting\winrmsrv
%windir%\system32\tasks\microsoft\windows\wininet\winlogui
%windir%\system32\tasks\srvhost
%windir%\system32\tasks\sysinfo
%windir%\system32\tasks\winlogui
%windir%\system32\tasks\winrmsrv

Trending

Most Viewed

Loading...