Threat Database Trojans Trojan.DarktrackRAT.A

Trojan.DarktrackRAT.A

By CagedTech in Trojans

Threat Scorecard

Popularity Rank: 15,775
Threat Level: 80 % (High)
Infected Computers: 324
First Seen: May 3, 2017
Last Seen: August 7, 2026
OS(es) Affected: Windows

The detection of Trojan.DarktrackRAT.A on your system indicates a potential security threat that requires immediate attention. Trojan-type threats are known for their ability to disguise themselves as legitimate programs, making them difficult to detect without proper security software. In this report, we will provide an overview of Trojan.DarktrackRAT.A, its operating methods, symptoms of infection, and most importantly, steps to remove it from your system.

What Is Trojan.DarktrackRAT.A?

Trojan.DarktrackRAT.A is identified as a Trojan-type threat, which typically means it is designed to allow unauthorized access to a computer system. Trojans can be used to spy on users, steal sensitive information, or disrupt system operation. The name Trojan.DarktrackRAT.A itself does not directly indicate a specific malware family, but it suggests characteristics of remote access Trojans (RATs), which are notorious for their ability to give attackers control over infected systems.

How Trojan.DarktrackRAT.A Operates

Trojan-type threats like Trojan.DarktrackRAT.A often operate by disguising themselves as useful or harmless programs. Once installed on a system, they can create backdoors that allow hackers to remotely access and control the infected computer. This can lead to a variety of malicious activities, including data theft, installation of additional malware, or using the infected system as part of a botnet for distributed denial-of-service (DDoS) attacks or spamming.

Symptoms of Infection

Symptoms of a Trojan.DarktrackRAT.A infection can vary widely, depending on the specific goals of the malware and the actions taken by the attackers. Common signs include unexpected changes to system settings, unusual network activity, appearance of unwanted programs or toolbars, and general system instability. In some cases, the infection may not exhibit obvious symptoms, making regular system monitoring and security scans crucial for early detection.

How to Remove Trojan.DarktrackRAT.A

Removing Trojan.DarktrackRAT.A requires careful steps to ensure the malware is completely eradicated from your system. Follow these steps:

  1. Boot your computer in Safe Mode with Networking. This will limit the malware's ability to interfere with the removal process.
  2. Perform a full scan of your system using a reputable anti-malware tool, such as SpyHunter. Ensure the tool is updated with the latest definitions to improve detection capabilities.
  3. Uninstall any suspicious programs that were installed around the time of the suspected infection. Be cautious and only remove programs you are certain are malicious or unnecessary.
  4. Reset your web browsers (Chrome, Firefox, Edge, etc.) to their default settings. This can help remove any malicious extensions or settings changes made by the malware.
  5. Reboot your computer and perform another full scan with your anti-malware tool to ensure no remnants of the malware remain.

Conclusion

The detection and removal of Trojan.DarktrackRAT.A are critical steps in protecting your system and personal data from potential harm. By understanding how Trojan-type threats operate and following the outlined removal steps, you can significantly reduce the risk of infection and mitigate damage if your system is already compromised. Regularly updating your security software, being cautious with email attachments and downloads, and maintaining good computing practices are essential in preventing future infections.

Analysis Report

General information

Family Name: Trojan.DarktrackRAT.A
Signature status: No Signature

Known Samples

MD5: 2055e29b56e4573a5d3c04c60d97bcf9
SHA1: e0e4345f261fcaa459541f5f2845a0cf01ddeac3
SHA256: 938421D2AF3E057BCA1C90649F9F5CD69E64ED1B601CD5EAD0747A225FB1C06A
File Size: 762.37 KB, 762368 bytes
MD5: 7f70f0c66becb05ef5f0c10e1aac16e3
SHA1: 4cc98f1f12ef40d80ecdb014347452f47b6c5f19
SHA256: 17B95C52E99714F415A271668F29513716F829C6DD94FB19C8A61924178FA335
File Size: 914.43 KB, 914432 bytes

Windows Portable Executable Attributes

  • File doesn't have "Rich" header
  • File doesn't have debug information
  • File doesn't have exports table
  • File doesn't have relocations information
  • File doesn't have security information
  • File has TLS information
  • File is 32-bit executable
  • File is either console or GUI application
  • File is GUI application (IMAGE_SUBSYSTEM_WINDOWS_GUI)
  • File is Native application (NOT .NET application)
Show More
  • File is not packed
  • IMAGE_FILE_DLL is not set inside PE header (Executable)
  • IMAGE_FILE_EXECUTABLE_IMAGE is set inside PE header (Executable Image)

File Icons

File Traits

  • 2+ executable sections
  • CryptUnprotectData
  • No CryptProtectData
  • No Version Info
  • ntdll
  • WriteProcessMemory
  • x86

Block Information

Total Blocks: 3,340
Potentially Malicious Blocks: 1,071
Whitelisted Blocks: 2,269
Unknown Blocks: 0

Visual Map

0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 1 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 x 0 0 x x 0 0 0 0 x 0 0 0 0 0 0 0 0 x 0 0 0 0 0 x x 0 x x 0 x x x 0 0 x 0 0 x x 0 x x 0 x x x x x x x x x x x 0 x x 0 x x 0 x x x x x 0 x 0 x x x x 0 x x 0 x x x x 0 x x 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 1 0 1 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 1 1 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 x 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 x x 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 x x x x x x x x x x x x x x x x x x x x x x x x x 0 0 0 0 x 0 0 0 0 0 0 0 0 0 0 x 0 0 0 0 0 0 0 0 0 0 0 0 x x x 0 0 0 0 0 0 0 0 0 0 0 x 0 x 0 x x 0 0 0 0 x x x x 0 x x x x 0 x x x x x x x 0 x 0 x 0 x x 0 0 x 0 0 x 0 x 0 x x x x x 0 0 0 0 0 0 x 0 0 x x x x x x x 0 x x 0 x x 0 x x 0 x x 0 x x 0 x x 0 x x 0 0 0 x 0 0 x x x x x x x 0 x 0 x x 0 0 x x x 0 x 0 0 x 0 0 0 x 0 0 x x 0 0 x x x 0 0 x x x x 0 x x x 0 0 x 0 0 0 x x x 0 0 0 0 x 0 0 0 0 0 0 0 0 x 0 0 0 x 0 0 0 x x 0 0 x x 0 x x x x 0 0 x 0 0 x 0 x 0 0 x x x 0 x x 0 0 x x x x x x x x x x x x x x x x x x 0 0 0 0 0 0 0 0 0 0 0 x x 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 x 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 x x 0 x 0 x x x x x x x x x x x x x 0 x x x 0 0 x x x 0 x x x 0 0 x 0 0 0 0 0 0 0 0 0 0 0 0 0 0 x x x 0 0 0 0 x 0 0 0 0 0 0 0 0 x
... Data truncated
0 - Probable Safe Block
? - Unknown Block
x - Potentially Malicious Block

Similar Families

  • Banker.GF
  • ConvertAd.RA
  • Injector.KPP
  • Lamer.B
  • Malat.A
Show More
  • Swisyn.B
  • Xtreme.A

Files Modified

File Attributes
\device\namedpipe\gmdasllogger Generic Write,Read Attributes
c:\users\user\appdata\local\microsoft\windows\usrclass.dat{dba6b5ef-640a-11ed-9bcb-f677369d361c}.txr.1.regtrans-ms Generic Read,Write Data,Write Attributes,Write extended,Append data
c:\users\user\appdata\local\microsoft\windows\usrclass.dat{dba6b5ef-640a-11ed-9bcb-f677369d361c}.txr.2.regtrans-ms Generic Read,Write Data,Write Attributes,Write extended,Append data
c:\windows\spynet\server.exe Generic Read,Write Data,Write Attributes,Write extended,Append data,Delete,LEFT 262144
c:\windows\spynet\server.exe Synchronize,Write Attributes

Registry Modifications

Key::Value Data API Name
HKLM\software\wow6432node\microsoft\windows\currentversion\run::server C:\WINDOWS\SpyNet\Server.exe RegNtPreCreateKey
HKCU\software\microsoft\windows\currentversion\run::server C:\WINDOWS\SpyNet\Server.exe RegNtPreCreateKey
HKLM\software\wow6432node\microsoft\active setup\installed components\{2j58xp0k-erqo-j3f4-1e5x-jb44dfp82s24}::stubpath C:\WINDOWS\SpyNet\Server.exe restart RegNtPreCreateKey
HKLM\software\wow6432node\microsoft\windows\currentversion\runonce::server C:\WINDOWS\SpyNet\Server.exe RegNtPreCreateKey
HKLM\software\wow6432node\microsoft\windows nt\currentversion\winlogon::shell explorer.exe "C:\WINDOWS\SpyNet\Server.exe" RegNtPreCreateKey
HKCU\software\microsoft\windows nt\currentversion\winlogon::shell explorer.exe "C:\WINDOWS\SpyNet\Server.exe" RegNtPreCreateKey
HKLM\software\microsoft\windows\currentversion\policies\explorer\run::server C:\WINDOWS\SpyNet\Server.exe RegNtPreCreateKey
HKCU\software\microsoft\windows\currentversion\policies\explorer\run::server C:\WINDOWS\SpyNet\Server.exe RegNtPreCreateKey
HKCU\software\microsoft\windows\currentversion\internet settings\zonemap::proxybypass  RegNtPreCreateKey
HKCU\software\microsoft\windows\currentversion\internet settings\zonemap::intranetname  RegNtPreCreateKey
Show More
HKCU\software\microsoft\windows\currentversion\internet settings\zonemap::uncasintranet  RegNtPreCreateKey
HKCU\software\microsoft\windows\currentversion\internet settings\zonemap::autodetect RegNtPreCreateKey
HKLM\software\microsoft\windows nt\currentversion\notifications\data::418a073aa3bc1c75 �n3 �v������Bx#�(�+�[1`1�1HO1�D9ߔ@V�A��H[uR20_�z`�2b"he�vk`k�qo�w�n{b�{�=�Jq�P��jI������������Ǐ�T����T���*�Dt�T��m�Ù�����=��$�8წ����&M�=�S �Y.SLB1_T�Vw RegNtPreCreateKey
HKLM\software\microsoft\windows nt\currentversion\notifications\data::418a073aa3bc1c75 �n5 �v������Bx#�%�(�+�[1`1�1HO1�D9ߔ@V�A��H[uR20_�z`�2a$b"he�vk`k�qo�w�n{b�{�=�Jq�P��jI������������Ǐ�T����T���*�Dt�T��m�Ù�����=��$�8წ����&M�=�S �Y.SLB1 RegNtPreCreateKey
HKLM\software\microsoft\windows nt\currentversion\notifications\data::418a073aa3bc3475 鴶ȁ獖} RegNtPreCreateKey
HKLM\software\microsoft\windows nt\currentversion\notifications\data::418a073aa3bc1c75 �n8 �v������Bx#�%�(�+�[,=�1`1�1HO1�D9ߔ@V�A��H[uN�R20_�z`�2a$b"he�vk`k�qo�w�ny�9{b�{�=�Jq�P��jI������������Ǐ�T����T���*�Dt�T��m�Ù�����=��$�8წ����&M�=� RegNtPreCreateKey
HKLM\software\microsoft\windows nt\currentversion\notifications\data::418a073aa3bc1c75 �n= �v������Bx#�%�(�+�[,=�1`1�1HO1�D9ߔ@V�A��H[uN�R20_�z`�2a$b"he�vk`k�qo�w�ny�9{b�{�=�Jq�P��jI�����7�M���������Ǐ�T����T���*�Dt�T��m�Ù��IV����=��$�8წ����&M RegNtPreCreateKey
HKLM\software\microsoft\windows nt\currentversion\notifications\data::418a073aa3bc1c75 �n> �v ��������Bx#�%�(�+�[,=�1`1�1HO1�D9ߔ@V�A��H[uN�R20_�z`�2a$b"he�vk`k�qo�w�ny�9{b�{�=�Jq�P��jI�����7�M���������Ǐ�T����T���*�Dt�T��m�Ù��IV����=��$�8წ��� RegNtPreCreateKey
HKLM\software\microsoft\windows nt\currentversion\notifications\data::418a073aa3bc1c75 �n? �v ��������Bx#�%�(�+�[,=�1`1�1HO1�D9ߔ@V�A��H[uN�R20_�z`�2a$b"he�vk`k�ql(�o�w�ny�9{b�{�=�Jq�P��jI�����7�M���������Ǐ�T����T���*�Dt�T��m�Ù��IV����=��$�8წ�� RegNtPreCreateKey
HKCU\software\microsoft\--((spynet))--::installedserver C:\WINDOWS\SpyNet\Server.exe RegNtPreCreateKey

Windows API Usage

Category API
Network Winsock2
  • WSAStartup
Process Manipulation Evasion
  • NtUnmapViewOfSection
  • ReadProcessMemory
  • VirtualAllocEx
Anti Debug
  • NtQuerySystemInformation
Process Shell Execute
  • CreateProcess
  • ShellExecute
Process Terminate
  • TerminateProcess

Shell Command Execution

C:\WINDOWS\SpyNet\Server.exe "C:\WINDOWS\SpyNet\Server.exe"
open C:\WINDOWS\SpyNet\Server.exe
svchost.exe