Threat Database Trojans Trojan.Delf.L

Trojan.Delf.L

By CagedTech in Trojans

Threat Scorecard

Popularity Rank: 11,975
Threat Level: 80 % (High)
Infected Computers: 48
First Seen: June 21, 2019
Last Seen: December 27, 2025
OS(es) Affected: Windows

Analysis Report

General information

Family Name: Trojan.Delf.L
Packers: UPX
Signature status: No Signature

Known Samples

MD5: 65c27c29fb6774e33cc920207e9f96d8
SHA1: 89f9c814b613dd3a457b25bb88f2171d453c6c01
SHA256: CD4C9143FD4CF5A375F3428E42BB220A21FFDA86AA5DD2DCF1C120DEE577F080
File Size: 50.69 KB, 50688 bytes
MD5: bcbbc740f5960b21474d5f2b91dd39a8
SHA1: 43d881c9b61a04c77cba953c07f80f843fca62b0
SHA256: D1B915ECA339BA3660C40F79A00C1C8276A448FC5376A352A59C443F44B855A4
File Size: 92.67 KB, 92672 bytes

Windows Portable Executable Attributes

  • File doesn't have "Rich" header
  • File doesn't have debug information
  • File doesn't have exports table
  • File doesn't have relocations information
  • File doesn't have security information
  • File has been packed
  • File has TLS information
  • File is 32-bit executable
  • File is either console or GUI application
  • File is GUI application (IMAGE_SUBSYSTEM_WINDOWS_GUI)
Show More
  • File is Native application (NOT .NET application)
  • IMAGE_FILE_DLL is not set inside PE header (Executable)
  • IMAGE_FILE_EXECUTABLE_IMAGE is set inside PE header (Executable Image)

File Icons

File Traits

  • dll
  • No Version Info
  • packed
  • x86

Block Information

Total Blocks: 289
Potentially Malicious Blocks: 58
Whitelisted Blocks: 230
Unknown Blocks: 1

Visual Map

0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 1 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 x x x 0 0 0 0 0 0 x x x 0 x x x x x x x x x x x x 0 x x 0 0 0 0 0 0 x 0 0 x x x x x 0 0 0 0 x 0 0 0 0 x x 0 x 0 0 0 0 x x 0 0 0 0 x x 0 0 x x x 0 x 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 x x x x x x x 0 x x x x x x x 0 0 0 0 0 x x x x 0 0 0 0 0 x x 0 ? 0 0 0
0 - Probable Safe Block
? - Unknown Block
x - Potentially Malicious Block

Registry Modifications

Key::Value Data API Name
HKCU\software\cerberus::filenameatual c:\users\user\downloads\43d881c9b61a04c77cba953c07f80f843fca62b0_0000092672 RegNtPreCreateKey

Windows API Usage

Category API
Anti Debug
  • IsDebuggerPresent
User Data Access
  • GetUserObjectInformation
Other Suspicious
  • AdjustTokenPrivileges
Process Manipulation Evasion
  • NtUnmapViewOfSection
  • VirtualAllocEx
Process Shell Execute
  • CreateProcess
Thread Create Remote
  • CreateRemoteThread

Shell Command Execution

C:\Program Files (x86)\Internet Explorer\iexplore.exe

Related Posts

Trending

Most Viewed

Loading...