Threat Database Trojans Trojan.Delf.XA

Trojan.Delf.XA

By CagedTech in Trojans

Threat Scorecard

Popularity Rank: 8,468
Threat Level: 80 % (High)
Infected Computers: 168
First Seen: July 20, 2024
Last Seen: January 16, 2026
OS(es) Affected: Windows

Analysis Report

General information

Family Name: Trojan.Delf.XA
Packers: UPX!
Signature status: No Signature

Known Samples

MD5: 69f0386bc575a1d2f13243fa9e431126
SHA1: d985279da2e0f0cb1d55ca18bb8deaa217144c4c
SHA256: AC1E878D356601594B11B2EC20C6AE0899E990F3287CD7D3DD4C1F6F9368ED84
File Size: 932.00 KB, 931997 bytes
MD5: c294c5eddcb8de2e3775da8af5ce39af
SHA1: 10315f86a94e76f67022dd9788e948df4d07a5ac
SHA256: 4A6354B57BBD647750736A1EBF828E3A72ABBC9E4206F46D3B201AF207F2B285
File Size: 659.46 KB, 659456 bytes

Windows Portable Executable Attributes

  • File doesn't have "Rich" header
  • File doesn't have debug information
  • File doesn't have exports table
  • File doesn't have relocations information
  • File doesn't have security information
  • File has been packed
  • File has TLS information
  • File is 32-bit executable
  • File is either console or GUI application
  • File is GUI application (IMAGE_SUBSYSTEM_WINDOWS_GUI)
Show More
  • File is Native application (NOT .NET application)
  • IMAGE_FILE_DLL is not set inside PE header (Executable)
  • IMAGE_FILE_EXECUTABLE_IMAGE is set inside PE header (Executable Image)

File Icons

Windows PE Version Information

Name Value
Company Name NeoSoft Corp.
File Description NeoBook 5 Runtime Player
File Version
  • 5.6.2.0
  • 1.0.0.0
Internal Name
  • Bingo
  • NBPlay5
Legal Copyright ©1993-2008 NeoSoft Corp.
Original Filename
  • Bingo
  • NBPlay5
Product Name NBPlay5
Product Version
  • 5.6.2.0
  • 1.0.0.0

File Traits

  • big overlay
  • packed
  • x86
  • zlib (In Overlay)
  • zlib overlay

Block Information

Total Blocks: 6,945
Potentially Malicious Blocks: 1,685
Whitelisted Blocks: 5,260
Unknown Blocks: 0

Visual Map

0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 1 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 1 1 1 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 1 0 1 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 x x x x x x x x 0 x x x x x x x x x 0 x 0 x x 0 0 x 0 0 0 0 0 0 0 0 0 0 x 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0
... Data truncated
0 - Probable Safe Block
? - Unknown Block
x - Potentially Malicious Block

Similar Families

  • Delf.XA

Registry Modifications

Key::Value Data API Name
HKCU\software\microsoft\multimedia\drawdib:: 1920x1200x32(bgr 0) 31,31,31,31 RegNtPreCreateKey
HKLM\software\classes\typelib\{8c2b40d2-963f-4307-ad3e-44a17d530d67}\1.0:: NBRun Library RegNtPreCreateKey
HKLM\software\classes\typelib\{8c2b40d2-963f-4307-ad3e-44a17d530d67}\1.0\flags:: 0 RegNtPreCreateKey
HKLM\software\classes\typelib\{8c2b40d2-963f-4307-ad3e-44a17d530d67}\1.0\0\win32:: c:\Users\user\downloads\d985279da2e0f0cb1d55ca18bb8deaa217144c4c_0000931997 RegNtPreCreateKey
HKLM\software\classes\typelib\{8c2b40d2-963f-4307-ad3e-44a17d530d67}\1.0\helpdir:: c:\Users\user\downloads\ RegNtPreCreateKey
HKLM\software\classes\wow6432node\interface\{ddb878b2-3f43-4471-b746-47906e644468}:: IBrowserToDelphi RegNtPreCreateKey
HKLM\software\classes\wow6432node\interface\{ddb878b2-3f43-4471-b746-47906e644468}\proxystubclsid32:: {00020424-0000-0000-C000-000000000046} RegNtPreCreateKey
HKLM\software\classes\wow6432node\interface\{ddb878b2-3f43-4471-b746-47906e644468}\typelib:: {8C2B40D2-963F-4307-AD3E-44A17D530D67} RegNtPreCreateKey
HKLM\software\classes\wow6432node\interface\{ddb878b2-3f43-4471-b746-47906e644468}\typelib::version 1.0 RegNtPreCreateKey
HKLM\software\classes\interface\{ddb878b2-3f43-4471-b746-47906e644468}:: IBrowserToDelphi RegNtPreCreateKey
Show More
HKLM\software\classes\interface\{ddb878b2-3f43-4471-b746-47906e644468}\proxystubclsid32:: {00020424-0000-0000-C000-000000000046} RegNtPreCreateKey
HKLM\software\classes\interface\{ddb878b2-3f43-4471-b746-47906e644468}\typelib:: {8C2B40D2-963F-4307-AD3E-44A17D530D67} RegNtPreCreateKey
HKLM\software\classes\interface\{ddb878b2-3f43-4471-b746-47906e644468}\typelib::version 1.0 RegNtPreCreateKey
HKLM\software\classes\wow6432node\interface\{1551601c-141c-4499-9c05-557ca1440a05}:: IBrowserToDelphiEvents RegNtPreCreateKey
HKLM\software\classes\wow6432node\interface\{1551601c-141c-4499-9c05-557ca1440a05}\proxystubclsid32:: {00020420-0000-0000-C000-000000000046} RegNtPreCreateKey
HKLM\software\classes\wow6432node\interface\{1551601c-141c-4499-9c05-557ca1440a05}\typelib:: {8C2B40D2-963F-4307-AD3E-44A17D530D67} RegNtPreCreateKey
HKLM\software\classes\wow6432node\interface\{1551601c-141c-4499-9c05-557ca1440a05}\typelib::version 1.0 RegNtPreCreateKey
HKLM\software\classes\interface\{1551601c-141c-4499-9c05-557ca1440a05}:: IBrowserToDelphiEvents RegNtPreCreateKey
HKLM\software\classes\interface\{1551601c-141c-4499-9c05-557ca1440a05}\proxystubclsid32:: {00020420-0000-0000-C000-000000000046} RegNtPreCreateKey
HKLM\software\classes\interface\{1551601c-141c-4499-9c05-557ca1440a05}\typelib:: {8C2B40D2-963F-4307-AD3E-44A17D530D67} RegNtPreCreateKey
HKLM\software\classes\interface\{1551601c-141c-4499-9c05-557ca1440a05}\typelib::version 1.0 RegNtPreCreateKey
HKLM\software\classes\wow6432node\clsid\{f1f35efe-c7d9-4628-a63c-dd41f5de5914}:: RegNtPreCreateKey
HKLM\software\classes\wow6432node\clsid\{f1f35efe-c7d9-4628-a63c-dd41f5de5914}\localserver32:: c:\Users\user\downloads\d985279da2e0f0cb1d55ca18bb8deaa217144c4c_0000931997 RegNtPreCreateKey
HKLM\software\classes\nbrun.neobookieprotocol:: RegNtPreCreateKey
HKLM\software\classes\nbrun.neobookieprotocol\clsid:: {F1F35EFE-C7D9-4628-A63C-DD41F5DE5914} RegNtPreCreateKey
HKLM\software\classes\wow6432node\clsid\{f1f35efe-c7d9-4628-a63c-dd41f5de5914}\progid:: NBRun.NeoBookIEProtocol RegNtPreCreateKey
HKLM\software\classes\wow6432node\clsid\{ed4f5a35-81e4-4cbf-a823-aaa3c0847c6e}:: BrowserToDelphi Object RegNtPreCreateKey
HKLM\software\classes\wow6432node\clsid\{ed4f5a35-81e4-4cbf-a823-aaa3c0847c6e}\localserver32:: c:\Users\user\downloads\d985279da2e0f0cb1d55ca18bb8deaa217144c4c_0000931997 RegNtPreCreateKey
HKLM\software\classes\nbrun.browsertodelphi:: BrowserToDelphi Object RegNtPreCreateKey
HKLM\software\classes\nbrun.browsertodelphi\clsid:: {ED4F5A35-81E4-4CBF-A823-AAA3C0847C6E} RegNtPreCreateKey
HKLM\software\classes\wow6432node\clsid\{ed4f5a35-81e4-4cbf-a823-aaa3c0847c6e}\progid:: NBRun.BrowserToDelphi RegNtPreCreateKey
HKLM\software\classes\wow6432node\clsid\{ed4f5a35-81e4-4cbf-a823-aaa3c0847c6e}\version:: 1.0 RegNtPreCreateKey
HKLM\software\classes\wow6432node\clsid\{ed4f5a35-81e4-4cbf-a823-aaa3c0847c6e}\typelib:: {8C2B40D2-963F-4307-AD3E-44A17D530D67} RegNtPreCreateKey
HKLM\software\classes\typelib\{8c2b40d2-963f-4307-ad3e-44a17d530d67}\1.0\0\win32:: c:\Users\user\downloads\10315f86a94e76f67022dd9788e948df4d07a5ac_0000659456 RegNtPreCreateKey
HKLM\software\classes\wow6432node\clsid\{f1f35efe-c7d9-4628-a63c-dd41f5de5914}\localserver32:: c:\Users\user\downloads\10315f86a94e76f67022dd9788e948df4d07a5ac_0000659456 RegNtPreCreateKey
HKLM\software\classes\wow6432node\clsid\{ed4f5a35-81e4-4cbf-a823-aaa3c0847c6e}\localserver32:: c:\Users\user\downloads\10315f86a94e76f67022dd9788e948df4d07a5ac_0000659456 RegNtPreCreateKey

Windows API Usage

Category API
Anti Debug
  • IsDebuggerPresent
User Data Access
  • GetUserObjectInformation

Trending

Most Viewed

Loading...