Threat Database Trojans Trojan.Dorkbot.D

Trojan.Dorkbot.D

By CagedTech in Trojans

Threat Scorecard

Popularity Rank: 18,100
Threat Level: 80 % (High)
Infected Computers: 40
First Seen: December 21, 2018
Last Seen: August 7, 2026
OS(es) Affected: Windows

Analysis Report

General information

Family Name: Trojan.Dorkbot.D
Signature status: No Signature

Known Samples

MD5: 92bf894713f33da8aaf4f03bc5f2616a
SHA1: 131e96c4c456d0c1a9ac68e0814c9cf52c686b95
SHA256: F3147EEFDAD65BCA7181262A6EF0765906B4BB19067FC1A88B6EC5C1B3C4EE6F
File Size: 160.77 KB, 160768 bytes

Windows Portable Executable Attributes

  • File doesn't have "Rich" header
  • File doesn't have debug information
  • File doesn't have exports table
  • File doesn't have security information
  • File is 32-bit executable
  • File is either console or GUI application
  • File is GUI application (IMAGE_SUBSYSTEM_WINDOWS_GUI)
  • File is Native application (NOT .NET application)
  • File is not packed
  • IMAGE_FILE_DLL is not set inside PE header (Executable)
Show More
  • IMAGE_FILE_EXECUTABLE_IMAGE is set inside PE header (Executable Image)

File Traits

  • No Version Info
  • WriteProcessMemory
  • x86

Block Information

Total Blocks: 436
Potentially Malicious Blocks: 368
Whitelisted Blocks: 65
Unknown Blocks: 3

Visual Map

x x x x x x x 0 1 x 0 x x x x x x x x x 0 x x x x x x x x x x 0 x x x x x x x x x x x x x 0 0 x x x 0 0 x x x x x x x x x x x x x x x x x x x x x x x x x x x 0 x x x x x 0 x x x x x x x x x 0 x x x x x x x x x x x x x x x x 0 x x x x x x x x x x 0 x x x 0 0 0 x x x x x x x x x x x x x x x x x ? 0 x 0 x 0 x 0 x x x x 0 x x x x x ? ? x x x 0 0 0 x x x x x x x x x x x x x x x x x 0 0 0 0 x x x x x 0 0 x x 0 0 0 x 1 0 x x x x x x x x x x 0 x x x x x x x x x x x x x x x x x x x x x x x x x x x x x x x x x x x x x x x 0 x x x x x x 0 x 0 0 0 0 x x 0 x x x x x x x x x x x x x x x x x x x x x 0 x x x x x x x 0 x x x x x x x x x x x x x x x x x x x x x x x x x x x x x x x x x x x 0 x 0 x x x x x x x x x x x x 0 x x x x x x x x x x x x 0 0 x x x x 0 0 0 x x x 0 x x 0 x x 0 x 0 0 x 0 0 x x x x x x x x x x x x x x x x x x x x 0 x x x x x x x x x x x x x x x x x 0 x 0 x 0
0 - Probable Safe Block
? - Unknown Block
x - Potentially Malicious Block

Similar Families

  • Dorkbot.D
  • Dorkbot.GN

Files Modified

File Attributes
c:\users\user\appdata\roaming\c731200 Generic Read,Write Data,Write Attributes,Write extended,Append data,Delete,LEFT 262144
c:\users\user\appdata\roaming\c731200 Synchronize,Write Attributes

Registry Modifications

Key::Value Data API Name
HKLM\software\microsoft\windows nt\currentversion\notifications\data::418a073aa3bc1c75 �n) �v������#�(�+�[,��1`1�1HO1�D9ߔ@V�A��H[uR20`�2b"hk`k�ql(�o�{�=�Jq�P��������Ǐ�T��T��Dt�T��m�Ù��=��$�8����&M �Y/�B1_�R������@K� RegNtPreCreateKey

Windows API Usage

Category API
Process Manipulation Evasion
  • NtUnmapViewOfSection
  • VirtualAllocEx
Process Shell Execute
  • CreateProcess
Thread Create Remote
  • CreateRemoteThread

Shell Command Execution

C:\WINDOWS\SysWOW64\svchost.exe (NULL)
C:\WINDOWS\SysWOW64\calc.exe (NULL)
c:\users\user\downloads\131e96c4c456d0c1a9ac68e0814c9cf52c686b95_0000160768 "c:\users\user\downloads\131e96c4c456d0c1a9ac68e0814c9cf52c686b95_0000160768"