Threat Database Trojans Trojan.Downloader.Gen.BY

Trojan.Downloader.Gen.BY

By CagedTech in Trojans

Analysis Report

General information

Family Name: Trojan.Downloader.Gen.BY
Signature status: No Signature

Known Samples

MD5: b6299145009e19412777b20cbbf99771
SHA1: 2c3517d490792a52b1e283457a1d31c417ba5e37
SHA256: 6DA36358A6D614BD0C98973EE18B7963054C7EF085414E7E45F110FA9308EF74
File Size: 3.72 MB, 3722050 bytes

Windows Portable Executable Attributes

  • File doesn't have "Rich" header
  • File doesn't have debug information
  • File doesn't have exports table
  • File doesn't have relocations information
  • File doesn't have security information
  • File has TLS information
  • File is 32-bit executable
  • File is either console or GUI application
  • File is GUI application (IMAGE_SUBSYSTEM_WINDOWS_GUI)
  • File is Native application (NOT .NET application)
Show More
  • File is not packed
  • IMAGE_FILE_DLL is not set inside PE header (Executable)
  • IMAGE_FILE_EXECUTABLE_IMAGE is set inside PE header (Executable Image)

File Icons

Windows PE Version Information

Name Value
Comments This installation was built with Inno Setup.
File Description Sputum Setup
File Version 8.3.0.0
Product Name Sputum
Product Version 7.6

File Traits

  • dll
  • x64

Files Modified

File Attributes
c:\users\user\appdata\local\temp\is-7pgmd.tmp\_isetup\_setup64.tmp Generic Read,Write Data,Write Attributes,Write extended,Append data
c:\users\user\appdata\local\temp\is-7pgmd.tmp\adapter_ext.rc Generic Write,Read Attributes
c:\users\user\appdata\local\temp\is-7pgmd.tmp\facomp10.dll Generic Write,Read Attributes
c:\users\user\appdata\local\temp\is-7pgmd.tmp\frameworkbase.dll Generic Write,Read Attributes
c:\users\user\appdata\local\temp\is-7pgmd.tmp\hashrate_architect.exe Generic Write,Read Attributes
c:\users\user\appdata\local\temp\is-7pgmd.tmp\msvcp140.dll Generic Write,Read Attributes
c:\users\user\appdata\local\temp\is-7pgmd.tmp\nativecontrols8.dll Generic Write,Read Attributes
c:\users\user\appdata\local\temp\is-7pgmd.tmp\runtimectx77.sys Generic Write,Read Attributes
c:\users\user\appdata\local\temp\is-7pgmd.tmp\vcruntime140.dll Generic Write,Read Attributes
c:\users\user\appdata\local\temp\is-7pgmd.tmp\vcruntime140_1.dll Generic Write,Read Attributes
Show More
c:\users\user\appdata\local\temp\is-amokk.tmp\2c3517d490792a52b1e283457a1d31c417ba5e37_0003722050.tmp Generic Write,Read Attributes

Registry Modifications

Key::Value Data API Name
HKLM\software\classes\.sng:: Song File RegNtPreCreateKey
HKLM\software\classes\.sng::content type nTrack/song RegNtPreCreateKey
HKLM\software\classes\song file:: n-Track Studio Song File RegNtPreCreateKey
HKLM\software\classes\song file\defaulticon:: C:\Users\Yiqmqzof\AppData\Local\Temp\is-7PGMD.tmp\ntrack.exe,2 RegNtPreCreateKey
HKLM\software\classes\song file\shell:: open,shell,command RegNtPreCreateKey
HKLM\software\classes\song file\shell\command:: Command RegNtPreCreateKey
HKLM\software\classes\song file\shell\command\command:: "C:\Users\Yiqmqzof\AppData\Local\Temp\is-7PGMD.tmp\ntrack.exe" "%1" RegNtPreCreateKey
HKLM\software\classes\song file\shell\open:: &Open RegNtPreCreateKey
HKLM\software\classes\song file\shell\open\command:: "C:\Users\Yiqmqzof\AppData\Local\Temp\is-7PGMD.tmp\ntrack.exe" "%1" RegNtPreCreateKey
HKLM\software\classes\song file\shell\shell:: Shell RegNtPreCreateKey
Show More
HKLM\software\classes\song file\shell\shell\command:: "C:\Users\Yiqmqzof\AppData\Local\Temp\is-7PGMD.tmp\ntrack.exe" "%1" RegNtPreCreateKey
HKLM\software\classes\.sgw:: Song File RegNtPreCreateKey
HKLM\software\classes\.sgw::content type nTrack/song RegNtPreCreateKey
HKLM\software\classes\song file:: n-Track Studio Song File RegNtPreCreateKey
HKLM\software\classes\song file\defaulticon:: C:\Users\Yiqmqzof\AppData\Local\Temp\is-7PGMD.tmp\ntrack.exe,2 RegNtPreCreateKey
HKLM\software\classes\song file\shell:: open,shell,command RegNtPreCreateKey
HKLM\software\classes\song file\shell\command:: Command RegNtPreCreateKey
HKLM\software\classes\song file\shell\command\command:: "C:\Users\Yiqmqzof\AppData\Local\Temp\is-7PGMD.tmp\ntrack.exe" "%1" RegNtPreCreateKey
HKLM\software\classes\song file\shell\open:: &Open RegNtPreCreateKey
HKLM\software\classes\song file\shell\open\command:: "C:\Users\Yiqmqzof\AppData\Local\Temp\is-7PGMD.tmp\ntrack.exe" "%1" RegNtPreCreateKey
HKLM\software\classes\song file\shell\shell:: Shell RegNtPreCreateKey
HKLM\software\classes\song file\shell\shell\command:: "C:\Users\Yiqmqzof\AppData\Local\Temp\is-7PGMD.tmp\ntrack.exe" "%1" RegNtPreCreateKey
HKLM\software\classes\.sngw:: Song File RegNtPreCreateKey
HKLM\software\classes\.sngw::content type nTrack/song RegNtPreCreateKey
HKLM\software\classes\song file:: n-Track Studio Song File RegNtPreCreateKey
HKLM\software\classes\song file\defaulticon:: C:\Users\Yiqmqzof\AppData\Local\Temp\is-7PGMD.tmp\ntrack.exe,2 RegNtPreCreateKey
HKLM\software\classes\song file\shell:: open,shell,command RegNtPreCreateKey
HKLM\software\classes\song file\shell\command:: Command RegNtPreCreateKey
HKLM\software\classes\song file\shell\command\command:: "C:\Users\Yiqmqzof\AppData\Local\Temp\is-7PGMD.tmp\ntrack.exe" "%1" RegNtPreCreateKey
HKLM\software\classes\song file\shell\open:: &Open RegNtPreCreateKey
HKLM\software\classes\song file\shell\open\command:: "C:\Users\Yiqmqzof\AppData\Local\Temp\is-7PGMD.tmp\ntrack.exe" "%1" RegNtPreCreateKey
HKLM\software\classes\song file\shell\shell:: Shell RegNtPreCreateKey
HKLM\software\classes\song file\shell\shell\command:: "C:\Users\Yiqmqzof\AppData\Local\Temp\is-7PGMD.tmp\ntrack.exe" "%1" RegNtPreCreateKey
HKLM\software\classes\.npk:: Peak file RegNtPreCreateKey
HKLM\software\classes\.npk::content type nTrack/peak RegNtPreCreateKey
HKLM\software\classes\peak file:: n-Track Studio wav peak file RegNtPreCreateKey
HKLM\software\classes\peak file\defaulticon:: C:\Users\Yiqmqzof\AppData\Local\Temp\is-7PGMD.tmp\ntrack.exe,3 RegNtPreCreateKey
HKLM\software\classes\peak file\shell:: open,shell,command RegNtPreCreateKey
HKLM\software\classes\peak file\shell\command:: Command RegNtPreCreateKey
HKLM\software\classes\peak file\shell\command\command:: "C:\Users\Yiqmqzof\AppData\Local\Temp\is-7PGMD.tmp\ntrack.exe" "%1" RegNtPreCreateKey
HKLM\software\classes\peak file\shell\open:: &Open RegNtPreCreateKey
HKLM\software\classes\peak file\shell\open\command:: "C:\Users\Yiqmqzof\AppData\Local\Temp\is-7PGMD.tmp\ntrack.exe" "%1" RegNtPreCreateKey
HKLM\software\classes\peak file\shell\shell:: Shell RegNtPreCreateKey
HKLM\software\classes\peak file\shell\shell\command:: "C:\Users\Yiqmqzof\AppData\Local\Temp\is-7PGMD.tmp\ntrack.exe" "%1" RegNtPreCreateKey

Windows API Usage

Category API
Process Manipulation Evasion
  • NtUnmapViewOfSection
Process Shell Execute
  • CreateProcess
Syscall Use
  • ntdll.dll!NtAlertThreadByThreadId
  • ntdll.dll!NtClose
  • ntdll.dll!NtCreateKey
  • ntdll.dll!NtCreateSection
  • ntdll.dll!NtFreeVirtualMemory
  • ntdll.dll!NtMapViewOfSection
  • ntdll.dll!NtOpenFile
  • ntdll.dll!NtOpenKeyEx
  • ntdll.dll!NtOpenSection
  • ntdll.dll!NtPowerInformation
Show More
  • ntdll.dll!NtProtectVirtualMemory
  • ntdll.dll!NtQueryAttributesFile
  • ntdll.dll!NtQueryInformationProcess
  • ntdll.dll!NtQueryInformationToken
  • ntdll.dll!NtQueryKey
  • ntdll.dll!NtQueryPerformanceCounter
  • ntdll.dll!NtQueryVirtualMemory
  • ntdll.dll!NtReleaseWorkerFactoryWorker
  • ntdll.dll!NtSetEvent
  • ntdll.dll!NtSetInformationProcess
  • ntdll.dll!NtSetInformationVirtualMemory
  • ntdll.dll!NtSetInformationWorkerFactory
  • ntdll.dll!NtTestAlert
  • ntdll.dll!NtWaitForAlertByThreadId
  • ntdll.dll!NtWaitForWorkViaWorkerFactory
  • ntdll.dll!NtWriteFile
  • UNKNOWN

Shell Command Execution

"C:\Users\Yiqmqzof\AppData\Local\Temp\is-AMOKK.tmp\2c3517d490792a52b1e283457a1d31c417ba5e37_0003722050.tmp" /SL5="$120344,3334215,121344,c:\users\user\downloads\2c3517d490792a52b1e283457a1d31c417ba5e37_0003722050"
"C:\Users\Yiqmqzof\AppData\Local\Temp\is-7PGMD.tmp\Hashrate_Architect.exe"

Trending

Most Viewed

Loading...