Threat Database Trojans Trojan.Downloader.Small.HA

Trojan.Downloader.Small.HA

By CagedTech in Trojans

Threat Scorecard

Threat Level: 80 % (High)
Infected Computers: 3
First Seen: October 26, 2021
Last Seen: April 10, 2026
OS(es) Affected: Windows

The detection of Trojan.Downloader.Small.HA on your system indicates a potential security threat that requires immediate attention. This type of malware is designed to download and install additional malicious software on your computer, which can lead to a range of problems, including data theft, system crashes, and unauthorized access to your personal information.

What Is Trojan.Downloader.Small.HA?

Trojan.Downloader.Small.HA is a type of Trojan horse malware that is designed to download and install additional malicious software on your computer. The name "Trojan" refers to the fact that this type of malware disguises itself as a legitimate program or file, allowing it to evade detection and gain access to your system. The "Downloader" part of the name indicates that this malware is capable of downloading additional malicious software from the internet, which can include viruses, spyware, adware, and other types of malware.

How Trojan.Downloader.Small.HA Operates

Trojan.Downloader.Small.HA typically operates by exploiting vulnerabilities in your system or tricking you into downloading and installing it. Once installed, it can download and install additional malicious software, including viruses, spyware, and adware. This malware can also modify your system settings, steal your personal data, and provide unauthorized access to your computer. It's worth noting that the exact mechanisms of operation can vary depending on the specific goals of the attackers and the vulnerabilities they exploit.

Symptoms of Infection

The symptoms of a Trojan.Downloader.Small.HA infection can vary, but common signs include slow system performance, unexpected pop-ups and ads, unfamiliar programs or icons on your desktop, and changes to your system settings. You may also notice that your browser is being redirected to unfamiliar websites or that your personal data is being stolen. In some cases, the infection may not exhibit any noticeable symptoms at all, making it difficult to detect without the use of antivirus software.

  • Slow system performance
  • Unexpected pop-ups and ads
  • Unfamiliar programs or icons on your desktop
  • Changes to your system settings
  • Browser redirection to unfamiliar websites
  • Theft of personal data

How to Remove Trojan.Downloader.Small.HA

  1. Boot your computer in Safe Mode with Networking to prevent the malware from loading and to allow for a clean scan.
  2. Use a reputable antivirus tool, such as SpyHunter, to perform a full scan of your system and remove any detected threats.
  3. Uninstall any suspicious programs or applications that you do not recognize or that were installed without your knowledge.
  4. Reset your web browsers, including Chrome, Firefox, and Edge, to their default settings to remove any malicious extensions or add-ons.
  5. Reboot your computer and perform another scan with your antivirus software to ensure that the malware has been completely removed.

Conclusion

Removing Trojan.Downloader.Small.HA from your system requires a combination of technical expertise and caution. By following the steps outlined above and using reputable antivirus software, you can help to protect your system and prevent future infections. It's also important to practice safe computing habits, such as avoiding suspicious downloads and emails, using strong passwords, and keeping your operating system and software up to date. Remember that prevention is key, and staying informed about the latest threats and vulnerabilities is essential for maintaining the security and integrity of your computer system.

Analysis Report

General information

Family Name: Trojan.Downloader.Small.HA
Packers: UPX
Signature status: No Signature

Known Samples

MD5: 18cb68ce8b24f3f057d557140c82ae10
SHA1: 4faedda49f66e36f8c044b0bf840295352654c22
SHA256: 66176AD49350EB0CAB418F4898531DFBEBF7742C678C1673E1F2D552EA76B61D
File Size: 10.75 KB, 10752 bytes

Windows Portable Executable Attributes

  • File doesn't have "Rich" header
  • File doesn't have debug information
  • File doesn't have exports table
  • File doesn't have relocations information
  • File doesn't have resources
  • File doesn't have security information
  • File has been packed
  • File is 32-bit executable
  • File is either console or GUI application
  • File is GUI application (IMAGE_SUBSYSTEM_WINDOWS_GUI)
Show More
  • File is Native application (NOT .NET application)
  • IMAGE_FILE_DLL is not set inside PE header (Executable)
  • IMAGE_FILE_EXECUTABLE_IMAGE is set inside PE header (Executable Image)

File Traits

  • No Version Info
  • packed
  • x86

Block Information

Total Blocks: 56
Potentially Malicious Blocks: 9
Whitelisted Blocks: 47
Unknown Blocks: 0

Visual Map

x x 0 0 0 x 0 0 0 0 0 0 0 0 0 0 0 x x 0 0 0 x 1 0 0 0 x 0 0 0 0 0 0 x 0 0 0 x 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0
0 - Probable Safe Block
? - Unknown Block
x - Potentially Malicious Block

Similar Families

  • Downloader.Small.HA

Files Modified

File Attributes
c:\users\user\appdata\local\temp\a68b.tmp Generic Write,Read Attributes
c:\users\user\downloads\tmpfile0.bat Generic Write,Read Attributes

Registry Modifications

Key::Value Data API Name
HKLM\system\controlset001\services\bam\state\usersettings\s-1-5-21-3119368278-1123331430-659265220-1001::\device\harddiskvolume2\windows\system32\conhost.exe 볻ᙧ畓ǜ RegNtPreCreateKey
HKCU\software\microsoft\windows\currentversion\internet settings\zonemap::proxybypass  RegNtPreCreateKey
HKCU\software\microsoft\windows\currentversion\internet settings\zonemap::intranetname  RegNtPreCreateKey
HKCU\software\microsoft\windows\currentversion\internet settings\zonemap::uncasintranet  RegNtPreCreateKey
HKCU\software\microsoft\windows\currentversion\internet settings\zonemap::autodetect RegNtPreCreateKey
HKCU\software\microsoft\windows\currentversion\internet settings\zonemap::proxybypass  RegNtPreCreateKey
HKCU\software\microsoft\windows\currentversion\internet settings\zonemap::intranetname  RegNtPreCreateKey
HKCU\software\microsoft\windows\currentversion\internet settings\zonemap::uncasintranet  RegNtPreCreateKey
HKCU\software\microsoft\windows\currentversion\internet settings\zonemap::autodetect RegNtPreCreateKey
HKLM\software\microsoft\windows nt\currentversion\notifications\data::418a073aa3bc1c75 (k�8��8tX��B�8 �6 �v 5� �Z xy ��T�B�������������5����ee��Bx�< �!wz"Wc#�#��$kF$��%"�%:�%�&� &�x(�(X�)�`*J*9*�^*�h+�[,��/9�/��0P%1`1�1HO1�D5�05�G6�^6�� RegNtPreCreateKey
Show More
HKLM\software\microsoft\windows nt\currentversion\notifications\data::418a073aa3bc3475 ��2 xy* �/��Y�d�kP~��� ��ރ�p��^�o���zee(Vs} kP~ ��1���7 ���ﺃee����1��fe��h RegNtPreCreateKey
HKLM\system\controlset001\services\bam\state\usersettings\s-1-5-21-3119368278-1123331430-659265220-1001::\device\harddiskvolume2\windows\system32\conhost.exe ៵畓ǜ RegNtPreCreateKey
HKLM\software\microsoft\windows nt\currentversion\notifications\data::418a073aa3bc1c75 )k�8��8tX��B�8 �6 �v 5� �Z xy ��T�B�������������5����ee��Bx�< �!wz"Wc#�#��$kF$��%"�%:�%�&� &�x(�(X�)�`*J*9*�^*�h+�[,��/9�/��0P%1`1�1HO1�D5�05�G6�^6�� RegNtPreCreateKey

Windows API Usage

Category API
Process Manipulation Evasion
  • NtUnmapViewOfSection
Process Shell Execute
  • CreateProcess
  • ShellExecute
  • WinExec
  • WriteConsole
Syscall Use
  • ntdll.dll!NtAccessCheck
  • ntdll.dll!NtAlertThreadByThreadId
  • ntdll.dll!NtAlpcConnectPortEx
  • ntdll.dll!NtAlpcQueryInformation
  • ntdll.dll!NtAlpcSendWaitReceivePort
  • ntdll.dll!NtApphelpCacheControl
  • ntdll.dll!NtAssociateWaitCompletionPacket
  • ntdll.dll!NtClearEvent
  • ntdll.dll!NtClose
  • ntdll.dll!NtConnectPort
Show More
  • ntdll.dll!NtCreateEvent
  • ntdll.dll!NtCreateFile
  • ntdll.dll!NtCreateMutant
  • ntdll.dll!NtCreateSection
  • ntdll.dll!NtCreateSemaphore
  • ntdll.dll!NtDeviceIoControlFile
  • ntdll.dll!NtDuplicateObject
  • ntdll.dll!NtDuplicateToken
  • ntdll.dll!NtEnumerateKey
  • ntdll.dll!NtEnumerateValueKey
  • ntdll.dll!NtFreeVirtualMemory
  • ntdll.dll!NtMapViewOfSection
  • ntdll.dll!NtOpenDirectoryObject
  • ntdll.dll!NtOpenEvent
  • ntdll.dll!NtOpenFile
  • ntdll.dll!NtOpenKey
  • ntdll.dll!NtOpenKeyEx
  • ntdll.dll!NtOpenMutant
  • ntdll.dll!NtOpenProcessToken
  • ntdll.dll!NtOpenProcessTokenEx
  • ntdll.dll!NtOpenSection
  • ntdll.dll!NtOpenSemaphore
  • ntdll.dll!NtOpenThreadToken
  • ntdll.dll!NtOpenThreadTokenEx
  • ntdll.dll!NtProtectVirtualMemory
  • ntdll.dll!NtQueryAttributesFile
  • ntdll.dll!NtQueryInformationProcess
  • ntdll.dll!NtQueryInformationThread
  • ntdll.dll!NtQueryInformationToken
  • ntdll.dll!NtQueryKey
  • ntdll.dll!NtQueryPerformanceCounter
  • ntdll.dll!NtQuerySecurityAttributesToken
  • ntdll.dll!NtQuerySecurityObject
  • ntdll.dll!NtQuerySystemInformation
  • ntdll.dll!NtQueryValueKey
  • ntdll.dll!NtQueryVirtualMemory
  • ntdll.dll!NtQueryVolumeInformationFile
  • ntdll.dll!NtQueryWnfStateData
  • ntdll.dll!NtReleaseMutant
  • ntdll.dll!NtReleaseSemaphore
  • ntdll.dll!NtReleaseWorkerFactoryWorker
  • ntdll.dll!NtRequestWaitReplyPort
  • ntdll.dll!NtSetEvent
  • ntdll.dll!NtSetInformationKey
  • ntdll.dll!NtSetInformationProcess
  • ntdll.dll!NtSetInformationVirtualMemory
  • ntdll.dll!NtSetInformationWorkerFactory
  • ntdll.dll!NtSetTimer2
  • ntdll.dll!NtSubscribeWnfStateChange
  • ntdll.dll!NtTestAlert
  • ntdll.dll!NtTraceControl
  • ntdll.dll!NtUnmapViewOfSection
  • ntdll.dll!NtUnmapViewOfSectionEx
  • ntdll.dll!NtWaitForAlertByThreadId
  • ntdll.dll!NtWaitForMultipleObjects
  • ntdll.dll!NtWaitForSingleObject
  • ntdll.dll!NtWaitForWorkViaWorkerFactory
  • ntdll.dll!NtWaitLowEventPair
  • ntdll.dll!NtWorkerFactoryWorkerReady
  • ntdll.dll!NtWriteFile
  • UNKNOWN
Anti Debug
  • IsDebuggerPresent
User Data Access
  • GetUserObjectInformation
Process Terminate
  • TerminateProcess

Shell Command Execution

"tmpfile0.bat"
WriteConsole: =-=-=-=-= Regist
WriteConsole: .
WriteConsole: .
WriteConsole:
Show More
WriteConsole: c:\users\user\DO
WriteConsole: regsvr32
WriteConsole: /c /s c:\dinema
WriteConsole:
C:\WINDOWS\system32\regsvr32.exe regsvr32 /c /s c:\dinema\santoni\Bin\colorwellN3.ocx
WriteConsole:
WriteConsole: c:\users\user\DO
WriteConsole: regsvr32
WriteConsole: /c /s c:\dinema
WriteConsole:
C:\WINDOWS\system32\regsvr32.exe regsvr32 /c /s c:\dinema\santoni\Bin\colorselectorN2.ocx
WriteConsole:
WriteConsole: c:\users\user\DO
WriteConsole: regsvr32
WriteConsole: /c /s c:\dinema
WriteConsole:
C:\WINDOWS\system32\regsvr32.exe regsvr32 /c /s c:\dinema\santoni\Bin\LanguageselectorN2.dll
WriteConsole:
WriteConsole: c:\users\user\DO
WriteConsole: regsvr32
WriteConsole: /c /s c:\dinema
WriteConsole:
C:\WINDOWS\system32\regsvr32.exe regsvr32 /c /s c:\dinema\santoni\Bin\MacN5.dll
WriteConsole:
WriteConsole: c:\users\user\DO
WriteConsole: regsvr32
WriteConsole: /c /s c:\dinema
WriteConsole:
C:\WINDOWS\system32\regsvr32.exe regsvr32 /c /s c:\dinema\santoni\Bin\MacBrowserN5.dll
WriteConsole:
WriteConsole: c:\users\user\DO
WriteConsole: regsvr32
WriteConsole: /c /s c:\dinema
WriteConsole:
C:\WINDOWS\system32\regsvr32.exe regsvr32 /c /s c:\dinema\santoni\Bin\SGConverter.dll
WriteConsole:
WriteConsole: c:\users\user\DO
WriteConsole: goto
WriteConsole: DONEOCX
WriteConsole:
WriteConsole:
WriteConsole: c:\users\user\DO
WriteConsole: call
WriteConsole: c:\dinema\santo
WriteConsole:
WriteConsole: The system canno
WriteConsole:
WriteConsole: c:\users\user\DO
WriteConsole: call
WriteConsole: c:\dinema\santo
WriteConsole:
WriteConsole: The system canno
WriteConsole:
WriteConsole: c:\users\user\DO
WriteConsole: call
WriteConsole: c:\dinema\santo
WriteConsole:
WriteConsole: The system canno
WriteConsole:
WriteConsole: c:\users\user\DO
WriteConsole: call
WriteConsole: c:\dinema\santo
WriteConsole:
WriteConsole: The system canno
WriteConsole:
WriteConsole: c:\users\user\DO
WriteConsole: call
WriteConsole: c:\dinema\santo
WriteConsole:
WriteConsole: The system canno
WriteConsole:
WriteConsole: c:\users\user\DO
WriteConsole: call
WriteConsole: c:\dinema\santo
WriteConsole:
WriteConsole: The system canno
WriteConsole:
WriteConsole: c:\users\user\DO
WriteConsole: call
WriteConsole: c:\dinema\santo
WriteConsole:
WriteConsole: The system canno
WriteConsole:
WriteConsole: c:\users\user\DO
WriteConsole: call
WriteConsole: c:\dinema\santo
WriteConsole:
WriteConsole: The system canno
WriteConsole:
WriteConsole: c:\users\user\DO
WriteConsole: c:\dinema\santon
WriteConsole: -L English_us
WriteConsole:
WriteConsole: The system canno
WriteConsole:
WriteConsole: c:\users\user\DO
WriteConsole: c:\dinema\santon
WriteConsole: c:\dinema\santo
WriteConsole:
WriteConsole: The system canno
WriteConsole:
WriteConsole: c:\users\user\DO
WriteConsole: c:\dinema\santon
WriteConsole: c:\dinema\santo
WriteConsole:
WriteConsole: The system canno
WriteConsole:
WriteConsole: c:\users\user\DO
WriteConsole: c:\dinema\santon
WriteConsole: c:\dinema\santo
WriteConsole:
WriteConsole: The system canno
C:\Users\Mflnmjiq\AppData\Local\Temp\A68B.tmp c:\users\user\DOWNLO~1
open tmpfile0.bat
WriteConsole:
WriteConsole: c:\users\user\DO
WriteConsole: del
WriteConsole: "C:\Users\Mflnm
WriteConsole:
WriteConsole:
WriteConsole: c:\users\user\DO
WriteConsole: del
WriteConsole: "tmpfile0.bat"
WriteConsole:
WriteConsole: The batch file c

Trending

Most Viewed

Loading...