Threat Database Trojans Trojan.Dropper-Delf

Trojan.Dropper-Delf

By CagedTech in Trojans

Threat Scorecard

Popularity Rank: 13,191
Threat Level: 90 % (High)
Infected Computers: 1,491
First Seen: July 24, 2009
Last Seen: January 3, 2026
OS(es) Affected: Windows

Aliases

15 security vendors flagged this file as malicious.

Antivirus Vendor Detection
Sophos Mal/Generic-L
Panda Trj/CI.A
NOD32 a variant of Win32/Delf.TKR
McAfee Generic.dx!tbc
Kaspersky Backdoor.Win32.Delf.vih
eSafe Win32.HEURMalware
CAT-QuickHeal Backdoor.Delf.vih
BitDefender Trojan.Generic.4322967
AVG Delf.RQG
AntiVir TR/Agent.260096.F
AhnLab-V3 Backdoor/Win32.Delf
McAfee-GW-Edition Heuristic.LooksLike.Trojan.Spy.Delf.I
AntiVir TR/Agent.406036.A
Microsoft VirTool:Win32/VBInject.gen!BP
BitDefender Gen:Trojan.Heur.GZ.!q0@bW6tdMai

File System Details

Trojan.Dropper-Delf may create the following file(s):
# File Name MD5 Detections
1. datastub.dll ee4abb039e7b610759f82f9e380ed87f 1
2. jhbini.dll 8bb7a6bf5968b0cff39ed22a64c588ad 0
3. fycini.dll b018a0ba8b4a7f0d838a6a7aad896502 0
4. fontext_a.dll f7601d1a4fa7e35d87fe4d5eaca0c5a2 0
5. msm.exe aa6ea0b8dffba3af32c92a1aacb04940 0
6. show2[1].exe edcbece80245af8ca7c415716336bc81 0
7. winlogo.exe 475de79b3e3ac05d5882aea679489c09 0
8. propa.exe 45c0bf52ef941a600798234ff3f84b27 0
9. lsas.exe 59fa22323eec6e0ff8e5fb8837bde567 0
10. Z4k3bSNu.dll 8bf6002aabc0b092c84d24039085e17c 0
11. services.exe 4ad640440d782204fac585eed10037b4 0
12. PR15.DLL f3b05a02f034a43af91f8465aedbd8e5 0
13. svchost32.exe ac782a0bc07fc653b10f6506a584b494 0
14. Oldwin2.exe 2e12a3b3b6cdca977481f01b344e7516 0
15. d215b4.exe 3e2638bc37920a78602283f71ff333a3 0
16. lsass.exe 60792211318a7479605271cc47a92b22 0
17. msdrv32.exe e0944ac9f65b81fa2a868aef5cc7ab78 0
18. winntR1.exe 74d9123390ffc6c4fc0c49221a05fbdb 0
19. 9D57.tmp 410824c4330b76115a16ee1c2e858dcc 0
20. svchost.exe c9df093778f8628fba86a37427916cd7 0
21. svhoster.exe 2f669a6b0f4e846eb01eb6acc4921426 0
22. msnmsgr.exe c68a2518eaf9529e8cc542b27544c087 0
23. windll32.exe 7685e13557e6bb437e4d74ecc7a6dcbb 0
24. filegetupgrade.exe aba66d1bba857711c94601e716cdc2c1 0
25. Metin2.exe 79faf020b720b0c7a9760abda2566e32 0
More files

Registry Details

Trojan.Dropper-Delf may create the following registry entry or registry entries:
CLSID
{B8A170A8-7AD3-4678-B2FE-F2D7381CC1B5}
File name without path
Metin2.exe
Run keys
gamma
RegistryMonitor1

Analysis Report

General information

Family Name: Trojan.Dropper.Delf
Signature status: No Signature

Known Samples

MD5: 7f843d20a42fe67f01826315c4ac8331
SHA1: 722250d4829cec16c4846b6907ab4ffd52822150
SHA256: 34232080DEED2E1C336F677EEB5AA8A5F37FB01DA611956876692B46BECBCAC6
File Size: 3.44 MB, 3441152 bytes
MD5: 00204b8a9179acf5decf78c175573083
SHA1: a27bc48a57e4979004166fe5282cc2295c5504cf
SHA256: FAC019E727A0BF49B3B422A23214ED7EC880A10F4D3E459A1ADF929C135A1279
File Size: 2.83 MB, 2832276 bytes

Windows Portable Executable Attributes

  • File doesn't have "Rich" header
  • File doesn't have debug information
  • File doesn't have exports table
  • File doesn't have relocations information
  • File doesn't have security information
  • File has TLS information
  • File is 32-bit executable
  • File is either console or GUI application
  • File is GUI application (IMAGE_SUBSYSTEM_WINDOWS_GUI)
  • File is Native application (NOT .NET application)
Show More
  • File is not packed
  • IMAGE_FILE_DLL is not set inside PE header (Executable)
  • IMAGE_FILE_EXECUTABLE_IMAGE is set inside PE header (Executable Image)

File Icons

Windows PE Version Information

Name Value
File Version 1.00
Internal Name TJprojMain
Original Filename TJprojMain.exe
Product Name Project1
Product Version 1.00

File Traits

  • dll
  • HighEntropy
  • x86

Block Information

Similar Families

  • Ekstak.AN
  • FakeAlert.X

Windows API Usage

Category API
Other Suspicious
  • SetWindowsHookEx

Trending

Most Viewed

Loading...