Threat Database Trojans Trojan.Dropper.NFA

Trojan.Dropper.NFA

By CagedTech in Trojans

Threat Scorecard

Threat Level: 80 % (High)
Infected Computers: 0
First Seen: June 15, 2026
OS(es) Affected: Windows

Analysis Report

General information

Family Name: Trojan.Dropper.NFA
Signature status: No Signature

Known Samples

MD5: 7f86248fbf1227d429e8a26e1ee1cf3b
SHA1: 48f92091911cdcb79d974699959d9001af1ab114
SHA256: D5D2A8B2CC5D9ADD34E18385B399CB813AF7C4D7A74C98F9C5952AD0D747EF38
File Size: 751.10 KB, 751104 bytes

Windows Portable Executable Attributes

  • File doesn't have "Rich" header
  • File doesn't have debug information
  • File doesn't have exports table
  • File doesn't have security information
  • File has TLS information
  • File is 64-bit executable
  • File is either console or GUI application
  • File is GUI application (IMAGE_SUBSYSTEM_WINDOWS_GUI)
  • File is Native application (NOT .NET application)
  • File is not packed
Show More
  • IMAGE_FILE_DLL is not set inside PE header (Executable)
  • IMAGE_FILE_EXECUTABLE_IMAGE is set inside PE header (Executable Image)

File Traits

  • No Version Info
  • x64

Block Information

Total Blocks: 102
Potentially Malicious Blocks: 1
Whitelisted Blocks: 68
Unknown Blocks: 33

Visual Map

0 0 0 0 0 0 0 0 0 0 ? ? 0 ? ? ? ? ? 0 0 0 0 ? ? 0 0 ? ? ? 0 0 0 ? ? 0 0 ? ? ? ? 0 ? ? 0 ? ? 0 0 ? 0 ? ? 0 ? ? 0 ? ? ? ? 0 ? ? x 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0
0 - Probable Safe Block
? - Unknown Block
x - Potentially Malicious Block

Files Modified

File Attributes
c:\users\public\runtimebroker.exe Generic Read,Write Data,Write Attributes,Write extended,Append data,Delete,LEFT 262144
c:\users\public\runtimebroker.exe Synchronize,Write Attributes
c:\users\public\syscfg_33d6b34d.datu Generic Read,Write Data,Write Attributes,Write extended,Append data
c:\users\public\syscfg_33d6b34d.w Generic Read,Write Data,Write Attributes,Write extended,Append data

Registry Modifications

Key::Value Data API Name
HKCU\software\microsoft\windows\currentversion\run::microsoftwindowsupdate C:\Users\Public\RuntimeBroker.exe RegNtPreCreateKey

Windows API Usage

Category API
Syscall Use
  • ntdll.dll!NtClose
  • ntdll.dll!NtEnumerateValueKey
  • ntdll.dll!NtFreeVirtualMemory
  • ntdll.dll!NtOpenKey
  • ntdll.dll!NtOpenKeyEx
  • ntdll.dll!NtOpenProcessToken
  • ntdll.dll!NtPowerInformation
  • ntdll.dll!NtProtectVirtualMemory
  • ntdll.dll!NtQueryInformationToken
  • ntdll.dll!NtQueryKey
Show More
  • ntdll.dll!NtReleaseWorkerFactoryWorker
  • ntdll.dll!NtSetEvent
  • ntdll.dll!NtSetInformationThread
  • ntdll.dll!NtSetInformationWorkerFactory
  • ntdll.dll!NtTestAlert
  • ntdll.dll!NtTraceEvent
  • ntdll.dll!NtUnmapViewOfSection
  • ntdll.dll!NtWaitForSingleObject
  • ntdll.dll!NtWaitForWorkViaWorkerFactory
  • ntdll.dll!NtWriteFile
  • ntdll.dll!NtYieldExecution
  • UNKNOWN
Process Shell Execute
  • CreateProcess
Network Winsock2
  • WSAStartup
Network Winsock
  • closesocket
  • connect
  • gethostbyname
  • inet_addr
  • recv
  • send
  • socket

Shell Command Execution

schtasks /create /tn MicrosoftEdgeUpdateCheck /tr "\"c:\users\user\downloads\48f92091911cdcb79d974699959d9001af1ab114_0000751104\"" /sc onlogon /ru SYSTEM /f