Threat Database Trojans Trojan.FakeDoc

Trojan.FakeDoc

By CagedTech in Trojans

Threat Scorecard

Threat Level: 80 % (High)
Infected Computers: 241
First Seen: July 24, 2009
Last Seen: May 5, 2026
OS(es) Affected: Windows

Aliases

5 security vendors flagged this file as malicious.

Antivirus Vendor Detection
Sophos Mal/Behav-043
Prevx1 Generic.Malware
Panda Suspicious file
F-Secure Suspicious:W32/Malware!Gemini
ClamAV Trojan.Fakedoc-2

SpyHunter Detects & Remove Trojan.FakeDoc

File System Details

Trojan.FakeDoc may create the following file(s):
# File Name MD5 Detections
1. Abaddon.exe 041d36b3de93f4d81408b6241f62a7b7 0

Registry Details

Trojan.FakeDoc may create the following registry entry or registry entries:
Regexp file mask
%APPDATA%\RAC\mls.exe

Analysis Report

General information

Family Name: Trojan.FakeDoc
Signature status: No Signature

Known Samples

MD5: 78ca816aa940f7aeac134269d8508097
SHA1: dd2dc9017b90b233f877d665d2c37f20ed542461
SHA256: 4AD3E44D30A8A5F8E781694732859DB32D154999B653B19CE1160639049E6310
File Size: 8.32 MB, 8318741 bytes
MD5: fb79b22dc1fca71a0805acdeb3b261c6
SHA1: 26e4bad26a734925f67e6d30631df92685a46224
SHA256: F832F1430B4E7FB9BED761639CEC61626097613150E63CC0377C120AA8949E7C
File Size: 729.09 KB, 729088 bytes
MD5: 549c5586e11172ba8db3c5064ddca88b
SHA1: 7fa3ba3f215feddcad822874e51ecd5d16cb4594
SHA256: 680631E64CAFDEE0B8AC6F7E2071157AC54EB4D8C46FBF053C99E0D9E7848B24
File Size: 8.81 MB, 8814758 bytes
MD5: b3a29faf4126f95be4cd48a6dcf41a4f
SHA1: 13ff8cecbde7a76611529742c4bcea3d95cb5ffb
SHA256: 37BE0A4AF9D79BF623C345153C6414BF2A302CA0BCEA037C21F8374D54E322AD
File Size: 1.63 MB, 1626112 bytes

Windows Portable Executable Attributes

  • File doesn't have "Rich" header
  • File doesn't have debug information
  • File doesn't have exports table
  • File doesn't have relocations information
  • File doesn't have security information
  • File is 32-bit executable
  • File is either console or GUI application
  • File is GUI application (IMAGE_SUBSYSTEM_WINDOWS_GUI)
  • File is Native application (NOT .NET application)
  • File is not packed
Show More
  • IMAGE_FILE_DLL is not set inside PE header (Executable)
  • IMAGE_FILE_EXECUTABLE_IMAGE is set inside PE header (Executable Image)

File Icons

Windows PE Version Information

Name Value
Company Name
  • Microsoft Corp.
  • Orlando's VBA and Excel Site
File Description Excel application converted by XLtoEXE utility.
File Version
  • 2.00.0006
  • 2.00
Internal Name
  • msfir80
  • XLtoEXE
Legal Copyright
  • Copyright © 2003-2017 Fco Orlando Magalhaes Filho. All rights reserved.
  • Copyright © 2003-2022 Francisco Orlando Magalhães Filho. All rights reserved.
Legal Trademarks Microsoft® Excel® is a registered trademark of Microsoft Corporation.
Original Filename
  • msfir80.exe
  • XLtoEXE.exe
Product Name
  • FireWall Files
  • XLtoEXE
Product Version
  • 2.00.0006
  • 2.00

File Traits

  • big overlay
  • vb6
  • x86

Files Modified

File Attributes
c:\users\user\appdata\local\temp\~dfa1e83ba017190c87.tmp Generic Read,Write Data,Write Attributes,Write extended,Append data

Windows API Usage

Category API
Other Suspicious
  • SetWindowsHookEx

Trending

Most Viewed

Loading...