Threat Database Trojans Trojan.Flystud.A

Trojan.Flystud.A

By CagedTech in Trojans

Threat Scorecard

Popularity Rank: 10,623
Threat Level: 80 % (High)
Infected Computers: 641
First Seen: September 23, 2021
Last Seen: February 21, 2026
OS(es) Affected: Windows

Analysis Report

General information

Family Name: Trojan.Flystud.A
Signature status: No Signature

Known Samples

MD5: 272cca10d3c2818ab06787b5dfb6903e
SHA1: 2d111c1a671daa30003c53a66ca17023af36060e
SHA256: 4F39A2E43695956F22BC01FC97DBF91BC1883939C72C87AEF9D0EA0E883F11F1
File Size: 1.06 MB, 1057525 bytes
MD5: 6600cc1f484c5bffef8d4eb16e30cce1
SHA1: e1a44c3150504390f003fe308e53a1adb877e9be
SHA256: 9A79771829846E6688E884FDBEFA16A99EBF031D5892E4EC1599DDB9405C8DA6
File Size: 1.18 MB, 1178624 bytes

Windows Portable Executable Attributes

  • File doesn't have "Rich" header
  • File doesn't have debug information
  • File doesn't have exports table
  • File doesn't have relocations information
  • File doesn't have security information
  • File is 32-bit executable
  • File is either console or GUI application
  • File is GUI application (IMAGE_SUBSYSTEM_WINDOWS_GUI)
  • File is Native application (NOT .NET application)
  • File is not packed
Show More
  • IMAGE_FILE_DLL is not set inside PE header (Executable)
  • IMAGE_FILE_EXECUTABLE_IMAGE is set inside PE header (Executable Image)

File Icons

Windows PE Version Information

Name Value
Assembly Version 4.9.0.0
Comments 用于检测邮箱是否真实有效
Company Name daya123.com
File Description 批量-邮箱-有效性-验证-专家
File Version
  • 4.9.0.0
  • 1.00
Internal Name
  • TJprojMain
  • 大牙批量邮箱验证专家.exe
Legal Copyright Copyright © maYax.cn 2019
Legal Trademarks 大牙软件
Original Filename
  • TJprojMain.exe
  • 大牙批量邮箱验证专家.exe
Product Name
  • Project1
  • 邮箱有效性验证专家
Product Version
  • 4.9.0.0
  • 1.00

File Traits

  • 2+ executable sections
  • HighEntropy
  • ntdll
  • WriteProcessMemory
  • x86

Block Information

Total Blocks: 658
Potentially Malicious Blocks: 155
Whitelisted Blocks: 189
Unknown Blocks: 314

Visual Map

0 x 0 ? ? ? ? ? x ? ? 0 x x x 0 ? ? ? x 0 x ? ? x ? x 0 ? x 0 0 0 ? ? ? ? ? ? 0 ? x x ? x x x ? 0 0 ? ? ? ? x x ? ? ? ? ? x 0 ? ? ? ? ? ? ? ? ? ? ? x ? x 0 x x x x ? x 0 0 ? x ? x x x 0 x ? 0 0 0 0 x x x x 0 ? ? ? ? ? 0 x x ? ? ? x 0 x ? x 0 0 x x 0 0 x 0 0 x 0 0 0 ? 0 x 0 x 0 x 0 x x ? x 0 0 ? x 0 0 0 ? ? 0 x x ? ? ? ? x 0 ? 0 x 0 0 0 x 0 ? ? ? ? ? ? 0 x ? 0 0 0 0 ? ? ? ? ? 0 ? x x ? x 0 x ? 0 ? ? ? ? 0 ? x ? x x x 0 ? ? x x x x x x ? ? ? ? ? ? 0 0 ? 0 0 x x 0 x ? ? ? 0 0 x 0 0 ? ? x ? x ? ? ? ? 0 ? ? ? 0 ? ? x ? ? ? 0 ? ? 0 ? x x x x ? 0 0 x x x x 0 x x 0 ? ? ? ? 0 ? x ? 0 x ? 0 x ? x 0 ? 0 ? 0 ? ? ? ? ? x ? ? ? ? ? ? ? x ? ? ? 0 ? ? ? ? ? ? ? ? 0 0 ? ? ? ? x ? ? 0 0 ? x 0 ? x ? x 0 ? x ? 0 ? 0 ? ? ? ? ? ? ? 0 x x ? 0 ? x ? 0 x ? ? ? 0 0 ? ? ? 0 0 ? 0 0 ? x 0 0 x 0 0 ? ? ? ? 0 ? x 0 x ? ? 0 ? ? ? ? ? x ? ? ? ? ? x 0 ? x ? 0 ? x x ? 0 ? ? 0 0 ? ? 0 0 x ? ? ? ? 0 ? ? ? x ? 0 ? ? ? x 0 ? 0 0 x ? x 0 ? ? ? ? ? x ? 0 0 ? 0 ? 0 ? ? x ? 0 x ? ? ? 0 ? ? 0 0 0 x x 0 ? 0 ? ? x x ? x x x 0 ? 0 0 ? ? ? 0 ? 0 ? 0 0 ? ? x 0 ? ? x 0 ? x ? x 0 0 x ? ? ? x x 0 0 ? ? ? ? ? x ? ? 0 0 ? 0 ? 0 0 0 0 x x 0 0 0 ? ? 0 0 0 ? 0 0 ? ? 0 x 0 x 0 0 0 ? 0 ? ? 0 ? x x 0 0 ? 0 ? x ? ? ? ? x 0 x ? 0 0 x x ? ? x ? ? 0 ? 0 ? ? ? ? x ? ? x ? ? 0 0 0 0 0 0 x ? 0 0 ? ? ? ? x ? 0 ? ? ? 0 x x x ? ? 0 x ? 0 0 0 0 ? ? ? ? ? x ? ? ? ?
0 - Probable Safe Block
? - Unknown Block
x - Potentially Malicious Block

Windows API Usage

Category API
Other Suspicious
  • SetWindowsHookEx

Trending

Most Viewed

Loading...