Threat Database Trojans Trojan.FlyStudio.D

Trojan.FlyStudio.D

By CagedTech in Trojans

Threat Scorecard

Popularity Rank: 7,136
Threat Level: 40 % (Medium)
Infected Computers: 799
First Seen: July 24, 2009
Last Seen: January 31, 2026
OS(es) Affected: Windows

Aliases

8 security vendors flagged this file as malicious.

Antivirus Vendor Detection
Sophos Troj/Zlobla-Gen
McAfee Puper.dll
Ikarus not-virus:Hoax.Win32.Renos.ei
Fortinet Misc/Zlobla
eWido Not-A-Virus.Hoax.Win32.Renos.ei
ClamAV Trojan.Downloader.Zlob-1358
AVG Generic2.BXK
Avast Win32:Zlob-NO

SpyHunter Detects & Remove Trojan.FlyStudio.D

File System Details

Trojan.FlyStudio.D may create the following file(s):
# File Name MD5 Detections
1. isaddon.dll 71b49ab8f9cbb76406b273df6a83ec6e 0

Analysis Report

General information

Family Name: Trojan.FlyStudio.D
Packers: UPX
Signature status: No Signature

Known Samples

MD5: 97383ed27b706163fe9b5c8655dfcc2e
SHA1: d7656908f33fa086c2770c7d48239e970fa59280
SHA256: F86CD519CDD69C941FB8F8ED44EC02F9981561CB4F5E7041B452B8ABB5F1F030
File Size: 7.10 MB, 7104000 bytes
MD5: f1b8c0549ea7e582a425b2517ab5b2e8
SHA1: 31795175a97e27cc8e7f49a04e80abc30010240e
SHA256: 1F4B57E854AA3D627976C2DE96B1CE250D98E66D5E0EB6126FBB18738CE245BB
File Size: 1.06 MB, 1064960 bytes
MD5: 2f591530a1abce964f8004ffab53b1bf
SHA1: a2a83b9ce537f1a2590885a34ef7719b53ddc63b
SHA256: E30DFF233AFECA4A87D4FB6D4EC0D9683C4D63EEF3409D3C10C5E325EC7AE7B8
File Size: 8.41 MB, 8409088 bytes
MD5: a2088c55cf23996ac01f4c58bfe6e2b4
SHA1: 130f159c516ac32ea0b12f7921796b214b34491c
SHA256: 633EFF3B26F0C5C29F7A474E07AC58AC143D6E1E43777C0BD99187A0F2432583
File Size: 410.11 KB, 410112 bytes
MD5: 704c54b0631110514a93044d8332e23e
SHA1: ec552a4dd47ce6ace3bf81e14b2fa61573f62b30
SHA256: 1A5E4FCE6203630307ACF2BD5E8AA0D26F06C8E8D730E284B4ECFEC9D145F243
File Size: 1.18 MB, 1179648 bytes
Show More
MD5: 6f280d30ef1c0c4aa9ac3aeacca954a6
SHA1: a042f85814c77917379ad06f435b2ca9e0fe19d0
SHA256: 192A7879624985CA2E16FB5251A98EF71A942A14F0BD3DA0902C154E26ACFB80
File Size: 1.66 MB, 1658880 bytes
MD5: 8a5c195cade8b26310502360e3d84f59
SHA1: 99f6582918aab0617fa2c8ee499ebf2b010f89dc
SHA256: 943621E02133C940D7DE4385822A07B83140B755AB37D4B2C9E5566F8C74B4D6
File Size: 475.65 KB, 475648 bytes

Windows Portable Executable Attributes

  • File doesn't have "Rich" header
  • File doesn't have debug information
  • File doesn't have exports table
  • File doesn't have relocations information
  • File doesn't have security information
  • File has been packed
  • File is 32-bit executable
  • File is either console or GUI application
  • File is GUI application (IMAGE_SUBSYSTEM_WINDOWS_GUI)
  • File is Native application (NOT .NET application)
Show More
  • File is not packed
  • IMAGE_FILE_DLL is not set inside PE header (Executable)
  • IMAGE_FILE_EXECUTABLE_IMAGE is set inside PE header (Executable Image)

File Icons

Windows PE Version Information

Name Value
Comments
  • Windows 高级电源辅助管理工具 by 有限的未知
  • 修真大陆
  • 本程序使用易语言编写(http://www.eyuyan.com)
  • 疯猫数据库
Company Name
  • 北冥
  • 有限的未知
  • 疯猫
File Description
  • Windows 高级电源辅助管理工具 by 有限的未知
  • 修真大陆
  • 复制粘贴
  • 疯猫数据库V9.2
  • 系统资源程序
File Version
  • 9.2.0.0
  • 1.1.1.11
  • 1.0.0.0
Legal Copyright
  • DXVM 非原创By:Gao Meinan
  • 作者版权所有 请尊重并使用正版
  • 北冥
  • 有限的未知 版权所有
  • 疯猫版权所有
Product Name
  • Windows 高级电源辅助管理工具 by 有限的未知
  • 修真大陆
  • 复制粘贴
  • 疯猫数据库
  • 系统资源程序
Product Version
  • 9.2.0.0
  • 1.1.1.1
  • 1.0.0.0

File Traits

  • .UPX
  • 2+ executable sections
  • HighEntropy
  • No Version Info
  • packed
  • UPX!
  • VirtualQueryEx
  • x86

Block Information

Total Blocks: 541
Potentially Malicious Blocks: 138
Whitelisted Blocks: 274
Unknown Blocks: 129

Visual Map

x x x x ? ? x 0 0 x ? 0 0 0 x ? ? ? ? 0 ? 0 ? ? ? ? ? ? ? ? ? ? ? x ? ? ? ? ? ? ? ? ? x ? ? x ? ? ? ? ? ? 0 ? ? ? ? ? ? ? ? ? ? ? ? ? ? x ? ? ? ? ? x ? ? 0 x ? 0 0 ? ? x ? ? ? ? x ? ? ? ? ? ? ? ? ? ? x ? x x ? ? x ? ? ? ? ? ? ? ? ? ? ? ? ? ? ? ? ? ? ? ? ? ? ? ? ? ? x ? ? ? ? ? ? ? ? ? ? ? ? ? ? ? x x x ? ? ? ? ? ? ? ? ? ? x x 0 0 0 0 x 0 0 x x x x x x x 0 x 0 x x x ? x x x x x x x 0 x x x 0 x x x x 0 x x x x x x x 0 x x 1 0 x x x 0 x x 1 x x x 0 x x x x x 0 x x x 0 x x x x 0 x 0 x x x x x x x x x 0 x x x x x x x x x x 0 x x 0 x x x x 0 x 0 0 0 1 0 0 0 0 1 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 1 0 0 0 0 0 1 0 0 0 0 0 1 1 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 1 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 1 1 0 0 0 0 0 0 0 0 0 0 0 0 0 0 1 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 1 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 x x x x x x x x x x x x x 0 0 0 0 x x x x x x x x x x 0 x x x x x x x x
0 - Probable Safe Block
? - Unknown Block
x - Potentially Malicious Block

Similar Families

  • Bitcoinminer.FD
  • Trojan.Downloader.Gen.CG
  • Trojan.Downloader.Gen.DO
  • Trojan.Downloader.Gen.EY
  • Trojan.Downloader.Gen.HL
Show More
  • Trojan.Downloader.Gen.HQ

Windows API Usage

Category API
Network Winsock2
  • WSAStartup
Anti Debug
  • IsDebuggerPresent
User Data Access
  • GetUserObjectInformation

Trending

Most Viewed

Loading...