Threat Database Trojans Trojan Generic29.ajge

Trojan Generic29.ajge

By JubileeX in Trojans

Threat Scorecard

Popularity Rank: 3,915
Threat Level: 90 % (High)
Infected Computers: 11,020
First Seen: April 29, 2013
Last Seen: November 25, 2025
OS(es) Affected: Windows

Trojan Generic29.ajge is a dangerous Trojan horse infection that is commonly loaded on vulnerable PCs. Through Trojan Generic29.ajge the master boot record could be manipulated causing the system to perform abnormally. The use of Trojan Generic29.ajge may be take advantage of by remote hackers where they could potentially gain access to an infected computer. Data stored on a system infected with Trojan Generic29.ajge is at risk. Removal of Trojan Generic29.ajge will ensure a system is not put a risk of having stored data stolen.

Analysis Report

General information

Family Name: Trojan.Coinminer.AF
Signature status: No Signature

Known Samples

MD5: 986658d7883fb7946f15befd1d9498d9
SHA1: 2f0bfbade5d40864e706216a0041d30279686874
SHA256: 878286492CBF1393C9CFC24B3A09419E6F50FE05A9392591675F7F3571EB31C3
File Size: 3.50 MB, 3497472 bytes

Windows Portable Executable Attributes

  • File doesn't have "Rich" header
  • File doesn't have debug information
  • File doesn't have exports table
  • File doesn't have relocations information
  • File doesn't have resources
  • File doesn't have security information
  • File has TLS information
  • File is 64-bit executable
  • File is console application (IMAGE_SUBSYSTEM_WINDOWS_CUI)
  • File is either console or GUI application
Show More
  • File is Native application (NOT .NET application)
  • File is not packed
  • IMAGE_FILE_DLL is not set inside PE header (Executable)
  • IMAGE_FILE_EXECUTABLE_IMAGE is set inside PE header (Executable Image)

File Traits

  • No Version Info
  • x64

Block Information

Total Blocks: 19,639
Potentially Malicious Blocks: 1,769
Whitelisted Blocks: 17,309
Unknown Blocks: 561

Visual Map

0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 ? ? 0 ? 0 0 0 0 x 0 0 0 0 0 0 0 0 0 x 0 0 0 ? 0 0 0 0 0 ? 0 x 0 0 0 x x x 0 ? ? 0 0 ? 0 ? 0 0 x ? ? ? ? ? 0 0 x x ? 0 0 ? 0 x ? 0 0 x 0 ? 0 0 0 ? ? 0 0 0 0 0 ? x 0 0 x x 0 0 0 0 0 0 0 0 0 ? x x x 0 x 0 ? ? ? ? 0 ? 0 ? 0 x ? x 0 0 ? 0 ? 0 ? x 0 ? ? 0 ? ? ? 0 ? ? x 0 ? ? 0 0 0 0 ? 0 x 0 0 0 0 0 x ? ? ? ? 0 ? 0 ? ? x 0 ? 0 ? x 0 0 0 0 x 0 ? 0 0 0 0 0 0 0 ? ? ? 0 0 0 0 0 x ? x 0 ? 0 0 0 0 x 0 0 ? 0 0 x x x 0 0 0 0 x ? 0 ? x x x 0 0 x 0 ? x 0 x 0 ? ? 0 ? ? x ? x 0 ? ? ? 0 ? 0 ? x ? ? ? ? x 0 ? 0 0 0 0 ? ? ? 0 x ? ? ? 0 0 ? ? x ? 0 0 x x x 0 0 0 0 0 x ? ? 0 ? x ? 0 ? 0 0 0 0 x ? ? x ? 0 0 x 0 x 0 ? ? x 0 ? ? ? ? ? ? ? ? ? ? 0 ? x x ? ? ? ? ? 0 ? ? ? ? 0 ? x ? ? ? ? ? ? 0 0 ? ? ? 0 ? ? ? ? ? ? ? ? 0 ? ? ? ? 0 ? ? ? ? ? 0 0 ? ? 0 0 ? ? ? 0 0 ? ? ? ? ? 0 0 ? ? ? ? ? 0 0 ? ? ? ? ? 0 0 ? ? ? 0 0 x x ? 0 ? ? ? ? x x ? ? 0 ? ? ? ? ? ? 0 ? ? ? ? ? ? ? ? 0 ? ? ? ? ? ? 0 ? ? ? ? 0 ? ? ? ? ? ? 0 ? ? ? ? ? 0 0 ? ? ? ? ? 0 ? ? 0 ? ? ? ? ? ? 0 ? ? ? ? ? ? ? ? ? ? ? ? ? x 0 x 0 x 0 x 0 ? x ? ? x ? x 0 ? x ? 0 0 x 0 x 0 x ? x 0 0 ? ? ? x x 0 x ? ? ? ? ? ? x x 0 x x ? ? x x ? ? ? x x 0 0 x 0 0 x 0 0 x 0 0 x x x x 0 0 ? ? ? x x x x x x 0 x x 0 x x 0 x x 0 x x x x x 0 x x x 0 ? ? 0 x ? x x 0 x x 0 x x 0 x x 0 x ? ? 0 x ? 0 x ? 0 x ? 0 x ? 0 ? ? ? ? 0 x x x 0 x 0 x x ? ? ? ? ? 0 x x x 0 x 0 x x ? x ? ? x 0 0 0 x x 0 x 0 x x x x x ? ? x 0 ? x x x x 0 x 0 x x x x ? ? ? x x 0 x x 0 ? ? x ? 0 x x ? x x ? x x ? ? x ? ? x x x 0 x x x x 0 0 x x x 0 x ? x ? x 0 ? x ? x ? x x ? x 0 x ? 0 0 0 0 x ? ? ? ? 0 0 0 0 0 ? x ? 0 x ? x x 0 x x 0 x ? 0 x ? ? ? 0 0 ? 0 x ? 0 ? ? x x 0 x x 0 x x 0 x x 0 ? ? x ? ? x ? x ? ? ? ? ? x x ? x x x ? ? x ? ? ? ? x x 0 x x 0 x x 0 x x 0 ? ? ? ? ? ? ? 0 ? x x x x x x 0 x ? ? ? ? ? ? ? x x x x x x x 0 x ? 0 x ? x x x ? 0 x ? x x x x 0 0 x 0 0 0 0 0 0 ? ? x 0 ? x 0 ? ? x 0 x x ? x x ? x x ? x x ? x x x x ? 0 x 0 x 0 x ? 0 x 0 x x ? 0 x 0 ? ? ? x 0 x 0 x 0 x 0 x 0 x 0 x 0 x 0 x 0 x 0 x 0 x 0 x 0 x 0 x 0 x x x ? 0 ? ? ? ? 0 x x 0 x 0 x ? x ? ? ? ? ? 0 0 x x 0 x 0 ? 0 ? ? ? ? ? ? 0 ? x x 0 ? ? ? ? ? ? 0 ? ? 0 ? x ? x 0 ? ? ? ? ? ? ? ? x ? x 0 ? x x x ? ? ? 0 x x 0 x 0 x ? x x 0 x x 0 x 0 x ? x x x x x 0 x 0 x x x x x ? x x x 0 x 0 x ? x x x ? x x x x x 0 0 0 x x x ? ? ? ? 0 x x 0 0 0 0 0 x x x x x x 0 0 0 x 0 ? 0 x ? x ? 0 ? ? 0 ? ? x ? 0 ? ? 0 0 ? ? 0 0 0 0 0 0 0 0 0 0 ? ? 0 0 0 0 x 0 x ? x 0 0 0 0 0 0 0 0 0 0 0 ? ? ? ? ? ? ? ? ? ? ? ? x x x 0 x 0 x x 0 x 0 x x 0 x 0 ? ? ? ? ? x ? 0 ? 0 x x x 0 0 0 0 x x x 0 x ? x x x 0 x ? ? x 0 ? ? ? ? ? ? ? x ? ? ? 0 x ? x ? 0 x x x ? ? ? x ? ? ? ? ? ? x ? 0 0 0 x x x x x x x x x ? ? ? ? ? x x x ? x 0 0 x x x x x x x 0 0 x x 0 0 0 ? ? 0 ? ? x 0 x ? ? x 0 x ? ? x 0 x ? ? ? x x ? 0 x x x x ? x ? x ? 0 ? 0 ? 0 0 ? ? x x x 0 0 x x 0 0 0 0 0 0 0 ? ? x x x x x 0 0 x 0 0 x x x x x x x x x x x x 0 x 0 0 x x x 0 x x x x x x x x x x x 0 0 x 0 0 0 x x 0 x 0 0 x x 0 x x x x x x x x x 0 x x x x x x x 0 0 x x x x x x x 0 x x x x x x x x x x x 0 x x x x x 0 x x x x x x x x x x x x x x x 0 x x x x x x 0 0 0 x x x x x x x x x x x x x x x x x 0 0 x x x 0 0 0 0 x 0 x x x x x 0 0 0 x x x x x x x x 0 x x x x x x x x x x x 0 0 0 0 0 x x x x 0 0 x x x x x 0 0 0 x x 0 0 x x x x x x x x x x 0 0 0 0 x 0 0 x x x x x x x x x 0 x x 0 0 x 0 0 x 0 0 0 x 0 x x x x 0 x 0 x x x 0 x 0 x x 0 x x 0 x 0 x 0 0 0 x x x x x x x x x x x x x x x x x 0 x x x x x 0 x x x x x x x x x x x x 0 0 x x 0 x x 0 0 0 x x 0 0 0 x x 0 x x 0 0 0 x 0 0 x 0 x x x x 0 x 0 0 0 x x x x x x x 0 0 x x 0 x x x x x x 0 0 0 x x x x x x x x x x 0 0 0 x x x x x x 0 x x x x x x x x x x x x x x 0 x x x x x 0 0 x x x x x x x x x x x x x x 0 x x x x x x x x x x x x x x x x x x x x x x x x x x x x x x x x x x x x x x x x x x x 0 x 0 0 x 0 x 0 x 0 x x x x 0 0 x x x x x x 0 0 x 0 0 0 x 0 x x 0 0 0 x x x x 0 x x 0 0 x x 0 x x x 0 x x 0 0 x 0 x x x x 0 0 x 0 x x 0 0 0 0 0 0 x x x x 0 0 x x 0 x x x 0 x 0 0 0 0 0 x x x x 0 0 0 0 0 0 x x 0 0 x x x x x x x x x x x 0 0 x x x x x x x x x x 0 0 0 x 0 0 x x x x x x x x x x x x x x x x x x x x x x x x x x 0 0 x x x x x x x x x x x x x x x x 0 x x x x x x x x x x x x x x x x x x x x 0 x 0 x 0 x x x x 0 0 0 0 0 x x x 0 x x 0 0 0 x 0 x x 0 x x 0 0 x 0 0 x 0 0 x 0 x x x x x x x 0 x x x x x x 0 x x 0 0 0 0 x x x 0 0 0 x x x x x x x x x x x x x x x x x x x x x x x x 0 x x x x x x x x x x x x x x x
... Data truncated
0 - Probable Safe Block
? - Unknown Block
x - Potentially Malicious Block

Similar Families

  • Bitcoinminer.CB

Windows API Usage

Category API
Syscall Use
  • ntdll.dll!NtClose
  • ntdll.dll!NtCreateEvent
  • ntdll.dll!NtFreeVirtualMemory
  • ntdll.dll!NtOpenKey
  • ntdll.dll!NtOpenKeyEx
  • ntdll.dll!NtQueryInformationProcess
  • ntdll.dll!NtQueryKey
  • ntdll.dll!NtQueryLicenseValue
  • ntdll.dll!NtQuerySystemInformation
  • ntdll.dll!NtQueryValueKey
Show More
  • ntdll.dll!NtQueryVirtualMemory
  • ntdll.dll!NtSetEvent
  • ntdll.dll!NtSetInformationThread
  • ntdll.dll!NtSetInformationVirtualMemory
  • ntdll.dll!NtSetInformationWorkerFactory
  • ntdll.dll!NtTerminateProcess
  • ntdll.dll!NtTestAlert
  • ntdll.dll!NtTraceControl
  • ntdll.dll!NtWriteFile
  • UNKNOWN

Trending

Most Viewed

Loading...