Threat Database Trojans Trojan.HPDefender.GA

Trojan.HPDefender.GA

By CagedTech in Trojans

Threat Scorecard

Popularity Rank: 25,154
Threat Level: 80 % (High)
Infected Computers: 6
First Seen: July 26, 2023
Last Seen: April 15, 2026
OS(es) Affected: Windows

Analysis Report

General information

Family Name: Trojan.HPDefender.GA
Signature status: No Signature

Known Samples

MD5: b97e44955644f9ee10d620617cb813c4
SHA1: fa8a60df92b05e8c1ca8a69475c6381a19beea03
SHA256: F948C51A830B33F6D0586CD547587E0EB453703B3521A4D9CE7DC3FC82ECA89C
File Size: 583.35 KB, 583349 bytes

Windows Portable Executable Attributes

  • File doesn't have "Rich" header
  • File doesn't have debug information
  • File doesn't have exports table
  • File doesn't have relocations information
  • File doesn't have security information
  • File is 32-bit executable
  • File is either console or GUI application
  • File is GUI application (IMAGE_SUBSYSTEM_WINDOWS_GUI)
  • File is Native application (NOT .NET application)
  • File is not packed
Show More
  • IMAGE_FILE_DLL is not set inside PE header (Executable)
  • IMAGE_FILE_EXECUTABLE_IMAGE is set inside PE header (Executable Image)

File Icons

Windows PE Version Information

Name Value
File Description iknew I’d had enough
File Version 35.46.95.1036
Internal Name I hung the gloves up
Legal Copyright century ago
Product Name A quarter of a
Product Version 35.46.95.1036

File Traits

  • x86

Files Modified

File Attributes
c:\users\user\appdata\local\temp\nsaa2b5.tmp\nsprocess.dll Generic Write,Read Attributes
c:\users\user\appdata\local\temp\nska2a4.tmp Generic Read,Write Data,Write Attributes,Write extended,Append data,Delete
c:\users\user\appdata\roaming\hwmonitorapp\hwmonitorapp.exe Generic Write,Read Attributes
c:\users\user\appdata\roaming\hwmonitorapp\hwmonitorapp\hwmonitor_x32.exe Generic Write,Read Attributes

Registry Modifications

Key::Value Data API Name
HKCU\software\microsoft\windows\currentversion\run::hwmonitorapp "C:\Users\Vqecyxxv\AppData\Roaming\HwmonitorApp\HwmonitorApp.exe" RegNtPreCreateKey
HKCU\software\hwmonitorapp::ynucer eyAgICAgICJ0aW1lb3V0X21pbiIgICAgICAgICAgICAgICAgICAgICAgICAgICAgICAgICAgICAgICAgICAgICAgICAgICAgICAgICAgICAgICAgICAgOiAgICAgICAg RegNtPreCreateKey
HKCU\software\hwmonitorapp\components::main 1 RegNtPreCreateKey

Windows API Usage

Category API
Anti Debug
  • IsDebuggerPresent
  • NtQuerySystemInformation
User Data Access
  • GetUserObjectInformation
Process Manipulation Evasion
  • NtUnmapViewOfSection
  • ZwMapViewOfSection
Process Shell Execute
  • CreateProcess

Shell Command Execution

"C:\Users\Vqecyxxv\AppData\Roaming\HwmonitorApp\HwmonitorApp.exe" "first_run" "c:\users\user\downloads\fa8a60df92b05e8c1ca8a69475c6381a19beea03_0000583349"
"C:\Users\Vqecyxxv\AppData\Roaming\HwmonitorApp\HwmonitorApp.exe" "write_patch_str_to_reg" "c:\users\user\downloads\fa8a60df92b05e8c1ca8a69475c6381a19beea03_0000583349" "HKCU" "Software\HwmonitorApp" "ynucer"

Trending

Most Viewed

Loading...