Threat Database Trojans Trojan.ICLoader

Trojan.ICLoader

By CagedTech in Trojans

Threat Scorecard

Popularity Rank: 5,441
Threat Level: 80 % (High)
Infected Computers: 182,480
First Seen: January 12, 2015
Last Seen: April 15, 2026
OS(es) Affected: Windows

SpyHunter Detects & Remove Trojan.ICLoader

Directories

Trojan.ICLoader may create the following directory or directories:

%ALLUSERSPROFILE%\Application Data\WIFIService
%ALLUSERSPROFILE%\Application Data\flexgridservice
%ALLUSERSPROFILE%\WIFIService
%ALLUSERSPROFILE%\flexgridservice
%PROGRAMFILES%\adBanner
%PROGRAMFILES(x86)%\adBanner

Analysis Report

General information

Family Name: Trojan.ICLoader
Packers: UPX
Signature status: Root Not Trusted

Known Samples

MD5: 3af6e48ce973aedf0f6ac900e9af9759
SHA1: 65266a204d1bbe1a0b29ffc45dfed2060ef55222
SHA256: C3288D2FFE1F80ACD995F58878A4216C76D4930506DDA47A59F756740C358637
File Size: 421.89 KB, 421888 bytes
MD5: 18c7f0b8f79b1ebfaec8e2590ea3a66d
SHA1: 4e066e50734fb6b03241cbd5731eb56bd96d5042
SHA256: B612F9744E517B01A13FF1CEEC85174C46451033ED2748F44FDCB9C256E8B24A
File Size: 2.00 MB, 2001584 bytes
MD5: ef67831a3bce429196a78e58308f256b
SHA1: d5438eabb5bcd0d6686fd4deb5bc332f9a29b44e
SHA256: 26C75C7997C3D9C504A244C74C70DB445C4FDA2A455B6F2D5A0859F4CACE57C2
File Size: 3.67 MB, 3673272 bytes

Windows Portable Executable Attributes

  • File doesn't have "Rich" header
  • File doesn't have debug information
  • File doesn't have exports table
  • File doesn't have relocations information
  • File doesn't have resources
  • File doesn't have security information
  • File has been packed
  • File has exports table
  • File has TLS information
  • File is 32-bit executable
Show More
  • File is console application (IMAGE_SUBSYSTEM_WINDOWS_CUI)
  • File is either console or GUI application
  • File is GUI application (IMAGE_SUBSYSTEM_WINDOWS_GUI)
  • File is Native application (NOT .NET application)
  • File is not packed
  • IMAGE_FILE_DLL is not set inside PE header (Executable)
  • IMAGE_FILE_EXECUTABLE_IMAGE is set inside PE header (Executable Image)

File Icons

Digital Signatures

Signer Root Status
Torgovy Dom UKMB Ta Evropa, LLC COMODO RSA Certification Authority Root Not Trusted
FINANSINVEST, OOO COMODO RSA Code Signing CA Self Signed

Block Information

Total Blocks: 42
Potentially Malicious Blocks: 0
Whitelisted Blocks: 2
Unknown Blocks: 40

Visual Map

? ? ? ? ? ? ? ? ? ? ? ? ? ? ? ? ? ? ? ? ? ? ? ? ? ? ? ? ? ? 0 ? ? ? ? ? ? ? ? 0 ? ?
0 - Probable Safe Block
? - Unknown Block
x - Potentially Malicious Block

Windows API Usage

Category API
Syscall Use
  • ntdll.dll!NtAlpcSendWaitReceivePort
  • ntdll.dll!NtClose
  • ntdll.dll!NtCreateFile
  • ntdll.dll!NtCreateSection
  • ntdll.dll!NtFreeVirtualMemory
  • ntdll.dll!NtMapViewOfSection
  • ntdll.dll!NtOpenFile
  • ntdll.dll!NtOpenKey
  • ntdll.dll!NtOpenProcessToken
  • ntdll.dll!NtQueryAttributesFile
Show More
  • ntdll.dll!NtQueryDebugFilterState
  • ntdll.dll!NtQueryInformationProcess
  • ntdll.dll!NtQueryInformationToken
  • ntdll.dll!NtQuerySystemInformationEx
  • ntdll.dll!NtQueryValueKey
  • ntdll.dll!NtQueryVirtualMemory
  • ntdll.dll!NtQueryVolumeInformationFile
  • ntdll.dll!NtReadFile
  • ntdll.dll!NtSetEvent
  • ntdll.dll!NtSetInformationFile
  • ntdll.dll!NtSetInformationProcess
  • ntdll.dll!NtSetInformationVirtualMemory
  • ntdll.dll!NtSetInformationWorkerFactory
  • ntdll.dll!NtTestAlert
  • ntdll.dll!NtTraceControl
  • ntdll.dll!NtUnmapViewOfSection
  • ntdll.dll!NtWriteFile
Process Manipulation Evasion
  • NtUnmapViewOfSection
Process Shell Execute
  • CreateProcess
Anti Debug
  • NtQuerySystemInformation
User Data Access
  • GetComputerNameEx

Shell Command Execution

C:\WINDOWS\SysWOW64\rundll32.exe C:\WINDOWS\system32\rundll32.exe c:\users\user\downloads\4e066e50734fb6b03241cbd5731eb56bd96d5042_0002001584.,LiQMAxHB

Related Posts

Trending

Most Viewed

Loading...