Threat Database Trojans Trojan.Incodboot

Trojan.Incodboot

By Domesticus in Trojans

Threat Scorecard

Popularity Rank: 23,544
Threat Level: 90 % (High)
Infected Computers: 136
First Seen: May 22, 2013
Last Seen: March 9, 2026
OS(es) Affected: Windows

Trojan.Incodboot is a Trojan that modifies the master boot record (MBR) on the infected computer system. Trojan.Incodboot permits cybercrooks to obtain remote unauthorized access and control over the compromised PC. Trojan.Incodboot may download and install more malware threats on the affected PC. Trojan.Incodboot may collect private details from victimized PC users and transmit it to a distant server. Trojan.Incodboot may propagate via malicious websites, insecure program downloads and spam email messages.

Analysis Report

General information

Family Name: Trojan.Chapak.O
Signature status: No Signature

Known Samples

MD5: 3c5e7be896de76c1c9cbf2192cb97954
SHA1: 9a99c639b06cc94df56aa2de201efbc4f066a707
SHA256: C551FDE78DAAD925B8A72BF25084DB82212DB0D7BDF15FC5685DD8C0259033CE
File Size: 2.77 MB, 2771968 bytes

Windows Portable Executable Attributes

  • File doesn't have "Rich" header
  • File doesn't have exports table
  • File doesn't have security information
  • File has TLS information
  • File is 32-bit executable
  • File is console application (IMAGE_SUBSYSTEM_WINDOWS_CUI)
  • File is either console or GUI application
  • File is Native application (NOT .NET application)
  • File is not packed
  • IMAGE_FILE_DLL is not set inside PE header (Executable)
Show More
  • IMAGE_FILE_EXECUTABLE_IMAGE is set inside PE header (Executable Image)

File Traits

  • big overlay
  • GetConsoleWindow
  • HighEntropy
  • No Version Info
  • x86

Block Information

Total Blocks: 1,945
Potentially Malicious Blocks: 107
Whitelisted Blocks: 1,539
Unknown Blocks: 299

Visual Map

0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 x x x x x x x x x x x x x x x x x x x x x x x x x x x x x x x x x x x x x x x x x x x x x x x x x x x x x x 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 x x 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 x x 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 x x 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 x ? ? ? ? ? 0 0 0 0 0 0 ? ? ? ? ? ? ? ? 0 ? ? 0 0 x ? ? 0 0 0 ? x ? x x x ? ? 0 0 0 0 0 ? ? ? ? ? ? ? ? ? ? 0 0 0 0 x ? ? 0 ? ? x ? ? 0 ? 0 ? ? ? ? ? ? x ? ? 0 0 0 0 ? ? ? 0 ? ? ? 0 0 0 ? ? 0 0 ? ? ? ? ? ? ? 0 ? ? ? ? ? 0 0 0 0 0 0 ? 0 0 ? ? 0 x 0 ? 0 x ? ? ? ? ? 0 0 0 ? ? 0 0 0 0 0 0 0 0 0 ? ? ? 0 0 0 0 ? x ? 0 ? 0 0 0 0 0 0 0 ? 0 0 ? 0 0 0 x 0 ? ? ? ? 0 ? ? 0 0 0 0 0 0 0 ? 0 ? ? ? ? ? ? ? ? ? ? ? ? ? ? 0 ? ? ? ? ? ? ? ? ? ? ? ? 0 0 0 ? 0 x ? ? 0 0 0 ? ? ? x 0 0 x ? 0 0 0 0 0 0 0 0 ? ? ? 0 ? 0 ? ? ? ? ? ? 0 ? ? 0 x 0 ? 0 ? 0 0 0 0 ? ? ? ? 0 ? 0 0 0 0 0 ? 0 0 0 0 0 0 0 0 x 0 0 x 0 0 ? ? ? 0 0 0 0 0 0 ? 0 0 0 0 0 0 0 0 0 ? ? ? 0 ? ? ? 0 0 0 ? ? 0 0 ? 0 0 0 0 ? 0 ? 0 ? 0 0 ? 0 ? 0 0 x x ? 0 ? ? 0 ? 0 ? 0 ? ? 0 ? ? 0 0 ? 0 ? ? 0 ? ? ? ? ? ? 0 ? 0 0 0 0 0 ? 0 0 ? 0 ? 0 ? 0 ? 0 0 0 0 ? 0 0 ? 0 ? 0 ? 0 ? 0 0 0 0 0 0 0 0 ? 0 0 0 0 0 0 0 0 ? ? 0 0 ? ? ? 0 0 ? 0 ? 0 ? 0 0 0 ? 0 ? 0 0 x ? 0 0 0 0 ? ? 0 ? 0 ? ? ? 0 ? 0 x ? ? 0 0 ? ? 0 ? 0 ? 0 0 ? 0 0 0 0 ? ? ? 0 ? x 0 0 0 0 0 x 0 0 x 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 ? 0 0 0 0 0 0 x x 0 0 0 0 0 x x 0 ? ? ? ? ? ? ? 0 ? ? ? 0 ? ? ? ? ? ? 0 ? ? ? 0 0 0 0 0 0 0 0 0 ? ? 0 0 ? 0 ? ? 0 0 0 0 0 0 0 ? 0 x 0 0 x 0 0 0 ? ? 0 0 ? 0 0 0 0 0 0 0 0 0 ? ? ? ? 0 ? 0 ? ? 0 0 ? 0 0 0 0 0 ? 0 ? ? ? 0 0 0 0 0 0 ? ? ? 0 ? ? ? 0 ? 0 ? ? ? 0 0 ? 0 ? x 0 ? ? x 0 ? ? ? ? ? ? ? 0 0 0 0 0 ? ? ? ? ? 0 ? 0 0 ? x x x x x 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 x 0 0 0 0 0 ? 0 0 0 x 0 x 0 0 0 0 0 0 0 0 ? 0 0 0 0 ? ? 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 x x ? 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 x 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 ? 0 0 0 0 0 0 x 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 ? x 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 1 0 1 1 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 1 0 0 0 0 0 0 0 0 0 0 1 1 1 1 1 1 1 0 0 0 0 0 0 0 0 0 0 0 0 2 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 1 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 1 1 0 0 1 1 0 0 1 0 0 0 0 0 0 0 0 0 0 0 0 0 0 1 0 0 0 1 0 0 0 0 0 0 2 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 1 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 1 1 0 0 2 0 0 0 0 0 0 0 0 0 0 0 1 0 0 0 0 0 0 0 0 0 0 0 0 0 0 1 0 0 0 0 0 0 0 0 0 1 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 1 0 0 0 1 0 0 1 0 0 0 0 0 2 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 1 1 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 2 0 0 0 0 2 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 2 0 1 0 0 0 0 2 2 0 0 2 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 2 0 0 0 0 0 2 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 2 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 2 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 2 1 0 2 2 0 0 1 1 0 1 0 1 0 1 0 0 0 0 0 0 0 0 ?
0 - Probable Safe Block
? - Unknown Block
x - Potentially Malicious Block

Files Modified

File Attributes
\device\namedpipe\gmdasllogger Generic Write,Read Attributes

Windows API Usage

Category API
Encryption Used
  • BCryptOpenAlgorithmProvider

Trending

Most Viewed

Loading...