Threat Database Trojans Trojan.Injector.GEA

Trojan.Injector.GEA

By CagedTech in Trojans

Threat Scorecard

Popularity Rank: 3,932
Threat Level: 80 % (High)
Infected Computers: 276
First Seen: March 30, 2023
Last Seen: October 24, 2025
OS(es) Affected: Windows

Analysis Report

General information

Family Name: Trojan.Injector.GEA
Packers: UPX
Signature status: No Signature

Known Samples

MD5: cf48de9bf81c5f2dcba4b47166cdcae5
SHA1: d62e3ce0f21591ca910ca4d3a2eaeb9422e5f039
SHA256: 63A477D747240F86B073EA6259129B3A939014709F3DAAF5CAF92274EF796A17
File Size: 2.20 MB, 2198072 bytes
MD5: 3c398984545b8345c2ac7fdbc2d3bb96
SHA1: 91ef5c61d165b30f9a8d7c44ca36ebaefea8777c
SHA256: 607E8A23D0EB0AFA548E578EDE94FA2427B8B19BCC2472562AF2BD93F607DF20
File Size: 2.81 MB, 2805706 bytes
MD5: 311edefcdea6cd88b6f6d6693c0faf47
SHA1: 4ffd7bb36115d10a95cca38dd0b29ca5674e4fb7
SHA256: 184059D8A8CD1ABCCAF54C8D4A52F96813F6BDA0ED100B6E39258F22732FDA3A
File Size: 81.83 KB, 81827 bytes

Windows Portable Executable Attributes

  • File doesn't have "Rich" header
  • File doesn't have debug information
  • File doesn't have exports table
  • File doesn't have relocations information
  • File doesn't have security information
  • File has been packed
  • File has TLS information
  • File is 32-bit executable
  • File is either console or GUI application
  • File is GUI application (IMAGE_SUBSYSTEM_WINDOWS_GUI)
Show More
  • File is Native application (NOT .NET application)
  • File is not packed
  • IMAGE_FILE_DLL is not set inside PE header (Executable)
  • IMAGE_FILE_EXECUTABLE_IMAGE is set inside PE header (Executable Image)

File Icons

Windows PE Version Information

Name Value
Company Name
  • Bome Software
  • Bome Software GmbH & Co. KG
Compiled Script AutoIt v3 Script: 3, 3, 6, 1
File Description
  • Restorator: Edit Resources and User Interface
  • Restorator Patcher
File Version
  • 3.9.0.1793
  • 3, 3, 6, 1
  • 1.1.0.119
Internal Name
  • ResPatcher
  • Restorator
Legal Copyright
  • (c) 1999-2007 by Bome Software
  • (c) 1999-2022 by Bome Software GmbH & Co. KG
Legal Trademarks Bome is a registered trademark of Bome Software.
Original Filename
  • ResPatcher
  • Restorator.exe
Product Name Restorator
Product Version
  • 3.9.0.0
  • 3.7.0.0
W W W http://www.bome.com/products/restorator/

Digital Signatures

Signer Root Status
Bome Software GmbH & Co.KG Symantec Class 3 SHA256 Code Signing CA Hash Mismatch
Bome Software GmbH & Co.KG VeriSign Class 3 Code Signing 2010 CA Hash Mismatch

File Traits

  • 2+ executable sections
  • packed
  • x86

Block Information

Total Blocks: 883
Potentially Malicious Blocks: 212
Whitelisted Blocks: 668
Unknown Blocks: 3

Visual Map

0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 1 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 x 0 0 0 x 0 x x 0 x 0 0 x x 0 0 x x 0 x x x 0 x x x x x x x x x x x x x x x x x x 0 x x x x 0 0 x x x x 0 x 0 0 x x x x x x 0 x 0 x 0 0 0 0 0 x x 0 x x 0 0 x 0 x 0 x x x 0 x x x 0 0 0 x x x x x x x x 0 x x 0 0 0 0 0 x 0 x x x x 0 0 x x x x 0 x 0 0 0 0 0 x x x x x 0 x x x 0 0 0 x x x 0 0 x x x 0 x x x x 0 x 0 0 0 x x x 0 x x 0 x x x 0 x 0 x 0 x x x x x 0 x x 0 x 0 x x x x 0 0 0 x x 0 x x 0 x 0 x 0 x 0 x x x 0 0 x x x x x x x x x x x x x x x 0 x x ? ? x x x x x x x x x x x x x x x x x x x x x x x x x x x ? x x x x x 0 x x 0 x x x x x x x x x x x x 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 x x 0 x 0 x x x x x x x x x x 0 x x x x x 0 0 0 0 0 x 0
0 - Probable Safe Block
? - Unknown Block
x - Potentially Malicious Block

Similar Families

  • Autoit
  • Bitcoinminer.BDA
  • Bitcoinminer.BDB
  • Bitcoinminer.DJE
  • Rugmi.T

Windows API Usage

Category API
User Data Access
  • GetUserObjectInformation
Anti Debug
  • IsDebuggerPresent
Service Control
  • OpenSCManager

Trending

Most Viewed

Loading...