Threat Database Trojans Trojan.Injector.KPQ

Trojan.Injector.KPQ

By CagedTech in Trojans

Threat Scorecard

Popularity Rank: 10,689
Threat Level: 80 % (High)
Infected Computers: 706
First Seen: October 11, 2021
Last Seen: April 4, 2026
OS(es) Affected: Windows

Analysis Report

General information

Family Name: Trojan.Injector.KPQ
Packers: ASPack v2.1
Signature status: No Signature

Known Samples

MD5: 1f64b0efe070ea462b9e0dc1b7d8e0e0
SHA1: e5ca25461e29a38ab9726ad5ff119624b23078ec
File Size: 6.00 MB, 6000213 bytes
MD5: 324e27dc5199bfab8edf41c6e3faa5aa
SHA1: 699490853942128d98b7c65523f8ecd9c2355779
SHA256: 5A1A22BDEF2B400AF532B41F7752AE69A43E82A973CB5BB3C154DE9C4052B2EA
File Size: 608.09 KB, 608094 bytes
MD5: ae16824ebb67589fb3c4b75a669c98e2
SHA1: 4442f41732dfea88a0416e8193283d789a1b5081
SHA256: 9A1408F3A6DD5D61AA70FCE338B02E23658E27DBFBF9A9C2E1A0886A4945A694
File Size: 3.39 MB, 3393807 bytes
MD5: d5ceaef76c3ce952efed49ac73b81c46
SHA1: 7e08b2b596a18e62578ac0a1a1f2a007d51d645e
SHA256: 6923CA2CFA50FBFBA1BACDF707B934064A8F38A96E5C68DB06B22CD7D5033541
File Size: 7.54 MB, 7543082 bytes
MD5: 07ea16d68ed8e0e8014c2b97a36470c6
SHA1: 465e2018660e4dc3d7743009dfa0fff1979d8505
SHA256: FE17BE8A4C9F1EC4697A495072971CD7270E2DB7F5FB89F8EEA4EEB6B1C18DAB
File Size: 1.75 MB, 1749092 bytes
Show More
MD5: c26401a4087287ffeb7f78a28723e2e8
SHA1: d37ee0a78743536ef8a90231c64f54a6ee3bf017
SHA256: 57D65A43B066447FECC7677F5DBF03CA09DDDDD98B60E00E28FED808D0860EDA
File Size: 1.80 MB, 1795611 bytes

Windows Portable Executable Attributes

  • File doesn't have "Rich" header
  • File doesn't have debug information
  • File doesn't have exports table
  • File doesn't have security information
  • File has been packed
  • File has TLS information
  • File is 32-bit executable
  • File is either console or GUI application
  • File is GUI application (IMAGE_SUBSYSTEM_WINDOWS_GUI)
  • File is Native application (NOT .NET application)
Show More
  • IMAGE_FILE_DLL is not set inside PE header (Executable)
  • IMAGE_FILE_EXECUTABLE_IMAGE is set inside PE header (Executable Image)

File Icons

Windows PE Version Information

Name Value
Comments Create Professional eBooks
Company Name Ada99.com
File Description eBook Workshop
File Version 1.4.0.0
Internal Name book.exe
Legal Copyright Copyright (C) 2002-2003 Ada99.com
Legal Trademarks $$
Original Filename book.exe
Product Name eBook Workshop
Product Version 1.4.0.0

File Traits

  • .aspack
  • ASPack v2.1
  • big overlay
  • HighEntropy
  • packed
  • x86

Block Information

Total Blocks: 2,837
Potentially Malicious Blocks: 76
Whitelisted Blocks: 2,761
Unknown Blocks: 0

Visual Map

0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 1 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 x 0 0 0 0 0 0 x x x 0 0 x x x x x x 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 x x 0 0 0 0 x x x x 0 x 0 x 0 0 x x x 0 x 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0
... Data truncated
0 - Probable Safe Block
? - Unknown Block
x - Potentially Malicious Block

Similar Families

  • Agent.XDC

Registry Modifications

Key::Value Data API Name
HKLM\software\classes\wow6432node\clsid\{e8cfc029-8420-4eae-adef-915bdc77e1dc}:: this is my ebook RegNtPreCreateKey
HKLM\software\classes\wow6432node\clsid\{e8cfc029-8420-4eae-adef-915bdc77e1dc}\localserver32:: c:\users\user\downloads\4442f41732dfea88a0416e8193283d789a1b5081_0003393807 RegNtPreCreateKey
HKLM\software\classes\4442f41732dfea88a0416e8193283d789a1b5081_0003393807.mynshandler:: this is my ebook RegNtPreCreateKey
HKLM\software\classes\4442f41732dfea88a0416e8193283d789a1b5081_0003393807.mynshandler\clsid:: {E8CFC029-8420-4EAE-ADEF-915BDC77E1DC} RegNtPreCreateKey
HKLM\software\classes\wow6432node\clsid\{e8cfc029-8420-4eae-adef-915bdc77e1dc}\progid:: 4442f41732dfea88a0416e8193283d789a1b5081_0003393807.MyNSHandler RegNtPreCreateKey
HKLM\software\classes\wow6432node\clsid\{e8cfc029-8420-4eae-adef-915bdc77e1dc}\localserver32:: c:\users\user\downloads\7e08b2b596a18e62578ac0a1a1f2a007d51d645e_0007543082 RegNtPreCreateKey
HKLM\software\classes\7e08b2b596a18e62578ac0a1a1f2a007d51d645e_0007543082.mynshandler:: this is my ebook RegNtPreCreateKey
HKLM\software\classes\7e08b2b596a18e62578ac0a1a1f2a007d51d645e_0007543082.mynshandler\clsid:: {E8CFC029-8420-4EAE-ADEF-915BDC77E1DC} RegNtPreCreateKey
HKLM\software\classes\wow6432node\clsid\{e8cfc029-8420-4eae-adef-915bdc77e1dc}\progid:: 7e08b2b596a18e62578ac0a1a1f2a007d51d645e_0007543082.MyNSHandler RegNtPreCreateKey
HKLM\software\classes\wow6432node\clsid\{e8cfc029-8420-4eae-adef-915bdc77e1dc}\localserver32:: c:\users\user\downloads\465e2018660e4dc3d7743009dfa0fff1979d8505_0001749092 RegNtPreCreateKey
Show More
HKLM\software\classes\465e2018660e4dc3d7743009dfa0fff1979d8505_0001749092.mynshandler:: this is my ebook RegNtPreCreateKey
HKLM\software\classes\465e2018660e4dc3d7743009dfa0fff1979d8505_0001749092.mynshandler\clsid:: {E8CFC029-8420-4EAE-ADEF-915BDC77E1DC} RegNtPreCreateKey
HKLM\software\classes\wow6432node\clsid\{e8cfc029-8420-4eae-adef-915bdc77e1dc}\progid:: 465e2018660e4dc3d7743009dfa0fff1979d8505_0001749092.MyNSHandler RegNtPreCreateKey
HKLM\software\classes\wow6432node\clsid\{e8cfc029-8420-4eae-adef-915bdc77e1dc}\localserver32:: c:\users\user\downloads\d37ee0a78743536ef8a90231c64f54a6ee3bf017_0001795611 RegNtPreCreateKey
HKLM\software\classes\d37ee0a78743536ef8a90231c64f54a6ee3bf017_0001795611.mynshandler:: this is my ebook RegNtPreCreateKey
HKLM\software\classes\d37ee0a78743536ef8a90231c64f54a6ee3bf017_0001795611.mynshandler\clsid:: {E8CFC029-8420-4EAE-ADEF-915BDC77E1DC} RegNtPreCreateKey
HKLM\software\classes\wow6432node\clsid\{e8cfc029-8420-4eae-adef-915bdc77e1dc}\progid:: d37ee0a78743536ef8a90231c64f54a6ee3bf017_0001795611.MyNSHandler RegNtPreCreateKey

Trending

Most Viewed

Loading...