Threat Database Trojans Trojan.Injector.SA

Trojan.Injector.SA

By CagedTech in Trojans

Threat Scorecard

Popularity Rank: 13,897
Threat Level: 80 % (High)
Infected Computers: 508
First Seen: September 19, 2012
Last Seen: April 6, 2026
OS(es) Affected: Windows

Aliases

15 security vendors flagged this file as malicious.

Antivirus Vendor Detection
Panda Trj/CI.A
McAfee-GW-Edition Artemis!58BBF30913F8
AntiVir TR/Injector.128000.2
Panda Generic Malware
AVG Dropper.Generic6.AZTN
Fortinet W32/Injector.UA!tr
Ikarus Backdoor.Win32.IRCBot
AhnLab-V3 Worm/Win32.IRCBot
AntiVir TR/Elzob.iiuoan
Comodo TrojWare.Win32.Injector.VCE
Kaspersky Trojan-Dropper.Win32.Dorifel.hmh
Avast Win32:IRCBot-EWW [Trj]
Symantec Trojan.Gen
K7AntiVirus Trojan
McAfee Artemis!8246A567A72D

File System Details

Trojan.Injector.SA may create the following file(s):
# File Name MD5 Detections
1. xknke.exe 164d671fdf419c4ad70de18645de7502 8
2. ydnfxg.exe 8246a567a72ddd416c4f41cf80743a72 3
3. cwbvlan.exe 58bbf30913f814dd19bf2edeb2e7c301 3
4. igfxdc64.exe 5dedc0f83c47c6b18b863fde093dbbf3 3

Analysis Report

General information

Family Name: Trojan.Injector.SA
Signature status: No Signature

Known Samples

MD5: 897880083bd81557b1db25caecd7b0cc
SHA1: 3a3bc26842c47b497f0a2904d57a75757879c3f0
SHA256: 6110BB3764EB2F0291B1F66B264C2F3FD6EE0A4AD110D662CEEFD0E35A1667C4
File Size: 66.05 KB, 66048 bytes
MD5: 1c637f543491664b61b918bd3985d345
SHA1: 0714f1dfd8abe5ad3e39ea7347cf705f5f175355
SHA256: ADEA0630B608B19F9159630945E76B60E340D5B72CDA477F4E8AD40E71CA702F
File Size: 4.39 MB, 4393638 bytes

Windows Portable Executable Attributes

  • File doesn't have "Rich" header
  • File doesn't have debug information
  • File doesn't have exports table
  • File doesn't have relocations information
  • File doesn't have security information
  • File has exports table
  • File has TLS information
  • File is 32-bit executable
  • File is either console or GUI application
  • File is GUI application (IMAGE_SUBSYSTEM_WINDOWS_GUI)
Show More
  • File is Native application (NOT .NET application)
  • File is not packed
  • IMAGE_FILE_DLL is not set inside PE header (Executable)
  • IMAGE_FILE_EXECUTABLE_IMAGE is set inside PE header (Executable Image)

File Icons

Windows PE Version Information

Name Value
Comments This installation was built with Inno Setup.
Company Name Softspecialists
File Description SmallUtilities
File Version 7.8.0.1
Legal Copyright © MMIX-MMXXI Roberto Bianchi
Product Name SmallUtilities
Product Version 7.8.0.1

File Traits

  • No Version Info
  • x86

Files Modified

File Attributes
c:\users\user\appdata\local\temp\is-kc084.tmp\0714f1dfd8abe5ad3e39ea7347cf705f5f175355_0004393638.tmp Generic Write,Read Attributes

Windows API Usage

Category API
Process Manipulation Evasion
  • NtUnmapViewOfSection
Process Shell Execute
  • CreateProcess
User Data Access
  • GetUserObjectInformation

Shell Command Execution

"C:\Users\Yjuuqmxr\AppData\Local\Temp\is-KC084.tmp\0714f1dfd8abe5ad3e39ea7347cf705f5f175355_0004393638.tmp" /SL5="$60308,3580364,785408,c:\users\user\downloads\0714f1dfd8abe5ad3e39ea7347cf705f5f175355_0004393638"

Trending

Most Viewed

Loading...