Threat Database Trojans Trojan.Juched.B

Trojan.Juched.B

By CagedTech in Trojans

Threat Scorecard

Popularity Rank: 15,011
Threat Level: 80 % (High)
Infected Computers: 43
First Seen: March 19, 2025
Last Seen: July 6, 2026
OS(es) Affected: Windows

The detection of Trojan.Juched.B on your system indicates a potential security threat that requires immediate attention. This report provides an overview of the threat, its operating methods, symptoms of infection, and guidance on how to remove it from your computer.

What Is Trojan.Juched.B?

Trojan.Juched.B is a type of malware that can compromise the security and integrity of your computer system. The term "Trojan" refers to a broad category of malicious software that disguises itself as legitimate to gain unauthorized access to a computer. Once inside, it can perform a variety of harmful actions, depending on its specific design and the intentions of its creators. Understanding the nature of Trojan.Juched.B is crucial for taking appropriate measures to protect your system and data.

How Trojan.Juched.B Operates

Trojan.Juched.B, like other Trojans, operates by deceiving users into installing it on their systems. This can happen through various means, such as opening malicious email attachments, downloading infected software, or visiting compromised websites. Once installed, it can create backdoors for remote access, allowing attackers to control the infected computer, steal sensitive information, or use the computer as part of a botnet for malicious activities. The exact operation of Trojan.Juched.B can vary, but its primary goal is to remain hidden while exploiting the system for malicious purposes.

Symptoms of Infection

Identifying a Trojan infection can be challenging due to its stealthy nature. However, there are several symptoms that may indicate the presence of Trojan.Juched.B or similar malware on your system. These include unexpected changes in system performance, such as slow operation, frequent crashes, or unusual network activity. You might also notice new, unfamiliar programs or icons on your desktop, or find that your web browser's homepage has been changed without your consent. Additionally, if you're experiencing issues with your antivirus software or if it's been disabled mysteriously, it could be a sign of a Trojan infection.

How to Remove Trojan.Juched.B

  1. Enter Safe Mode with Networking to prevent the malware from loading and to allow for a clean environment to perform removal steps.
  2. Conduct a full scan of your system using a reputable anti-malware tool, such as SpyHunter, to detect and remove all traces of the malware.
  3. Uninstall suspicious programs that you don't recognize or that were installed around the time you suspect the infection occurred.
  4. Reset your web browsers, including Chrome, Firefox, and Edge, to their default settings to remove any malicious extensions or settings changes made by the Trojan.
  5. Reboot your computer and perform another scan with your anti-malware tool to ensure that the system is clean and the malware has been successfully removed.

Conclusion

Removing Trojan.Juched.B from your system requires careful and thorough action to ensure all components of the malware are eliminated. It's also crucial to take preventive measures to avoid future infections, such as keeping your operating system and software up to date, using strong antivirus protection, and being cautious when opening emails or downloading files from the internet. By understanding the threat posed by Trojan.Juched.B and following the removal steps outlined, you can protect your computer and personal data from this and similar threats.

Analysis Report

General information

Family Name: Trojan.Juched.B
Signature status: Hash Mismatch

Known Samples

MD5: 780533d8d52c2fd75476a800b096ea44
SHA1: e47a281e668072c43c99d70a2ce2fad182639952
File Size: 2.08 MB, 2075381 bytes
MD5: e40574342ac5cc586651ed939fc44fc0
SHA1: 39ba323c80e4a24d4682e44d6a217d5bef432505
File Size: 1.97 MB, 1971227 bytes
MD5: 4d38b292e41278e5b7501433e1dda6a3
SHA1: 93e631c4dd4c3ddad46e68effe17e551b197f783
SHA256: 084E1B08D487BA2D6906570235C841DEC1CBE52E53DEC0838B2BCF26F2883FA0
File Size: 2.04 MB, 2043232 bytes
MD5: 1488f1b1d6d5f92a547ccb99218ef41a
SHA1: 615104d59f1fd7a63726727d8acd383e7d433d6a
SHA256: 72D06D7A549CE49773E503ADD3D90840BB45EC2BE441A9D00616D2F252E127C7
File Size: 1.90 MB, 1898538 bytes
MD5: 4a62a9411a1af091a10ccc5e65c77a09
SHA1: 8b95ec2f1f1f497bbe557f60ac39b10b10ceec78
SHA256: D0AC9E2C24C61D74036909DDC68F8600A55828FFC68E0B6090E941DEA7E17199
File Size: 2.05 MB, 2052731 bytes
Show More
MD5: 242cdee847f866ae402cc67524b85142
SHA1: 211d2a34f4d7d0ee35fb35a4fcf8a82a44f0f7d3
SHA256: 7AA26E24050F4B42423291A876948A5C0BDF63A5406C6F0ABAC4C8B6C99E0C68
File Size: 2.08 MB, 2075919 bytes
MD5: e310e1c62f201358943a1f53248a5e86
SHA1: ffc35d6327a5a31a1c79495b79d92fccd2344072
SHA256: 0248407EFEBD59532332007B54C3C3127E834B7490446E1B761C3B31DD2E0E5D
File Size: 2.05 MB, 2052121 bytes
MD5: 120232243aa5fde1b7ca488fdca950e8
SHA1: 38ef19b8c9c1cad4646a3721f604ab3e64e7613a
SHA256: DF524BE1E9BF9EB23B568DCDED635106CC11BE511DB0469F24251C75D13DE2EC
File Size: 2.04 MB, 2041439 bytes
MD5: e7650a6fc0cb60ff2e6f4192923ad507
SHA1: 098af5d808932fc4702bb4bc5acf171522388567
SHA256: D155E7708AC3EF19AA6D7457A504407CADCF7835C57715C66416349035DA6BAA
File Size: 1.97 MB, 1971227 bytes
MD5: 425aaa89fb2c1b3527705b753b942696
SHA1: b24613deab412fc6825dba1aefaa162036740971
SHA256: 8E1470998FACD1B816ECF127BDFEFCE321A0624D40B566E185A6D865385C0182
File Size: 2.08 MB, 2075963 bytes
MD5: 0a1a64e09fff4f5b6ff86953da024643
SHA1: 0d0ad92f1e99702715783d5d65fafe25b1f95d41
SHA256: 62D0E33286E481948BB784DE076B04DDBF75A915124522F6C9EAF72495276268
File Size: 2.04 MB, 2043232 bytes
MD5: 07445b9cb73b5bb1c6e842a8893538fb
SHA1: 4907244ae0aefdeaff9dabe065c817f3ff7ab4df
SHA256: A792FE8FB2E28C5092DB33579980089D674DA280021803CBBB1FA61DE2974517
File Size: 1.91 MB, 1911940 bytes
MD5: c5749f654f9747fe57db741a3bc1d5fe
SHA1: 99ab7cb3aba382bbfc6d4acc611c868991dbdbee
SHA256: 602A90BBEB0F4DAFE8187D2E8DF1A736AC37D03E2EC7D71184DA5EF00197AACD
File Size: 1.97 MB, 1971226 bytes
MD5: ef78e4054aaba3f1b39de36e446b7473
SHA1: 475aac4296c41871141f1ea8ebc20aaa964d0a86
SHA256: 7B92EA2589099F1788B58EB35B6946A53C3C799EE6E104B9EFF8C4D46DEF63EF
File Size: 1.89 MB, 1890410 bytes
MD5: 02fbc59665db9997edf592ed6591e3e4
SHA1: 27d282bfbe289a7c4ba1b8859f05d75d73e74978
SHA256: 2A5C9EDC7AD52BEEBD332D4E8B46111FC6D906F5DD756C25404579E9DBD5D1A2
File Size: 2.05 MB, 2052690 bytes
MD5: 937e12cee747a8d80d2df58b8de48b88
SHA1: a3f7987e8d3ee863fc3e0f4fd6784befcf172840
SHA256: 8C5F642ABC6E9D38D04CFA9B6066DD58CF5F793B2E4D735BEA78F743C7FE4E89
File Size: 2.45 MB, 2446580 bytes
MD5: a7cda329d62b4f77f68e4ca673ae221c
SHA1: 34760a59ecc033ef5e97d45cc953291a24c1618c
SHA256: 24474636C97AAB5CEF1BB38EBED96402604540C581F25CB121EC8771583F59C8
File Size: 1.91 MB, 1911902 bytes
MD5: a78b66f328910f32d68375347d66d161
SHA1: 45d32f15300d216536528f5ef1fe30b67939cbef
SHA256: C5A4AE2A81CEE16D2A63F44B1D6C778767FA8952E4AF772A2988D9CF72CE9681
File Size: 1.96 MB, 1962336 bytes

Windows Portable Executable Attributes

  • File doesn't have "Rich" header
  • File doesn't have debug information
  • File doesn't have exports table
  • File doesn't have relocations information
  • File doesn't have security information
  • File is 32-bit executable
  • File is either console or GUI application
  • File is GUI application (IMAGE_SUBSYSTEM_WINDOWS_GUI)
  • File is Native application (NOT .NET application)
  • File is not packed
Show More
  • IMAGE_FILE_DLL is not set inside PE header (Executable)
  • IMAGE_FILE_EXECUTABLE_IMAGE is set inside PE header (Executable Image)

File Icons

Windows PE Version Information

Name Value
Company Name
  • Microsoft
  • Oracle Corporation
File Description Java Platform SE binary
File Version
  • 8.0.2310.11
  • 8.0.2210.11
  • 8.0.2110.12
  • 8.0.2010.9
  • 8.0.1910.12
  • 8.0.1810.13
  • 8.0.1710.11
  • 1.00
Full Version
  • 1.8.0_231-b11
  • 1.8.0_221-b11
  • 1.8.0_211-b12
  • 1.8.0_201-b09
  • 1.8.0_191-b12
  • 1.8.0_181-b13
  • 1.8.0_171-b11
Internal Name
  • Setup Launcher
  • TJprojMain
  • Win
Legal Copyright
  • Copyright © 2018
  • Copyright © 2019
Original Filename
  • JavaSetup8u181.exe
  • jre-8u181-windows-i586-iftw.exe
  • jxpiinstall-8u171-fcs-bin-b11-windows-i586-28_mar_2018.exe
  • online_wrapper-cab.exe
  • online_wrapper-jchrome.exe
  • online_wrapper-jxpi.exe
  • TJprojMain.exe
  • Win.exe
Product Name
  • Java Platform SE 8 U171
  • Java Platform SE 8 U181
  • Java Platform SE 8 U191
  • Java Platform SE 8 U201
  • Java Platform SE 8 U211
  • Java Platform SE 8 U221
  • Java Platform SE 8 U231
  • Project1
  • Win
Product Version
  • 8.0.2310.11
  • 8.0.2210.11
  • 8.0.2110.12
  • 8.0.2010.9
  • 8.0.1910.12
  • 8.0.1810.13
  • 8.0.1710.11
  • 1.00

Digital Signatures

Signer Root Status
Oracle America, Inc. Symantec Class 3 SHA256 Code Signing CA Hash Mismatch

File Traits

  • HighEntropy
  • Installer Version
  • x86

Block Information

Total Blocks: 3,818
Potentially Malicious Blocks: 239
Whitelisted Blocks: 3,536
Unknown Blocks: 43

Visual Map

0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 x x 0 0 0 0 x 0 x 0 x x x 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 x 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 x 0 x x x x 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 x x 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 x 0 0 0 x 0 0 0 x x x x x x x 0 x x x x x 0 x x 0 0 0 0 x x x x x 0 0 x x x 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 x 0 0 0 0 x 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 x x 0 0 x x 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 x 0 x 0 0 0 0 0 0 0 1 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 1 0 0 0 0 0 1 0 0 0 0 0 0 0 0 1 0 0 1 0 1 1 1 1 2 0 1 1 0 1 0 0 0 0 0 1 0 0 0 0 0 0 0 0 0 0 0 1 0 0 1 1 0 1 1 1 0 1 0 0 0 0 1 1 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 1 0 0 0 1 0 0 0 0 0 0 1 0 0 0 1 0 0 0 1 0 0 0 0 0 0 1 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 1 0 0 0 0 0 0 0 0 0 1 1 1 0 3 1 1 0 0 0 0 0 0 0 0 0 0 0 0 0 1 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 1 1 0 0 1 0 0 1 0 0 0 0 0 0 1 0 0 0 0 0 0 0 0 1 0 0 0 0 0 0 0 0 0 0 0 1 0 1 1 0 0 0 0 1 0 0 0 0 0 0 0 0 0 0 0 2 2 2 3 0 0 0 0 0 0 1 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 1 0 0 1 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 2 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 1 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 1 0 0 0 0 1 1 0 0 1 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 1 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 1 0 0 0 0 0 0 0 0 0 0 1 0 0 0 0 0 0 ? ? ? ? ? ? ? ? ? 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 x 0 0 x 0 0 x x x ? x 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 x 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 x 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 x x 0 0 0 x x x 0 0 x 0 x x x x x x x x x 0 x x x x 0 0 0 0 0 0 0 x 0 0 0 x 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 ? 0 x 0 0 0 x 0 0 0 0 0 0 0 0 0 0 x 0 x 0 x x 0 0 0 0 0 x x x 0 0 0 0 0 x 0 0 0 0 0 0 0 x x ? ? 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 x 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 x 0 0 0 0 0 0 0 x x 0 0 x 0 0 0 0 x x x x 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 x 0 0 0 0 0 0 0 0 0 0 0 x 0 0 0 0 0 x 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 x x x 0 x x x 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 x 0 x 0 0 0 0 0 0 0 0 0 x 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 x x x x 0 x x 0 0 ? ? x 0 x x 0 0 ? 0 x x x ? 0 x x 0 0 0 x 0 0 x 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 x 0 x 0 x 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 x 0 0 0 0 0 0 0 0 0 0 0 0 0 x 0 0 0 0 0 0 x 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 x 0 0 0 0 0 0 0 0 x 0 x 0 0 0 0 0 x 0 0 0 0 0 0 0 x x 0 0 0 0 0 0 0 0 0 0 x 0 x 0 0 0 x 0 0 0 x 0 0 0 0 0 0 0 0 0 0 0 0 0 x x 0 0 0 0 0 0 0 x 0 0 0 x 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 x x 0 0 0 0 0 0 x x 0 0 0 x 0 x x x x x 0 0 x x 0 x x x 0 x 0 0 x 0 0 x x x x 0 x x x x x 0 0 0 0 0 0 0 0 0 0 0 x 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 x 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 x x x 0 0 0 0 0 0 0 x 0 0 0 0 0 0 0 x 0 0 0 0 0 0 0 0 0 0 0 x 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 x 0 0 0 x 0 0 x x x 0 x 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 x 0 0 0 0 0 x 0 0 0 0 0 0 0 x x x 0 0 0 0 0 x x x x x x x x x x x 0 0 x 0 x x x x 0 0 0 0 0 0 x x 0 0 0 0 0 x 0 0 0 0 0 0 0 0 0 0 0 0 0 0 x 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 x 0 0 x 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 x 0 x x x 0 0 0 0 0 0 0 0 0 0 ? 0 0 x 0 0 0 0 x x 0 ? ? ? ? ? ? ? ? ? ? ? ? ? ? ? ? ? ? ? ? ? ? x 0 0 0 0
... Data truncated
0 - Probable Safe Block
? - Unknown Block
x - Potentially Malicious Block

Similar Families

  • Juched.B

Files Modified

File Attributes
c:\users\user\appdata\local\temp\jds1822171.tmp Generic Write,Read Attributes
c:\users\user\appdata\local\temp\jds1822171.tmp\4907244ae0aefdeaff9dabe065c817f3ff7ab4df_0001911940 Synchronize,Write Data
c:\users\user\appdata\local\temp\jds1822171.tmp\jds1822171.tmp Generic Write,Read Attributes
c:\users\user\appdata\local\temp\jds19265.tmp Generic Write,Read Attributes
c:\users\user\appdata\local\temp\jds19265.tmp\8b95ec2f1f1f497bbe557f60ac39b10b10ceec78_0002052731 Synchronize,Write Data
c:\users\user\appdata\local\temp\jds19265.tmp\jds19562.tmp Generic Write,Read Attributes
c:\users\user\appdata\local\temp\jds2124140.tmp Generic Write,Read Attributes
c:\users\user\appdata\local\temp\jds2124140.tmp\e47a281e668072c43c99d70a2ce2fad182639952_0002075381.exe Synchronize,Write Data
c:\users\user\appdata\local\temp\jds2124140.tmp\jds2124156.tmp Generic Write,Read Attributes
c:\users\user\appdata\local\temp\jds2370890.tmp Generic Write,Read Attributes
Show More
c:\users\user\appdata\local\temp\jds2370890.tmp\0d0ad92f1e99702715783d5d65fafe25b1f95d41_0002043232 Synchronize,Write Data
c:\users\user\appdata\local\temp\jds2370890.tmp\jds2370890.tmp Generic Write,Read Attributes
c:\users\user\appdata\local\temp\jds2926187.tmp Generic Write,Read Attributes
c:\users\user\appdata\local\temp\jds2926187.tmp\27d282bfbe289a7c4ba1b8859f05d75d73e74978_0002052690 Synchronize,Write Data
c:\users\user\appdata\local\temp\jds2926187.tmp\jds2926203.tmp Generic Write,Read Attributes
c:\users\user\appdata\local\temp\jds3154062.tmp Generic Write,Read Attributes
c:\users\user\appdata\local\temp\jds3154062.tmp\475aac4296c41871141f1ea8ebc20aaa964d0a86_0001890410 Synchronize,Write Data
c:\users\user\appdata\local\temp\jds3154062.tmp\jds3154078.tmp Generic Write,Read Attributes
c:\users\user\appdata\local\temp\jds322968.tmp Generic Write,Read Attributes
c:\users\user\appdata\local\temp\jds322968.tmp\39ba323c80e4a24d4682e44d6a217d5bef432505_0001971227.exe Synchronize,Write Data
c:\users\user\appdata\local\temp\jds322968.tmp\jds322984.tmp Generic Write,Read Attributes
c:\users\user\appdata\local\temp\jds3330031.tmp Generic Write,Read Attributes
c:\users\user\appdata\local\temp\jds3330031.tmp\ffc35d6327a5a31a1c79495b79d92fccd2344072_0002052121 Synchronize,Write Data
c:\users\user\appdata\local\temp\jds3330031.tmp\jds3330046.tmp Generic Write,Read Attributes
c:\users\user\appdata\local\temp\jds3564703.tmp Generic Write,Read Attributes
c:\users\user\appdata\local\temp\jds3564703.tmp\615104d59f1fd7a63726727d8acd383e7d433d6a_0001898538 Synchronize,Write Data
c:\users\user\appdata\local\temp\jds3564703.tmp\jds3564703.tmp Generic Write,Read Attributes
c:\users\user\appdata\local\temp\jds7139312.tmp Generic Write,Read Attributes
c:\users\user\appdata\local\temp\jds7139312.tmp\34760a59ecc033ef5e97d45cc953291a24c1618c_0001911902 Synchronize,Write Data
c:\users\user\appdata\local\temp\jds7139312.tmp\jds7139328.tmp Generic Write,Read Attributes
c:\users\user\appdata\local\temp\jds7684671.tmp Generic Write,Read Attributes
c:\users\user\appdata\local\temp\jds7684671.tmp\99ab7cb3aba382bbfc6d4acc611c868991dbdbee_0001971226 Synchronize,Write Data
c:\users\user\appdata\local\temp\jds7684671.tmp\jds7684687.tmp Generic Write,Read Attributes
c:\users\user\appdata\local\temp\jds81921.tmp Generic Write,Read Attributes
c:\users\user\appdata\local\temp\jds81921.tmp\211d2a34f4d7d0ee35fb35a4fcf8a82a44f0f7d3_0002075919 Synchronize,Write Data
c:\users\user\appdata\local\temp\jds81921.tmp\jds81937.tmp Generic Write,Read Attributes
c:\users\user\appdata\local\temp\jds82703.tmp Generic Write,Read Attributes
c:\users\user\appdata\local\temp\jds82703.tmp\098af5d808932fc4702bb4bc5acf171522388567_0001971227 Synchronize,Write Data
c:\users\user\appdata\local\temp\jds82703.tmp\jds82703.tmp Generic Write,Read Attributes
c:\users\user\appdata\local\temp\jds8413687.tmp Generic Write,Read Attributes
c:\users\user\appdata\local\temp\jds8413687.tmp\45d32f15300d216536528f5ef1fe30b67939cbef_0001962336 Synchronize,Write Data
c:\users\user\appdata\local\temp\jds8413687.tmp\jds8413703.tmp Generic Write,Read Attributes
c:\users\user\appdata\local\temp\jds93093.tmp Generic Write,Read Attributes
c:\users\user\appdata\local\temp\jds93093.tmp\b24613deab412fc6825dba1aefaa162036740971_0002075963 Synchronize,Write Data
c:\users\user\appdata\local\temp\jds93093.tmp\jds93109.tmp Generic Write,Read Attributes
c:\users\user\appdata\local\temp\jusched.log Generic Write,Read Attributes
c:\users\user\appdata\locallow\oracle\java\java_install_flag Generic Read,Write Data,Write Attributes,Write extended,Append data,Delete
c:\windows\65f0bd Generic Write,Read Attributes

Registry Modifications

Key::Value Data API Name
HKCU\software\microsoft\windows\currentversion\explorer\advanced::hidden  RegNtPreCreateKey
HKLM\software\wow6432node\microsoft\security center::antivirusoverride  RegNtPreCreateKey
HKLM\software\wow6432node\microsoft\security center::antivirusdisablenotify  RegNtPreCreateKey
HKLM\software\wow6432node\microsoft\security center::firewalldisablenotify  RegNtPreCreateKey
HKLM\software\wow6432node\microsoft\security center::firewalloverride  RegNtPreCreateKey
HKLM\software\wow6432node\microsoft\security center::updatesdisablenotify  RegNtPreCreateKey
HKLM\software\wow6432node\microsoft\security center::uacdisablenotify  RegNtPreCreateKey
HKLM\software\wow6432node\microsoft\security center\svc::antivirusoverride  RegNtPreCreateKey
HKLM\software\wow6432node\microsoft\security center\svc::antivirusdisablenotify  RegNtPreCreateKey
HKLM\software\wow6432node\microsoft\security center\svc::firewalldisablenotify  RegNtPreCreateKey
Show More
HKLM\software\wow6432node\microsoft\security center\svc::firewalloverride  RegNtPreCreateKey
HKLM\software\wow6432node\microsoft\security center\svc::updatesdisablenotify  RegNtPreCreateKey
HKLM\software\wow6432node\microsoft\security center\svc::uacdisablenotify  RegNtPreCreateKey
HKCU\software\microsoft\windows\currentversion\internet settings::globaluseroffline RegNtPreCreateKey
HKLM\software\microsoft\windows\currentversion\policies\system::enablelua RegNtPreCreateKey
HKLM\system\controlset001\services\sharedaccess\parameters\firewallpolicy\standardprofile::enablefirewall RegNtPreCreateKey
HKLM\system\controlset001\services\sharedaccess\parameters\firewallpolicy\standardprofile::donotallowexceptions RegNtPreCreateKey
HKLM\system\controlset001\services\sharedaccess\parameters\firewallpolicy\standardprofile::disablenotifications  RegNtPreCreateKey
HKCU\software\qnco\6f318400::4f76fefc_ RegNtPreCreateKey
HKCU\software\qnco\6f318400::30a399d9_ 韂 RegNtPreCreateKey
HKCU\software\qnco\6f318400::f_52a2f6f ⠃ࢬ RegNtPreCreateKey
HKCU\software\qnco\6f318400::10_3b47de74 耒㧵 RegNtPreCreateKey
HKCU\software\qnco\6f318400::14_4f338648 : RegNtPreCreateKey
HKCU\software\qnco\6f318400::15_4f338648 㠔つ RegNtPreCreateKey
HKCU\software\qnco\6f318400::1c_36f75301 ꀚ襥 RegNtPreCreateKey
HKCU\software\qnco\6f318400::24_da2e906e 䀀虃 RegNtPreCreateKey
HKCU\software\qnco\6f318400::25_da2e906e 退댑 RegNtPreCreateKey
HKCU\software\qnco\6f318400::26_d640d89a ��� RegNtPreCreateKey
HKCU\software\qnco\6f318400::20_d4e9acec RegNtPreCreateKey
HKCU\software\qnco\6f318400::21_94d7cd82 塊翔 RegNtPreCreateKey
HKCU\software\qnco\6f318400::17_f7cdf346 鋶 RegNtPreCreateKey
HKCU\software\qnco::11_0 㣊ם RegNtPreCreateKey
HKCU\software\qnco::12_0 RegNtPreCreateKey
HKCU\software\qnco::13_0 権ă RegNtPreCreateKey
HKCU\software\qnco::14_0 RegNtPreCreateKey
HKCU\software\qnco::11_1 ��� RegNtPreCreateKey
HKCU\software\qnco::12_1 ጳ㘲 RegNtPreCreateKey
HKCU\software\qnco::13_1 夘㜱 RegNtPreCreateKey
HKCU\software\qnco\6f318400::19_31520a8a 頋 RegNtPreCreateKey
HKCU\software\qnco::14_1 ㌱㘲 RegNtPreCreateKey
HKCU\software\qnco::11_2 蔟첻 RegNtPreCreateKey
HKCU\software\qnco::12_2 竘汤 RegNtPreCreateKey
HKCU\software\qnco::13_2 ో浧 RegNtPreCreateKey
HKCU\software\qnco::14_2 晢汤 RegNtPreCreateKey
HKCU\software\qnco::11_3 �I_� RegNtPreCreateKey
HKCU\software\qnco::12_3 뼻ꊖ RegNtPreCreateKey
HKCU\software\qnco::13_3 ꎕ RegNtPreCreateKey
HKCU\software\qnco::14_3 馓ꊖ RegNtPreCreateKey
HKCU\software\qnco::11_4 ཱྀ⑐ RegNtPreCreateKey
HKCU\software\qnco::12_4 ��� RegNtPreCreateKey
HKCU\software\qnco::13_4 ��� RegNtPreCreateKey
HKCU\software\qnco::14_4 ���� RegNtPreCreateKey
HKCU\software\qnco::11_5 鬥ﻠ RegNtPreCreateKey
HKCU\software\qnco::12_5 ໺ RegNtPreCreateKey
HKCU\software\qnco::13_5 關࿹ RegNtPreCreateKey
HKCU\software\qnco::14_5 ￵໺ RegNtPreCreateKey
HKCU\software\qnco::11_6 㩹횈 RegNtPreCreateKey
HKCU\software\qnco::12_6 ⯐䔭 RegNtPreCreateKey
HKCU\software\qnco::13_6 夏䐮 RegNtPreCreateKey
HKCU\software\qnco::14_6 ㌦䔭 RegNtPreCreateKey
HKCU\software\qnco::11_7 缰絘 RegNtPreCreateKey
HKCU\software\qnco::12_7 牿筟 RegNtPreCreateKey
HKCU\software\qnco::13_7 ౾穜 RegNtPreCreateKey
HKCU\software\qnco::14_7 晗筟 RegNtPreCreateKey
HKCU\software\qnco::11_8 䫗묹 RegNtPreCreateKey
HKCU\software\qnco::12_8 酋놑 RegNtPreCreateKey
HKCU\software\qnco::13_8 낒 RegNtPreCreateKey
HKCU\software\qnco::14_8 馈놑 RegNtPreCreateKey
HKCU\software\qnco::11_9 ꠿퐩 RegNtPreCreateKey
HKCU\software\qnco::12_9 f��� RegNtPreCreateKey
HKCU\software\qnco::13_9 Ꚑ RegNtPreCreateKey
HKCU\software\qnco::14_9 첹 RegNtPreCreateKey
HKCU\software\qnco::11_10 竔者 RegNtPreCreateKey
HKCU\software\qnco::12_10 ᷵ RegNtPreCreateKey
HKCU\software\qnco::13_10 闃ᳶ RegNtPreCreateKey
HKCU\software\qnco::14_10 ↑᷵ RegNtPreCreateKey
HKCU\software\qnco::11_11 쟒 RegNtPreCreateKey
HKCU\software\qnco::12_11 ⒞吨 RegNtPreCreateKey
HKCU\software\qnco::13_11 夲唫 RegNtPreCreateKey
HKCU\software\qnco::14_11 ㌛吨 RegNtPreCreateKey
HKCU\software\qnco::11_12 ゖ RegNtPreCreateKey
HKCU\software\qnco::12_12 磐詚 RegNtPreCreateKey
HKCU\software\qnco::13_12 ౥譙 RegNtPreCreateKey
HKCU\software\qnco::14_12 晌詚 RegNtPreCreateKey
HKCU\software\qnco::11_13 ﮵贅 RegNtPreCreateKey
HKCU\software\qnco::12_13 鞟삌 RegNtPreCreateKey
HKCU\software\qnco::13_13 솏 RegNtPreCreateKey
HKCU\software\qnco::14_13 饽삌 RegNtPreCreateKey
HKCU\software\qnco::11_14 ��v� RegNtPreCreateKey
HKCU\software\qnco::12_14  RegNtPreCreateKey
HKCU\software\qnco::13_14 ꚇ RegNtPreCreateKey
HKCU\software\qnco::14_14 첮 RegNtPreCreateKey
HKCU\software\qnco::11_15 Ⱊ黯 RegNtPreCreateKey
HKCU\software\qnco::12_15 ���, RegNtPreCreateKey
HKCU\software\qnco::13_15 闶ⷳ RegNtPreCreateKey
HKCU\software\qnco::14_15 ￟⳰ RegNtPreCreateKey
HKCU\software\qnco::11_16 鵦ᬦ RegNtPreCreateKey
HKCU\software\qnco::12_16 ⫍挣 RegNtPreCreateKey
HKCU\software\qnco::13_16 夹戠 RegNtPreCreateKey
HKCU\software\qnco::14_16 ㌐挣 RegNtPreCreateKey
HKCU\software\qnco::11_17 軅煞 RegNtPreCreateKey
HKCU\software\qnco::12_17 槳饕 RegNtPreCreateKey
HKCU\software\qnco::13_17 ౨顖 RegNtPreCreateKey
HKCU\software\qnco::14_17 晁饕 RegNtPreCreateKey
HKCU\software\qnco::11_18 ꓄粗 RegNtPreCreateKey
HKCU\software\qnco::12_18 訳쾇 RegNtPreCreateKey
HKCU\software\qnco::13_18 캄 RegNtPreCreateKey
HKCU\software\qnco::14_18 饲쾇 RegNtPreCreateKey
HKCU\software\qnco::11_19 ᦟ혼 RegNtPreCreateKey
HKCU\software\qnco::12_19 펮ֹ RegNtPreCreateKey
HKCU\software\qnco::13_19 ꚊҺ RegNtPreCreateKey
HKCU\software\qnco::14_19 첣ֹ RegNtPreCreateKey
HKCU\software\qnco::11_20 킺캂 RegNtPreCreateKey
HKCU\software\qnco::12_20 㯫 RegNtPreCreateKey
HKCU\software\qnco::13_20 闽㫨 RegNtPreCreateKey
HKCU\software\qnco::14_20 ᅯ㯫 RegNtPreCreateKey
HKCU\software\qnco::11_21 㩚먨 RegNtPreCreateKey
HKCU\software\qnco::12_21 ⫿爞 RegNtPreCreateKey
HKCU\software\qnco::13_21 夬猝 RegNtPreCreateKey
HKCU\software\qnco::14_21 ㌅爞 RegNtPreCreateKey
HKCU\software\qnco::11_22 컀 RegNtPreCreateKey
HKCU\software\qnco::12_22 祖ꡐ RegNtPreCreateKey
HKCU\software\qnco::13_22 ట꥓ RegNtPreCreateKey
HKCU\software\qnco::14_22 昶ꡐ RegNtPreCreateKey
HKCU\software\qnco::11_23 ���� RegNtPreCreateKey
HKCU\software\qnco::12_23 ‚�� RegNtPreCreateKey
HKCU\software\qnco::13_23 N�� RegNtPreCreateKey
HKCU\software\qnco::14_23 g��� RegNtPreCreateKey
HKCU\software\qnco::11_24 虒酂 RegNtPreCreateKey
HKCU\software\qnco::12_24 퓌ᒴ RegNtPreCreateKey
HKCU\software\qnco::13_24 ꚱᖷ RegNtPreCreateKey
HKCU\software\qnco::14_24 처ᒴ RegNtPreCreateKey
HKCU\software\qnco::11_25 ଒ RegNtPreCreateKey

Windows API Usage

Category API
Process Manipulation Evasion
  • NtUnmapViewOfSection
Process Shell Execute
  • CreateProcess
Anti Debug
  • IsDebuggerPresent
  • NtQuerySystemInformation
Network Wininet
  • HttpOpenRequest
  • HttpQueryInfo
  • HttpSendRequest
  • InternetConnect
  • InternetOpen
Network Winhttp
  • WinHttpOpen
User Data Access
  • GetUserObjectInformation
Other Suspicious
  • SetWindowsHookEx

Shell Command Execution

C:\Users\Likhgoep\AppData\Local\Temp\jds2124140.tmp\e47a281e668072c43c99d70a2ce2fad182639952_0002075381.exe "C:\Users\Likhgoep\AppData\Local\Temp\jds2124140.tmp\e47a281e668072c43c99d70a2ce2fad182639952_0002075381.exe"
C:\Users\Kjrkhiip\AppData\Local\Temp\jds322968.tmp\39ba323c80e4a24d4682e44d6a217d5bef432505_0001971227.exe "C:\Users\Kjrkhiip\AppData\Local\Temp\jds322968.tmp\39ba323c80e4a24d4682e44d6a217d5bef432505_0001971227.exe"
C:\Users\Jxutomgv\AppData\Local\Temp\jds3564703.tmp\615104d59f1fd7a63726727d8acd383e7d433d6a_0001898538 "C:\Users\Jxutomgv\AppData\Local\Temp\jds3564703.tmp\615104d59f1fd7a63726727d8acd383e7d433d6a_0001898538"
C:\Users\Dmfuncav\AppData\Local\Temp\jds19265.tmp\8b95ec2f1f1f497bbe557f60ac39b10b10ceec78_0002052731 "C:\Users\Dmfuncav\AppData\Local\Temp\jds19265.tmp\8b95ec2f1f1f497bbe557f60ac39b10b10ceec78_0002052731"
C:\Users\Skncezcm\AppData\Local\Temp\jds81921.tmp\211d2a34f4d7d0ee35fb35a4fcf8a82a44f0f7d3_0002075919 "C:\Users\Skncezcm\AppData\Local\Temp\jds81921.tmp\211d2a34f4d7d0ee35fb35a4fcf8a82a44f0f7d3_0002075919"
Show More
C:\Users\Feymgwwn\AppData\Local\Temp\jds3330031.tmp\ffc35d6327a5a31a1c79495b79d92fccd2344072_0002052121 "C:\Users\Feymgwwn\AppData\Local\Temp\jds3330031.tmp\ffc35d6327a5a31a1c79495b79d92fccd2344072_0002052121"
C:\Users\Ynwfqikn\AppData\Local\Temp\jds82703.tmp\098af5d808932fc4702bb4bc5acf171522388567_0001971227 "C:\Users\Ynwfqikn\AppData\Local\Temp\jds82703.tmp\098af5d808932fc4702bb4bc5acf171522388567_0001971227"
C:\Users\Rreqyqgu\AppData\Local\Temp\jds93093.tmp\b24613deab412fc6825dba1aefaa162036740971_0002075963 "C:\Users\Rreqyqgu\AppData\Local\Temp\jds93093.tmp\b24613deab412fc6825dba1aefaa162036740971_0002075963"
C:\Users\Fpmozhwh\AppData\Local\Temp\jds2370890.tmp\0d0ad92f1e99702715783d5d65fafe25b1f95d41_0002043232 "C:\Users\Fpmozhwh\AppData\Local\Temp\jds2370890.tmp\0d0ad92f1e99702715783d5d65fafe25b1f95d41_0002043232"
C:\Users\Kuelafow\AppData\Local\Temp\jds1822171.tmp\4907244ae0aefdeaff9dabe065c817f3ff7ab4df_0001911940 "C:\Users\Kuelafow\AppData\Local\Temp\jds1822171.tmp\4907244ae0aefdeaff9dabe065c817f3ff7ab4df_0001911940"
C:\Users\Fdjpczcu\AppData\Local\Temp\jds7684671.tmp\99ab7cb3aba382bbfc6d4acc611c868991dbdbee_0001971226 "C:\Users\Fdjpczcu\AppData\Local\Temp\jds7684671.tmp\99ab7cb3aba382bbfc6d4acc611c868991dbdbee_0001971226"
C:\Users\Fhmuaame\AppData\Local\Temp\jds3154062.tmp\475aac4296c41871141f1ea8ebc20aaa964d0a86_0001890410 "C:\Users\Fhmuaame\AppData\Local\Temp\jds3154062.tmp\475aac4296c41871141f1ea8ebc20aaa964d0a86_0001890410"
C:\Users\Jsadrtaq\AppData\Local\Temp\jds2926187.tmp\27d282bfbe289a7c4ba1b8859f05d75d73e74978_0002052690 "C:\Users\Jsadrtaq\AppData\Local\Temp\jds2926187.tmp\27d282bfbe289a7c4ba1b8859f05d75d73e74978_0002052690"
C:\Users\Iakiwwlc\AppData\Local\Temp\jds7139312.tmp\34760a59ecc033ef5e97d45cc953291a24c1618c_0001911902 "C:\Users\Iakiwwlc\AppData\Local\Temp\jds7139312.tmp\34760a59ecc033ef5e97d45cc953291a24c1618c_0001911902"
C:\Users\Xdcmwkun\AppData\Local\Temp\jds8413687.tmp\45d32f15300d216536528f5ef1fe30b67939cbef_0001962336 "C:\Users\Xdcmwkun\AppData\Local\Temp\jds8413687.tmp\45d32f15300d216536528f5ef1fe30b67939cbef_0001962336"

Trending

Most Viewed

Loading...