Threat Database Trojans Trojan.LynceBir.A

Trojan.LynceBir.A

By CagedTech in Trojans

Threat Scorecard

Popularity Rank: 6,538
Threat Level: 80 % (High)
Infected Computers: 164
First Seen: September 21, 2022
Last Seen: April 22, 2026
OS(es) Affected: Windows

Analysis Report

General information

Family Name: Trojan.LynceBir.A
Signature status: No Signature

Known Samples

MD5: 934cda3ed7323c36fbd7930ff3f4f4f7
SHA1: 219ea34ab41b64c057e80413558352766d413219
File Size: 96.04 KB, 96036 bytes
MD5: 236d91d02f4aa5c2ef5b52c955c0cfda
SHA1: b0d00add1e734abbf7ba22e6f0ac4a86f397fc3a
SHA256: 924F1D1516BF73CDBCC912DE60A12B0256BA7033109B6F47645328009B351264
File Size: 60.42 KB, 60416 bytes
MD5: c7dd0558ee390599ee34501a41f8edf0
SHA1: 24505bc76792328e97aea5e16e55a7dd851ced59
SHA256: 309F2FAFFBCFA12CF9DE6574A7043F51C4EB07CDFBD0135AD25067E145DD4C22
File Size: 2.27 MB, 2265088 bytes
MD5: a885a003bfca82a22996b4173300e87c
SHA1: 530ef2112c6b8206f3a2b74040b465f65d19afd9
SHA256: 7B743CD7F362FDD62D5988185704A46914A299B599D553628DED4D3AB9C9822F
File Size: 393.44 KB, 393436 bytes
MD5: 45ffd1336bc56a318dae6bed2047be5f
SHA1: 161650a30adcb08460d5b952fac952e88ba465e6
SHA256: E3274B5FB0FF4C3810E71615F6251282D49E271FC63AA04C9F0D4A364B3DF895
File Size: 13.82 KB, 13824 bytes
Show More
MD5: a93edd9897210ea0e5f99e42b99674c5
SHA1: 55530708fa0e353c2f7344929f03f130ac46be03
SHA256: 749B32EE591D5AD0A48DF0800702785FCA1AB60A066532A7861B9DFF252437AF
File Size: 111.34 KB, 111341 bytes
MD5: 9f8a7eeebc7d8dd55b77b059996ef6cb
SHA1: 81c67997d7f030ce83e7f718ab80631314e840e0
SHA256: 28F02FB45605C72543A9C49C2786F28776EAF618F99233A97B254E1A45A5DE06
File Size: 7.34 MB, 7335652 bytes
MD5: 8e8a8abcb836e6d08e41885881773460
SHA1: 1f8c8816f72c9e5e3596a3224ccd8355fdfcb3ed
SHA256: 9F202729CE47D8205407050E27309C4C666115C81C999A07013354A38CB71FD3
File Size: 60.92 KB, 60925 bytes
MD5: 8ee9a91772ea2e0e033a82c3d9dd6f4f
SHA1: 8deab2286ab499f2e4a77fd5b55a2da0192da0e7
SHA256: 5194C6F4CDF7A0E416250E533F6D012181E86AB89B19624D159092CC37979248
File Size: 7.17 KB, 7168 bytes
MD5: 4229878e89ec40ac480ed4973b8ae1e4
SHA1: 4da3c251047af6a62613acf4cdd16149cb2b8c14
SHA256: 19D681797AB156A7275E72A1FDDB749F3B62998C3026674651FD1D973CB1E37F
File Size: 123.19 KB, 123193 bytes

Windows Portable Executable Attributes

  • File doesn't have "Rich" header
  • File doesn't have debug information
  • File doesn't have exports table
  • File doesn't have relocations information
  • File doesn't have resources
  • File doesn't have security information
  • File has been packed
  • File has TLS information
  • File is .NET application
  • File is 32-bit executable
Show More
  • File is console application (IMAGE_SUBSYSTEM_WINDOWS_CUI)
  • File is either console or GUI application
  • File is GUI application (IMAGE_SUBSYSTEM_WINDOWS_GUI)
  • File is Native application (NOT .NET application)
  • File is not packed
  • IMAGE_FILE_DLL is not set inside PE header (Executable)
  • IMAGE_FILE_EXECUTABLE_IMAGE is set inside PE header (Executable Image)

File Icons

Windows PE Version Information

Name Value
Assembly Version 1.0.23.0
Comments
  • COMPUTERBILD-Abzockschutz-Installer (1.0.23 Online)
  • This installation was built with Inno Setup.
Company Name
  • Grenouille - C'MON
  • J3S GmbH
  • n37
File Description
  • COMPUTERBILD-Abzockschutz-Installer
  • Developed using the Dev-C++ IDE
  • Pause
  • PyGrenouille Setup
File Version 1.0.23.0
Internal Name
  • COMPUTERBILD-Abzockschutz-Installer.exe
  • Dunno
Legal Copyright
  • Bill Gates
  • Copyright © COMPUTERBILD GmbH
Legal Trademarks Bill Gates
Original Filename COMPUTERBILD-Abzockschutz-Installer.exe
Product Name
  • COMPUTERBILD-Abzockschutz-Installer
  • PyGrenouille
Product Version 1.0.23.0

File Traits

  • No Version Info
  • packed
  • x86

Block Information

Total Blocks: 508
Potentially Malicious Blocks: 8
Whitelisted Blocks: 479
Unknown Blocks: 21

Visual Map

0 0 0 0 x 0 0 0 ? ? ? ? ? ? ? ? ? 0 ? ? ? ? ? ? ? ? ? ? ? x x x 0 x 0 x 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 x 0 x 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 ? 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0
0 - Probable Safe Block
? - Unknown Block
x - Potentially Malicious Block

Similar Families

  • Dialer.X
  • Kindal.B
  • LynceBir.A

Files Modified

File Attributes
c:\windows\appcompat\programs\amcache.hve Read Data,Read Control,Write Data
c:\windows\appcompat\programs\amcache.hve.log1 Read Data,Write Data
c:\windows\appcompat\programs\amcache.hve.log2 Read Data,Write Data

Windows API Usage

Category API
Syscall Use
  • ntdll.dll!NtAdjustPrivilegesToken
  • ntdll.dll!NtAlpcSendWaitReceivePort
  • ntdll.dll!NtApphelpCacheControl
  • ntdll.dll!NtClearEvent
  • ntdll.dll!NtClose
  • ntdll.dll!NtConnectPort
  • ntdll.dll!NtCreateEvent
  • ntdll.dll!NtCreateFile
  • ntdll.dll!NtCreateKey
  • ntdll.dll!NtCreateMutant
Show More
  • ntdll.dll!NtCreateSection
  • ntdll.dll!NtCreateSemaphore
  • ntdll.dll!NtDelayExecution
  • ntdll.dll!NtDeleteValueKey
  • ntdll.dll!NtDeviceIoControlFile
  • ntdll.dll!NtDuplicateObject
  • ntdll.dll!NtEnumerateKey
  • ntdll.dll!NtEnumerateValueKey
  • ntdll.dll!NtFreeVirtualMemory
  • ntdll.dll!NtFsControlFile
  • ntdll.dll!NtLoadKeyEx
  • ntdll.dll!NtMapViewOfSection
  • ntdll.dll!NtOpenDirectoryObject
  • ntdll.dll!NtOpenEvent
  • ntdll.dll!NtOpenFile
  • ntdll.dll!NtOpenKey
  • ntdll.dll!NtOpenKeyEx
  • ntdll.dll!NtOpenProcessToken
  • ntdll.dll!NtOpenSection
  • ntdll.dll!NtOpenSymbolicLinkObject
  • ntdll.dll!NtOpenThread
  • ntdll.dll!NtOpenThreadToken
  • ntdll.dll!NtProtectVirtualMemory
  • ntdll.dll!NtQueryAttributesFile
  • ntdll.dll!NtQueryDefaultLocale
  • ntdll.dll!NtQueryDirectoryFileEx
  • ntdll.dll!NtQueryFullAttributesFile
  • ntdll.dll!NtQueryInformationFile
  • ntdll.dll!NtQueryInformationProcess
  • ntdll.dll!NtQueryInformationThread
  • ntdll.dll!NtQueryInformationToken
  • ntdll.dll!NtQueryKey
  • ntdll.dll!NtQueryLicenseValue
  • ntdll.dll!NtQueryPerformanceCounter
  • ntdll.dll!NtQuerySecurityAttributesToken
  • ntdll.dll!NtQuerySecurityObject
  • ntdll.dll!NtQuerySymbolicLinkObject
  • ntdll.dll!NtQuerySystemInformation
  • ntdll.dll!NtQuerySystemInformationEx
  • ntdll.dll!NtQueryValueKey
  • ntdll.dll!NtQueryVirtualMemory
  • ntdll.dll!NtQueryVolumeInformationFile
  • ntdll.dll!NtReadVirtualMemory
  • ntdll.dll!NtReleaseMutant
  • ntdll.dll!NtReleaseWorkerFactoryWorker
  • ntdll.dll!NtRequestWaitReplyPort
  • ntdll.dll!NtSetEvent
  • ntdll.dll!NtSetInformationKey
  • ntdll.dll!NtSetInformationProcess
  • ntdll.dll!NtSetInformationThread
  • ntdll.dll!NtSetInformationVirtualMemory
  • ntdll.dll!NtTestAlert
  • ntdll.dll!NtTraceControl
  • ntdll.dll!NtTraceEvent
  • ntdll.dll!NtUnmapViewOfSection
  • ntdll.dll!NtUnmapViewOfSectionEx
  • ntdll.dll!NtWaitForSingleObject
  • ntdll.dll!NtWaitForWorkViaWorkerFactory
  • ntdll.dll!NtWaitLowEventPair
  • ntdll.dll!NtWriteFile
  • ntdll.dll!NtWriteVirtualMemory
  • UNKNOWN
  • win32u.dll!NtUserGetKeyboardLayout
  • win32u.dll!NtUserGetThreadState
User Data Access
  • GetUserObjectInformation
Anti Debug
  • IsDebuggerPresent
Encryption Used
  • BCryptOpenAlgorithmProvider
  • CryptAcquireContext
Process Shell Execute
  • CreateProcess
Process Manipulation Evasion
  • ReadProcessMemory
Network Info Queried
  • GetAdaptersInfo

Shell Command Execution

C:\Windows\Microsoft.NET\Framework64\v2.0.50727\\dw20.exe dw20.exe -x -s 868

Trending

Most Viewed

Loading...