Threat Database Trojans Trojan.Madang

Trojan.Madang

By CagedTech in Trojans

Threat Scorecard

Popularity Rank: 16,023
Threat Level: 80 % (High)
Infected Computers: 1,042
First Seen: November 1, 2014
Last Seen: January 2, 2026
OS(es) Affected: Windows

SpyHunter Detects & Remove Trojan.Madang

Registry Details

Trojan.Madang may create the following registry entry or registry entries:
Regexp file mask
%WINDIR%\SysWOW64\Serverx.exe
Software\Microsoft\Windows\CurrentVersion\Run\Serverx

Analysis Report

General information

Family Name: Trojan.Madang
Signature status: Hash Mismatch

Known Samples

MD5: 9f26f38e4c20642dbf1a4f3c349e9a10
SHA1: 403d2ece3b80dd282fef82a4c5a69097617b5a66
SHA256: DBFF1D0A4D876018EAB8B13FB33D268291E5D02BF4942729A87B8196D14499DF
File Size: 1.09 MB, 1094422 bytes

Windows Portable Executable Attributes

  • File doesn't have "Rich" header
  • File has exports table
  • File has TLS information
  • File is 32-bit executable
  • File is either console or GUI application
  • File is GUI application (IMAGE_SUBSYSTEM_WINDOWS_GUI)
  • File is Native application (NOT .NET application)
  • File is not packed
  • IMAGE_FILE_DLL is not set inside PE header (Executable)
  • IMAGE_FILE_EXECUTABLE_IMAGE is set inside PE header (Executable Image)

File Icons

Windows PE Version Information

Name Value
Company Name
  • Zhuhai Kingsoft Office Software Co.,Ltd
File Description
  • WPS Office service program for service such as login and Cloud storage
  • WPS服务程序,提供账号登录、云存储等服务
File Version
  • 12,2,0,23196
Internal Name
  • wpscloudsvr
Legal Copyright
  • Copyright©2025 Kingsoft Corporation. All rights reserved.
Original Filename
  • wpscloudsvr.exe
Product Name
  • WPS Office
Product Version
  • 12,2,0,23196

Digital Signatures

Signer Root Status
Zhuhai Kingsoft Office Software Co., Ltd. DigiCert Trusted G4 Code Signing RSA4096 SHA384 2021 CA1 Hash Mismatch
Zhuhai Kingsoft Office Software Co., Ltd. DigiCert Trusted Root G4 Hash Mismatch

File Traits

  • 2+ executable sections
  • HighEntropy
  • x86

Block Information

Total Blocks: 3,483
Potentially Malicious Blocks: 40
Whitelisted Blocks: 3,131
Unknown Blocks: 312

Visual Map

? 0 0 ? ? 0 ? 0 0 0 0 0 0 0 0 0 0 ? 0 0 0 0 0 ? 0 0 0 0 0 ? 0 0 0 ? 0 ? ? ? 0 ? ? 0 0 0 ? ? 1 0 0 0 0 0 0 0 0 ? 0 ? 0 0 0 0 0 ? 0 ? 0 ? ? 1 0 1 1 1 1 ? 0 0 0 ? ? ? 0 0 0 0 0 0 0 0 0 0 0 ? 0 0 0 0 0 ? ? ? ? 0 ? ? ? ? ? ? 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 ? 0 0 0 ? ? ? 0 ? ? x 0 0 ? ? ? ? 2 ? ? ? ? ? ? ? ? ? ? 0 0 0 0 ? ? ? 0 0 0 0 0 0 0 1 ? ? ? 0 0 0 0 ? 1 ? 0 ? ? ? ? ? 0 0 0 0 0 0 ? 0 0 0 0 0 ? 0 0 ? 0 0 0 0 0 0 ? ? ? ? ? 0 ? 0 0 0 ? 0 0 0 0 0 0 0 0 ? ? ? ? ? ? 0 0 ? 0 0 0 0 ? ? 0 ? ? ? 0 0 0 0 ? 0 ? 0 0 0 ? ? ? 0 0 0 0 0 0 0 0 ? 0 0 ? 0 0 0 0 0 0 0 0 0 0 ? ? ? 0 ? ? ? 0 ? ? 0 0 0 0 0 0 0 0 0 0 ? ? ? ? 0 ? 0 ? ? 1 ? 0 0 0 0 0 ? 0 ? 0 0 ? ? 0 0 0 0 0 1 ? ? ? ? ? ? 0 0 ? 0 0 ? 0 0 ? ? 0 0 ? 0 0 0 ? 0 0 0 0 0 0 0 0 0 ? ? ? ? 0 0 0 x ? 0 0 0 0 0 0 ? 0 0 ? ? 0 0 ? ? 0 0 ? 0 0 0 0 0 ? 0 0 0 0 0 0 0 0 0 ? 0 0 ? 0 0 0 0 0 0 0 0 0 0 x ? 0 0 ? 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 1 0 0 ? 0 ? 0 0 0 0 0 ? ? 0 1 1 0 0 0 ? x ? ? 0 0 0 0 0 ? 0 0 0 ? ? 0 ? ? 0 0 0 0 0 0 0 ? 0 ? ? 0 0 0 0 ? ? ? ? ? 0 ? 0 ? 0 0 ? ? 0 0 0 0 0 0 ? 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 ? ? 0 0 ? 0 ? ? 0 0 ? 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 ? 0 0 0 0 0 0 0 0 0 ? ? ? 0 0 0 ? 0 0 0 0 0 0 0 0 0 0 ? ? 0 0 0 0 0 0 0 0 0 1 0 0 0 0 0 0 0 0 0 0 0 ? 0 ? 0 0 0 ? ? 0 ? ? ? ? 0 0 ? 0 ? 0 ? ? 0 ? ? ? ? ? 0 0 0 1 ? 0 ? 0 0 0 ? 0 ? ? 0 ? 0 0 0 ? 0 0 ? 0 0 0 0 0 0 0 ? ? ? ? 1 1 ? 0 0 ? 0 0 ? 0 ? ? ? ? 0 ? 0 0 ? 0 0 0 0 0 ? ? 0 0 0 0 0 0 ? 0 0 0 0 ? ? 0 ? ? 0 ? ? ? 0 ? 0 0 0 0 0 0 ? ? ? ? 0 0 0 ? ? 0 0 ? 0 ? ? 0 ? 0 0 ? ? ? ? ? ? ? 0 ? 0 ? ? ? 0 0 0 0 0 0 0 0 0 0 0 0 0 0 ? ? ? 0 ? ? 0 0 0 0 0 0 ? ? 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 ? 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 ? 0 0 ? 0 0 0 0 0 0 0 0 0 0 ? ? 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 ? 0 0 0 0 0 ? ? 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 ? ? ? 0 0 0 0 0 0 0 0 ? 0 ? ? ? ? 0 0 0 0 0 0 0 0 0 0 ? ? 0 ? ? 0 0 0 0 0 0 ? 0 0 0 0 0 0 0 0 0 0 0 0 0 ? 0 0 0 0 0 0 0 0 ? 0 0 0 ? 0 0 0 0 0 0 0 0 0 0 0 ? ? 0 ? ? 0 0 ? 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 ? 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 ? 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 1 0 0 0 1 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 1 0 0 0 0 ? 0 0 0 0 0 0 0 0 0 0 ? 0 0 0 0 0 0 0 ? 0 0 0 0 0 0 0 0 0 0 0 0 ? ? ? 0 ? ? ? ? ? 0 0 0 0 0 0 0 0 0 0 0 0 0 ? ? ? 0 0 ? 0 ? 0 ? ? 0 ? 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 1 1 1 0 0 0 0 0 1 1 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 1 0 1 1 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0
... Data truncated
0 - Probable Safe Block
? - Unknown Block
x - Potentially Malicious Block

Trending

Most Viewed

Loading...